Category: HIPAA Security Rule Compliance

  • What OCR Told Us at the 2026 HIPAA Security Conference: Enforcement, Risk Analysis, and Policy Gaps

    What OCR Told Us at the 2026 HIPAA Security Conference: Enforcement, Risk Analysis, and Policy Gaps

    Quick answer: At the OCR/NIST โ€œSafeguarding Health Informationโ€ conference held September 2 to 3, 2026, in Gaithersburg, Maryland, HHS’s Office for Civil Rights delivered a consistent message across sessions: enforcement is not slowing down; risk analyses remain the most commonly cited deficiency because they are still inaccurate or incomplete; and many organizations still lack the documented policies and procedures needed to turn a risk analysis into an actual risk management program. OCR was direct on one point in particular: organizations should not wait for a breach, or a completed OCR investigation, before conducting a compliant risk analysis.

    Why This Conference Matters for Compliance Programs

    Each year, OCR and NIST’s Information Technology Laboratory co-host this conference to walk through where enforcement is headed and where organizations continue to fall short. This year’s agenda, spanning two full days, included briefings from OCR’s Director, threat intelligence updates from the Health Information Sharing and Analysis Center, and a dedicated OCR track on the Health Information Privacy, Data, and Cybersecurity Division’s own enforcement data.

    For compliance teams that could not attend, the sessions functioned less like a lecture and more like a preview of what OCR expects to see when it opens the next investigation, whether that investigation starts with a breach report or a routine complaint.

    Three themes ran through nearly every OCR-led session.

    1. Enforcement Is Not Slowing Down

    OCR used its own numbers to make the point directly. As of this year’s conference, OCR reported 21 completed ransomware investigations and 14 completed investigations under its Risk Analysis Enforcement Initiative; separately, its Right of Access Initiative, focused on individuals being denied timely access to their own health records, has produced 55 completed enforcement actions to date, with a newly stated focus on parent and personal representative access requests.

    The shift in breach data helps explain where that enforcement attention is concentrated. Comparing OCR’s historical breach portal data, September 2009 through December 2025, against the first seven months of 2026:

    • Hacking and IT incidents grew from 52 percent of reported large breaches to 75 percent.
    • Network servers, as the breach location, grew from 39 percent to 68 percent.
    • Theft, once 18 percent of reported breaches, has fallen to roughly 1 percent.
    • Physical causes, such as paper records and lost laptops, have both dropped to a small share of the total.

    In short, OCR’s own data show breaches are concentrated almost entirely in network-based, hacking-related incidents, and its enforcement priorities follow that data. Organizations that assume a strong physical security posture covers their exposure are missing where the actual risk, and the actual enforcement attention, now sits.

    2. OCR Still Finds Risk Analyses Inaccurate and Incomplete

    If OCR repeated one message more than any other, it was this: a risk analysis is requested in every Security Rule investigation OCR conducts, and it remains one of the most commonly deficient documents organizations produce.

    OCR drew a specific distinction that trips up many compliance programs: a gap analysis is not the same as a risk analysis. A gap analysis compares current practices against a checklist or a set of standards. A risk analysis, as required under the Security Rule’s Security Management Process standard, is a more rigorous exercise; it requires organizations to assess risks to all electronic protected health information at every stage in which that information exists within the organization, with enough specificity to drive decisions.

    OCR’s guidance broke this down into three stages that a thorough risk analysis has to cover:

    • Where ePHI is created or enters the organization: file transmissions and uploads, manual data entry or edits to existing ePHI, and lab results or images coming in from outside systems.
    • Where ePHI flows within the organization: movement into EHR systems, between clinical and other departments, through applications such as office productivity tools, web and mobile platforms, and remote access, and across infrastructure such as backups and system logs.
    • Where ePHI leaves the organization: email, fax, and file transfer applications, collaboration tools, and equipment disposal.

    An organization that has assessed risk at only one of these three stages, most commonly the point where ePHI enters or lives in the primary EHR, has not completed the kind of accurate and thorough risk analysis the Security Rule actually requires. This is very likely why risk analysis deficiencies remain the most cited finding across OCR’s enforcement actions.

    3. Organizations Still Lack Comprehensive Policies and Procedures

    The third theme is closely tied to the second. OCR was clear that a risk analysis is not the finish line; it is meant to be a direct input into an organization’s risk management process, used to develop corrective actions for each identified risk and to guide the implementation of security measures that reduce risk to a reasonable and appropriate level while protecting the confidentiality, integrity, and availability of ePHI.

    In practice, this is where many compliance programs stall. A risk analysis is completed, findings are documented, and then the corresponding policies, procedures, and corrective action plans are never built, updated, or tied back to what the risk analysis actually found. The Right of Access Initiative is a clear example of this gap in action: individuals have a right under the Privacy Rule to timely access to their own health records, generally within 30 days, with the possibility of one 30-day extension, and at a reasonable, cost-based fee. OCR continues to receive a high volume of complaints alleging denial of access, which points less to organizations being unaware of the rule and more to access request procedures that are not documented, not followed consistently, or not updated to reflect current staff and systems.

    The pattern OCR described is consistent: a risk analysis without a connected risk management program, and policies without a documented, current process behind them, are both incomplete compliance postures, even when each piece looks reasonable on its own.

    What OCR Wants Organizations to Do Right Now

    OCR’s message on timing was direct, and it is worth stating exactly as presented: organizations should not wait for a breach, or for a completed OCR investigation, before conducting a compliant risk analysis. Waiting is, itself, the exposure.

    OCR also pointed attendees to its own risk analysis resources, including a risk analysis explainer video, the Security Risk Assessment (SRA) Tool, and ongoing guidance and cybersecurity newsletters, all built to help organizations complete a risk analysis that meets the Security Rule’s standard rather than a lighter gap assessment.

    Organizations must also notify affected individuals of a breach no later than 60 calendar days after discovery, a deadline that does not shift based on the organization’s size or complexity.

    Frequently Asked Questions

    Is OCR’s HIPAA enforcement slowing down in 2026?

    No. OCR reported 21 completed ransomware investigations, 14 completed Risk Analysis Enforcement Initiative investigations, and 55 completed Right of Access enforcement actions as of its 2026 conference, and its breach data shows hacking and network server incidents making up a growing share of reported breaches.

    Is a gap analysis the same as a HIPAA risk analysis?

    No. OCR was explicit that a gap analysis, which compares current practices to a checklist, does not meet the Security Rule’s risk analysis requirement. A compliant risk analysis assesses risk to all ePHI as it is created, as it flows through the organization, and as it leaves the organization.

    Does OCR require a risk analysis for every investigation?

    Yes. OCR stated that it requests a risk analysis in every Security Rule investigation it conducts, which makes an outdated or incomplete risk analysis one of the most common findings across enforcement actions.

    What is OCR’s Right of Access Initiative?

    It is an enforcement initiative focused on individuals being denied timely access to their own health records. The HIPAA Privacy Rule requires access generally within 30 days, with one possible 30-day extension, at a reasonable, cost-based fee; OCR has completed 55 enforcement actions under this initiative and has signaled a new focus on parent and personal representative access.

    Should organizations wait for a breach before doing a risk analysis?

    No. OCR was clear on this point: organizations should not wait for a breach or a completed OCR investigation before conducting a compliant risk analysis.

    Not Sure Your Risk Analysis Would Hold Up to OCR’s Standard? Colington Consulting Can Help You Find Out

    OCR was clear that a risk analysis needs to cover ePHI at every stage it exists in your organization, feed directly into a documented risk management program, and stay current, not sit as a one-time project. Colington Consulting works directly with covered entities and business associates to build and maintain the accurate, thorough risk analysis and related policies and procedures OCR expects to see before an investigation starts.

    Get a free HIPAA Risk Review. We will help you see exactly where your risk analysis and policies and procedures stand relative to what OCR is actually enforcing, and show you where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โ€œSafeguarding Health Information: Building Assurance Through HIPAA Securityโ€ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.

    U.S. Department of Health and Human Services, Office for Civil Rights, conference session materials: Risk Management; Key Takeaways; Right of Access Initiative; Risk Analysis: Accurate and Thorough.

    U.S. Department of Health and Human Services, Office for Civil Rights, HIPAA Breach Portal data, breaches by type and location of breach, September 23, 2009 through July 31, 2026.

    45 C.F.R. ยง 164.308(a)(1) โ€” Security Management Process (Risk Analysis and Risk Management).

    45 C.F.R. ยง 164.524 โ€” Right of Access.

  • Why Syncing Data to the Cloud Isnโ€™t a Valid HIPAA Ransomware Strategy

    Why Syncing Data to the Cloud Isnโ€™t a Valid HIPAA Ransomware Strategy

    If your practice or business relies on continuous cloud sync or daily cloud snapshots as your primary disaster recovery strategy, your ePHI is far more vulnerable than you think.

    Modern malware doesn’t just encrypt local workstations; it actively targets connected network drives, mapped cloud folders, and online backup repositories. If your backup target is continuously connected to your network, ransomware can encrypt the backup right along with your live electronic Protected Health Information (ePHI).

    The Flaw in Standard Cloud Sync

    Standard cloud storage services mirror changes made on local devices in real time. If a ransomware strain silently encrypts files on a local server, those encrypted files instantly sync to the cloud, overwriting clean versions.

    In its Ransomware and HIPAA Fact Sheet, the HHS Office for Civil Rights (OCR) emphasizes that ransomware is specifically designed to deny access to data. Simply having a cloud backup provider sign a Business Associate Agreement (BAA) satisfies administrative requirements. Still, it does not satisfy the technical requirements of data recovery if the underlying backup mechanism is vulnerable to simultaneous encryption.

    What the HIPAA Security Rule Actually Requires

    Under the HIPAA Security Rule, maintaining retrievable data isn’t just an IT best practiceโ€”it is an explicit legal mandate under the Contingency Plan standard (45 C.F.R. ยง 164.308(a)(7)).

    According to HHS guidance on HIPAA contingency planning, covered entities and business associates must implement three core specifications:

    1. Data Backup Plan (ยง 164.308(a)(7)(ii)(A)): Establish and implement procedures to create and maintain retrievable, exact copies of ePHI.
    2. Disaster Recovery Plan (ยง 164.308(a)(7)(ii)(B)): Establish procedures to restore any lost data resulting from an emergency or cyberattack.
    3. Testing and Revision Procedures (ยง 164.308(a)(7)(ii)(E)): Perform periodic testing and revision of contingency plans to verify data can actually be restored.

    Building an HHS-Aligned Cyber Resilience Strategy

    To meet OCR expectations during a post-incident investigation, HHS security guidance recommends moving beyond basic cloud sync to a resilient backup framework:

    • Maintain Isolated/Air-Gapped Copies: Backups must be decoupled from the primary network. Immutable storageโ€”where data is written once and cannot be altered or deleted, even by an administrative accountโ€”ensures ransomware cannot wipe out recovery points.
    • Implement Strict Access Controls: Under 45 C.F.R. ยง 164.308(a)(3), backup administrative controls must be isolated, requiring multi-factor authentication (MFA) and restricted access to prevent credential-based wiping.
    • Document Regular Restoration Tests: OCR auditors evaluate whether an organization regularly tests data restoration. Running routine restoration drills proves that backup files are uncorrupted and accessible within necessary operational timeframes.

    Action Steps for Practice Managers

    1. Audit Backup Isolation: Verify with your IT team or Managed Service Provider (MSP) whether your backups are truly air-gapped or protected by immutable object locking.
    2. Verify Testing Logs: Ensure your technical staff or vendor provides written verification of successful data restoration tests to include in your annual Security Risk Assessment (SRA) documentation.

    Not Sure Your Backups Would Actually Survive a Ransomware Attack? Colington Consulting Can Help You Find Out

    A cloud sync tool and a signed Business Associate Agreement feel like protection, but they do not test whether your data actually comes back after an attack. Colington Consulting works directly with practices and businesses to build a documented, defensible contingency plan that meets the Security Ruleโ€™s backup, disaster recovery, and testing requirements, not just the appearance of one.

    Get a free HIPAA Risk Review. We will help you evaluate your backup isolation, restoration testing, and contingency planning against what OCR actually expects, and show you exactly where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’