Category: Cybersecurity

  • HIPAA Security Rule Delay: Why You’re Not Off the Hook

    Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ€” the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.

    What Actually Happened

    In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:

    • Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
    • Mandatory multi-factor authentication on all systems touching ePHI
    • 72-hour incident reporting timelines
    • Annual penetration testing
    • Tighter oversight and contractual obligations for business associates

    More than 100 hospital systems and provider associations โ€” including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ€” formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.

    HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ€” and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.

    What the Delay Does Not Change

    This is the part that gets lost in the headlines:

    1. The current Security Rule is still active and enforceable. Every requirement already on the books โ€” risk analysis, access controls, audit controls, transmission security, business associate agreements โ€” remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
    2. OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
    3. State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
    4. The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ€” they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.

    “We Have More Time” Is the Wrong Read

    The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:

    • Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
    • A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
    • Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ€” that risk doesn’t disappear because the paperwork is delayed.

    What Compliance Teams Should Do With the Extra Time

    Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.

    1. Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ€” these are the two changes most likely to survive the rulemaking process largely intact.
    2. Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
    3. Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ€” this is the kind of internal capability that takes real time to build.
    4. Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.

    Frequently Asked Questions

    Is the HIPAA Security Rule update dead?

    No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.

    Do I still have to comply with HIPAA Security Rule requirements right now?

    Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.

    When will the new HIPAA Security Rule requirements take effect?

    HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.

    What should healthcare organizations do now?

    Use the additional time to close gaps against the proposed requirements โ€” especially encryption, MFA, business associate oversight, and incident response โ€” rather than waiting for a final rule to start preparing.

    Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To

    The safest move during this delay isn’t waiting โ€” it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.

    Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.

    Schedule Your Free HIPAA Risk Review โ†’

    Source

    U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ€” RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Cybersecurity & HIPAA Compliance: Ransomware Enforcement Cases

    How Ransomware Is Driving OCR Enforcement

    What is the connection between cybersecurity and HIPAA?

    Cybersecurity is a core requirement of HIPAA compliance. The HIPAA Security Rule mandates that healthcare organizations implement administrative, technical, and physical safeguards to protect electronic protected health information (ePHI).

    As ransomware attacks increase, regulators now treat weak cybersecurity controls as direct HIPAA violations, not just IT failures.

    Why is ransomware increasing HIPAA enforcement?

    Ransomware incidents often expose gaps in compliance programs. When attackers encrypt or steal ePHI, the Office for Civil Rights (OCR)investigates whether the organization:

    • Conducted a risk analysis
    • Implemented access controls
    • Maintained system security and patching
    • Documented safeguards

    If these are missing, fines and settlements are likely, even if the attack itself was external.

    How Ransomware Is Reshaping HIPAA Compliance

    Ransomware has made healthcare one of the most targeted sectors for cyberattacks. As a result, HIPAA compliance now requires continuous cybersecurity risk management, not just annual documentation.

    OCR enforcement trends show that organizations are penalized most often for:

    • Failure to perform a risk analysis
    • Lack of multi-factor authentication (MFA)
    • Unpatched systems or outdated software
    • Insufficient audit controls and monitoring

    These findings confirm that cybersecurity weaknesses directly translate into HIPAA Security Rule violations.

    OCR Enforcement Examples and Common Violations

    1. Lack of Risk Analysis

    OCR consistently identifies missing or incomplete risk assessments as a top violation. Organizations must demonstrate they actively identify and mitigate risks.

    What is a Security Risk Assessment?

    A proper risk analysis is not optionalโ€”it is the foundation of HIPAA compliance.

    2. Weak Access Controls

    Ransomware attackers commonly exploit poor authentication and user access management. OCR frequently cites:

    • No MFA
    • Shared logins
    • Excessive user privileges

    3. Inadequate System Security

    Failure to patch systems or monitor networks allows ransomware to spread quickly. OCR expects proactive vulnerability management and real-time detection.

    What Cybersecurity Measures Are Required for HIPAA Compliance?

    To meet modern HIPAA expectations, healthcare organizations should implement:

    • Enterprise-wide risk assessments
    • Endpoint detection and response (EDR)
    • Secure, tested backups
    • Email security and phishing prevention
    • Continuous monitoring and audit logging
    • Workforce security training

    These safeguards must be documented and regularly updated.

    How to Align Cybersecurity with HIPAA Requirements

    Organizations must move from reactive compliance to integrated security programs.

    At Colington Consulting we help healthcare organizations align cybersecurity with HIPAA requirements.

    What services are needed to meet HIPAA requirements?

    Our approach combines regulatory expertise with real-world threat protection, reducing both breach risk and enforcement exposure. For additional guidance, visit our HIPAA compliance blog page.

    Key Takeaways

    • Cybersecurity failures are now HIPAA violations
    • Ransomware drives increased OCR enforcement actions
    • Risk analysis is the most commonly cited deficiency
    • Organizations must implement proactive, continuous security controls
    • Compliance now requires operational cybersecurity, not just policies

    FAQ

    Are ransomware-related HIPAA breaches made public by OCR?

    Yes. As required by the HITECH Act, OCR posts on the HHS website a list of breaches of unsecured protected health information affecting 500 or more individuals.

    What is the most common HIPAA violation in ransomware cases?

    Failure to conduct a comprehensive risk analysis is the most frequent violation cited by OCR.

    Does HIPAA require cybersecurity frameworks like NIST?

    HIPAA does not mandate NIST, but OCR expects organizations to follow recognized security standards to meet compliance requirements.

    Schedule a 30 minute HIPAA Risk Review

  • Data Breach Costs at an All-Time High According to 2022 Report

    Guest article authored by Gabby Williams โ€“ Content Specialist at New Reach Marketing

    Data breaches have become a pervasive and costly problem in today’s digital world. With the increasing reliance on technology and the proliferation of data, the risk of data breaches has risen exponentially.

    According to the IBM Security Cost of a Data Breach Report 2022, 83% percent of organizations studied have experienced more than one data breach, and just 17% said this was their first data breach. Due to the increased occurrence of data breaches, 60% of organizations studied stated that they increased the price of their services or products.

    In this article, we will explore the rising cost of data breaches, examining the reasons behind the trend, the industry impacted the most, and the steps that can be taken to mitigate the risks.

    What Is a Data Breach?

    Data breaches refer to unauthorized access, theft, or exposure of sensitive data. This can include personal information such as names, addresses, phone numbers, Social Security numbers, financial information, and even intellectual property or trade secrets.

    Cybercriminals and hackers are constantly seeking vulnerabilities in systems and networks to gain unauthorized access and exploit sensitive data for various purposes, including financial gain, identity theft, corporate espionage, and more.

    Rising Cost of Data Breaches

    The cost of data breaches has also been on the rise in recent years, with numerous high-profile incidents grabbing headlines and affecting millions of individuals and businesses around the world.

    The IBM Report showed that the cost of a data breach averaged USD 4.35 million in 2022. This figure represents a 2.6% increase from the previous year, when the average breach cost was USD 4.24 million. Compared to 2020, the average cost has climbed 12.7% from USD 3.86 million.

    It is evident that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year.

    Data Breaches in Healthcare

    Healthcare organizations are particularly vulnerable to data breaches due to the wealth of personal and sensitive data stored within their systems. Patient records, medical history, insurance information, and payment details are what make them prime targets for cybercriminals seeking access to valuable data for various malicious purposes.

    Regulatory fines and legal liabilities for non-compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) alone are extremely costly.

    HIPAA Compliance

    All regulated entities must comply with HIPAA Privacy, Security, and Breach Notification Rules to ensure the protection and security of patient privacy and medical records. Failing to follow HIPAA safeguards greatly increases the risk of cyberattacks and results in non-compliance penalties.

    As the healthcare industry remains the primary target for data breaches, it is the responsibility of each organization, provider, and employee to maintain HIPAA compliance. Some of the most effective ways to negate data breaches and HIPAA violations include routine HIPAA compliance and cybersecurity training, penetration testing tools, and conducting required security risk assessments.

    A lack of training and assessment of daily practices can lead to unintentional HIPAA violations, a common issue among healthcare organizations. For example, failing to follow the HIPAA Breach Rule Notification Requirements, whether unintentional or not, can lead to significant consequences.

    In another example, say your healthcare practice has been using online forms to gather new patient information without ensuring they are HIPAA-compliant. While this may have been a small oversight, these forms resulted in the theft of your patientsโ€™ protected health information (PHI).

    This could have been prevented by following HIPAA compliance and cybersecurity best practices, such as proper training and conducting assessments. Utilizing one of these 5 HIPAA-compliant form builders helps to ensure HIPAA compliance requirements.

    Impact of Data Breaches on Healthcare Organizations

    Data breaches can significantly impact healthcare organizations, both financially and reputationally.

    • Legal and financial consequences: Healthcare organizations may face legal and financial consequences as a result of data breaches. This may include fines, penalties, and legal settlements, as well as potential lawsuits from affected patients.
    • Loss or theft of PHI: A data breach can result in the loss or theft of PHI, which can be very costly to remediate. The healthcare organization may be required to offer credit monitoring or identity theft protection services to affected patients, which can be expensive. The organization may also have to pay fines and penalties, both from regulatory bodies and potentially from affected patients who may take legal action.
    • Reputational damage: A data breach can harm the organization’s reputation. Patients may lose trust in the organization’s ability to protect their PHI and seek services elsewhere. This can result in a loss of revenue and difficulty in attracting new patients.
    • Operational disruption: A data breach can disrupt the normal operations of a healthcare organization. Organizations may need to dedicate significant resources to investigating and resolving the breach, including IT resources, staff time, and external consulting services. This can result in operational disruptions, increased costs, and diversion of resources away from other critical activities.

    Why Are Data Breaches Getting Costly?

    There are several reasons behind the rising cost of data breaches:

    Increased Use of Technology

    The increased use of technology has created a larger attack surface for cybercriminals to target. Take Microsoft statistics, for example. In 2020, Microsoft Office 365 usage rose by 20%. However, about 67% of IT leaders who use this software reported an increase in data breaches.

    With the proliferation of connected devices, cloud computing, and the Internet of Things (IoT), the volume of data generated and transmitted has skyrocketed. This provides more opportunities for cybercriminals to infiltrate systems and networks.

    Increased Implementation of Data Protection Regulations

    Another factor contributing to the rising cost of data breaches is the growing regulatory landscape around data protection. Many countries and regions have implemented stringent data protection laws, such as HIPAA, the European Union’s General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

    They impose significant fines and penalties for non-compliance. In the event of a data breach, organizations may face not only the direct costs of investigating and mitigating the breach but also regulatory fines and legal liabilities. These costs can add up quickly, leading to significant financial burdens.

    Increased Online Presence

    The impact of data breaches extends beyond financial costs. Businesses also face reputational damage, loss of customer trust, and potential legal liabilities. In today’s hyper-connected world, news of a data breach can spread quickly through social media and other online channels, resulting in negative publicity and damage to a company’s brand image.

    Customers may lose trust in the affected organization’s ability to protect their data, leading to customer churn and loss of business opportunities. Additionally, businesses may face legal actions from affected customers, partners, or regulators, resulting in costly legal battles and financial settlements.

    Conclusion

    It is clear from the IBM Security Cost of a Data Breach Report 2022 that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year. Healthcare organizations, in particular, are at risk due to the sensitive data stored within their systems.

    Maintaining HIPAA compliance is crucial to protect patients’ privacy and avoid penalties for non-compliance. Colington Consulting can assist in conducting HIPAA security risk assessments, developing risk management plans, and providing workforce security awareness and privacy training to reduce the risk of data breaches and HIPAA violations.

    By taking the necessary steps to protect sensitive data, organizations can prevent the costly consequences of data breaches and safeguard their reputation and finances. Don’t wait for a data breach to occur; contact Colington Consulting today to protect your organization’s sensitive information.

  • Improve Your Organization’s Cybersecurity & Prevent Data Breaches

    Guest article authored by Gabby Williams โ€“ Content Specialist at Hushmail

    With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.

    According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months โ€” the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.

    In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.

    In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.

    Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the โ€œstandards, best practices, guidelines, procedures, methodologies, and processes developedโ€ under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.

    Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organizationโ€™s cybersecurity and prevent data breaches.

    1. Locate your sensitive data

    Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.

    2. Keep strict tabs on privileged access

    The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.

    Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. Itโ€™s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.

    3. Properly patch your infrastructure

    Your cybersecurity measures are only as strong as your organizationโ€™s underlying infrastructure. Your organizationโ€™s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.

    4. Fortify your network perimeter

    While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.

    5. Get rid of redundant data

    Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.

    There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.

    6. Ensure endpoint protection

    Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.

    Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.

    7. Encrypt data at rest and in transit

    Unencrypted data is like a bank with an open vault. If data isnโ€™t encrypted, anyone can access it or even steal it since thereโ€™s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.

    8. Establish a robust password policy

    The importance of a sound password policy canโ€™t be emphasized enough. Itโ€™s a necessity for all services and applications running on a network. Here are some general password policy requirements:

    • Minimum of 8-10 characters
    • 4 character types including uppercase, lowercase, number, and special character
    • Must not have 3 consecutive or repeating characters
    • 90-day password rotation policy
    • Multi-factor authentication may also be enforced using email or soft token

    9. Prepare business continuity and disaster recovery plans

    Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.

    New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.

    10. Instill cybersecurity training across your organization

    Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.

    Conclusion

    With hackers becoming more sophisticated, itโ€™s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.

  • OCR Issues Quarterly Cybersecurity Newsletter

    On March 17, the HHS Office for Civil Rights issued its quarterly cybersecurity newsletter. The big take away from the newsletter and the OCR mantra, is most cybersecurity attacks in the healthcare sector can “prevented or substantially mitigated” if organizations implemented all the required safeguards under the HIPAA Security Rule. According to the newsletter, “the number of breaches due to hacking or IT incidents accounted for 66% of all breaches affecting 500 or more individuals reported to OCR in 2020.”

    However, in a recent presentation made by Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, at the HIPAA Summit, hacking and IT related incidents now account for 73% of all reported breaches. Regardless of the current percentages, this is concerning and organizations must do more to address technical safeguard requirements. Also troubling is the vector of the breaches with 52% affecting network servers and 28% by email, most likely due to phishing.

    There needs to a holistic approach to overall compliance which includes the integration of technical safeguards along with program management. Small to mid-size healthcare organizations that outsource their IT requirements must use managed service providers that understand the world of HIPAA compliance. The days of trying to handle IT inhouse, as small to mid-size provider, should be over. Most HIPAA Security Officers have too much on their plates now to handle vast IT requirements. As the newsletter bluntly states, “A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.”

    Although not required by the HIPAA Security Rule, organizations should consider conducting a cybersecurity assessment to fully understand the landscape of potential threats. In addition, add some type of IT vulnerability assessment to enhance the requirement of a HIPAA Security Risk Assessment. Being proactive with a systematic approach to cybersecurity safeguards and HIPAA compliance program management can go a long way to help prevent hacking and breaches to occur.

    To read the OCR newsletter, click here.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management | Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    This article was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

  • OCR Provides Ransomware Resources

    On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

    Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

    Here is the list of those resources:

    HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

    ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

    HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

    OCR Guidance:

    CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

    CISA Ransomware Guide:

    FBI Ransomware Resources:

    OCR Cybersecurity Newsletters:

    REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Critical Vulnerabilities in Microsoft Windows Operating Systems

    The Cybersecurity and Infrastructure Security Agency (CISA) issued guidance regarding vulnerabilities in Microsoft Windows Operating Systems. If your organization manages all IT related services in-house and utilizes Microsoft systems, please be aware of this warning.

    Read the Alert

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • PHI – Striking Fear When It Comes to Being Compromised

    by Jay Hodes, Presidentย – Colington Consultingย 

    I am not sure if those tasked with securing protected health information lose sleep every night worrying if they did enough to safeguard the data their organizations maintain. If they are losing sleep, though, that may be a good thing, because it could show how seriously they take this responsibility. But for the rest, that obnoxious wake up alarm that we all hate at times should be the recent ransomware case that occurred at the Hollywood (CA) Presbyterian Medical Center.

    A letter released by Allen Stefanek, President and CEO of the Center, acknowledged that $17,000 in a ransom was paid to the alleged perpetrators to get their electronic health records back. Stefanek stated the โ€œquickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key.โ€

    If a hospital system can be put into a virtual shutdown, how vulnerable are millions of small to mid-size providers?

    When conducting HIPAA risk assessments, I ask required questions about contingency, emergency and disaster recovery plans. Some organizations do not realize these are critical elements for HIPAA compliance. Policies and procedures must be in place and address these potential vulnerabilities that could result in a high risk rating. Unless these providers are outsourcing IT services and secure backup is part of the arrangement, many fall short in making sure all PHI maintained is available at all times, regardless of emergency or disaster โ€“ or data being taken hostage, as was the case with Hollywood Presbyterian.

    One of the lessons I learned from my time in Federal law enforcement is to โ€œwhat ifโ€ scenarios to death. Try to determine all the negatives an operation or mission could face, and then have a contingency plan to address each particular scenario. Being prepared is crucial because if something does go bad, a plan is already in place to address it. When it comes to protecting healthcare data, the same philosophy should hold true. There are required HIPAA implementation specifications for the standard of developing and maintaining contingency plans. Policy and procedure must be in place to address areas like data backup, disaster recovery, system criticality analysis and emergency mode operations.

    Although not technically a HIPAA requirement, I always bring up continuity of business operations when talking with clients. It goes beyond needing access to protected health information in emergency conditions. I recommend timelines in cases where a facility cannot be occupied after a natural or man-made disaster and there is the need to assign roles and responsibilities to do certain things, such as locating temporary office space, procuring IT, telecom, and medical equipment and establishing a process to notify patients about the closure or relocation.

    Many larger organizations have procedures in place and routinely test and drill their contingency plans. Small to mid-size organizations must have the same protocols in place; albeit to a lesser extent because of the nature of their business operations.

    Fearing if your organization is going to be compromised is a reality that needs to be faced. Most experts agree it is not if, but when. Having addressed these issues before a breach occurs and having a game plan in place can go a long way in making sure any impact can be minimized as much as possible.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Ransomware Threatens More Than Livelihood – It Threatens Lives

    Ransomware does a lot more than hurt your organizationโ€™s bottom line. It can actually risk the lives of hospital patients. And weโ€™re not talking about just privacy concerns this time. A recent story in the news earlier in October has painted a truly frightening and all-too-real scenario: patients being sent away because of hospital systems being down.

    Hereโ€™s an overview of what happened.

    Which Hospitals Were Hit with Ransomware?

    There were a total of ten hospitals that were infected all around the same time. Seven of them were in Australia, and three of them were here in the U.S. in the state of Alabama. The two groupings are not suspected to be connected to the same attacker, but all ten were forced to take the same drastic actions. All three hospitals that make up the DCH Health System in Alabama were closed to new patients when the attack paralyzed the health network’s computer system.

    At the time this news broke, the hospitals – DCH Regional Medical Center in Tuscaloosa, Northport Medical Center, and Fayette Medical Center – were forced to turn away all but the most critical new patients. Non-critical patients were diverted to nearby hospitals, and even some emergency patients were also relocated once they were stabilized.

    How did the Hospitals Respond?

    DCH representatives wrote in a release that a criminal was limiting their ability to use their computer systems in exchange for a payment amount that was not known at the time. Eventually, the Alabama hospitals felt they had no choice but to pay the ransom demands in order to obtain the decryption keys necessary to rebuild their networks. The Tuscaloosa News reported that DCH officials made a payment to the people responsible for the ransomware attack, but didnโ€™t state how much was paid. In exchange for the payment, according to a statement from DCH, โ€œthis included purchasing a decryption key from the attackers to expedite system recovery and help ensure patient safety.โ€

    How Can HIPAA Compliance Prevent Ransomware?

    According to an FAQ published by DCH, the strain of ransomware that hit the hospitals is known as โ€œRyuk,โ€ which specializes in burrowing deep into infected networks to exact big payments. Thus far, Ryuk has nearly always been associated with phishing campaigns directed at employees of target companies. The United Statesโ€™ healthcare system is one of the largest targets by far for such campaigns, and itโ€™s quite possible that strict adherence to HIPAA guidelines could have potentially prevented this attack from happening altogether.

    Weโ€™ve reached a tipping point in the world of cybersecurity and data protection. Itโ€™s no longer just about protecting privacy. Even though the leaking of patient data can most certainly ruin lives, we are now seeing examples of how this battleground can physically endanger lives. You can be sure to see more such examples as technology continues to evolve.

    How can organizations expect to adapt to new challenges by applying new safeguards if theyโ€™re not yet following those standards that are already currently in place? HIPAA exists for a reason.

    Take Action Now

    Does your organization have a fully implemented HIPAA Risk Management Plan that includes how to address ransomware attacks? If not, we can develop one for you as part of our comprehensive package of HIPAA services.ย  Give us a call today at 800-733-6379 or drop us an email at info@cchipaa.com for a free, initial consultation.