Category: Healthcare Regulations

  • HIPAA Security Rule Delay: Why You’re Not Off the Hook

    Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ€” the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.

    What Actually Happened

    In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:

    • Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
    • Mandatory multi-factor authentication on all systems touching ePHI
    • 72-hour incident reporting timelines
    • Annual penetration testing
    • Tighter oversight and contractual obligations for business associates

    More than 100 hospital systems and provider associations โ€” including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ€” formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.

    HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ€” and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.

    What the Delay Does Not Change

    This is the part that gets lost in the headlines:

    1. The current Security Rule is still active and enforceable. Every requirement already on the books โ€” risk analysis, access controls, audit controls, transmission security, business associate agreements โ€” remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
    2. OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
    3. State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
    4. The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ€” they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.

    “We Have More Time” Is the Wrong Read

    The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:

    • Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
    • A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
    • Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ€” that risk doesn’t disappear because the paperwork is delayed.

    What Compliance Teams Should Do With the Extra Time

    Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.

    1. Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ€” these are the two changes most likely to survive the rulemaking process largely intact.
    2. Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
    3. Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ€” this is the kind of internal capability that takes real time to build.
    4. Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.

    Frequently Asked Questions

    Is the HIPAA Security Rule update dead?

    No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.

    Do I still have to comply with HIPAA Security Rule requirements right now?

    Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.

    When will the new HIPAA Security Rule requirements take effect?

    HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.

    What should healthcare organizations do now?

    Use the additional time to close gaps against the proposed requirements โ€” especially encryption, MFA, business associate oversight, and incident response โ€” rather than waiting for a final rule to start preparing.

    Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To

    The safest move during this delay isn’t waiting โ€” it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.

    Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.

    Schedule Your Free HIPAA Risk Review โ†’

    Source

    U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ€” RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.

  • What Are HIPAA Workforce Training Requirements?

    Under federal regulation 45 C.F.R. ยง 164.530(b)(1), all HIPAA Covered Entities and Business Associates are legally required to provide security and privacy training to every member of their workforce. Training must be delivered to new employees within a reasonable period after hiring and updated whenever a significant change occurs in company policies, software, or federal regulations. Failing to properly train employees is one of the most common triggers for Office for Civil Rights (OCR) investigations and costly financial settlements. A single employee clicking on a phishing link or mishandling Protected Health Information (PHI) can breach data security, transforming workforce training from a legal chore into your strongest line of defense.

    A common misconception is that HIPAA training is only for doctors, nurses, and medical staff. Under the law, workforce members is broadly defined to include full-time and part-time employees, volunteers, interns, contractors, and temporary staff. Administrative personnel in billing, human resources, IT, and reception roles must also be trained if they have any potential to encounter protected data. Essentially, if someone works under your direct control and could come into contact with PHI, they require formal compliance training.

    Timing is critical for maintaining a defensible position during an OCR audit. New workforce members must receive training within a reasonable period after joining the organization, which best practice dictates should occur within the first 30 to 90 days of employment. This onboarding training should ideally conclude before individuals are granted unsupervised access to systems containing Electronic Protected Health Information (ePHI). Additionally, if your organization updates its internal privacy policies, implements new Electronic Health Record (EHR) software, or if federal regulations change, affected workforce members must receive immediate retraining on those specific updates. While the law does not explicitly mandate annual training, the HIPAA Security Rule requires an ongoing security awareness training program, meaning compliance experts strongly recommend annual refresher courses alongside monthly phishing simulations.

    To satisfy both the Privacy and Security Rules, an effective training curriculum must address broad data handling principles alongside specific technological safeguards. Your training program must cover core privacy fundamentals, including what constitutes PHI, the minimum necessary standard, proper disclosure rules, and patient rights. On the technical side, employees need guidance on password management best practices, log-in monitoring protocols, and recognizing malware or phishing attempts. Finally, the training must cover organizational policies like mobile device management for personal devices, data backup protocols, physical data destruction, and clear instructions on your internal sanction policies for reporting a suspected data breach.

    If an auditor or investigator requests proof of compliance, simply stating that you train your staff is not enough. You must maintain audit-ready documentation, which means keeping signed acknowledgments or digital logs proving each employee completed their assigned modules. You must also log the exact dates training was completed and keep a record of the specific curriculum, slides, or videos used.

    Need help evaluating your organization’s current training protocols or overall compliance posture? You can schedule a HIPAA risk review with Colington Consulting to identify structural gaps before they lead to an enforcement action.

    • Reviewed on June 13, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The formal regulatory source for HIPAA workforce training requirements is 45 C.F.R. ยง 164.530(b)(1). This specific section falls under the administrative requirements of the HIPAA Privacy Rule, which dictates that a Covered Entity or Business Associate must train all members of its workforce on the policies and procedures regarding Protected Health Information (PHI) as necessary and appropriate for them to carry out their functions within the organization.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Does HIPAA Require Employee Background Checks?

    Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

    Executive Summary:

    Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

    HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

    While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

    Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

    How “Authorized Access” Impacts Hiring

    • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
    • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
    • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

    The OIG Exclusion List: A Mandatory Compliance Check

    While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

    Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

    Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

    Frequently Asked Questions (FAQ)

    Is a criminal background check required by HIPAA?

    No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

    What background checks are recommended for healthcare employees?

    At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

    What happens if a healthcare company hires an excluded individual?

    Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

    Ready to Eliminate Your HIPAA Risks?

    Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

    At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

    Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.