Is Your HIPAA Compliance Program on Summer Vacation?

Summer is here — and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

Hackers Don’t Take Time Off — The Numbers Prove It

At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals — making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

What OCR’s Own Investigations Keep Finding

OCR doesn’t just count breaches — it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain — not just once, but on an ongoing basis.

That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

OCR Is Actively Auditing Right Now

OCR launched its 2024–2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware — and the scale of harm to patients — have made Security Rule compliance a top enforcement priority.

If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready — regardless of the season.

What You Should Be Doing Right Now

OCR provides guidance your organization can use today:

Conduct a Security Risk Assessment — HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

OCR Ransomware and HIPAA Factsheet — outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

OCR Breach Portal — publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

The bottom line: summer is not a compliance pause. It may actually be your highest-risk window — reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

Frequently Asked Questions

Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

What is the most common cause of large HIPAA breaches?

According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related — making hacking and IT incidents the dominant threat to protected health information.

Is OCR actively auditing organizations right now?

Yes. OCR’s 2024–2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

Where can I report a HIPAA breach to HHS?

Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

Need Help with Your HIPAA Compliance Program?

At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

Regulatory Sources:

Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.