Cybersecurity enforcement and HIPAA: what healthcare practices need to know in 2026

Return to Top

Published on:

Mon, Jan 12, 2026

Categories:

Client Alerts
Industry News
Share This Post:

If 2024–2025 felt like a turning point, that’s because it was. OCR confirmed it prioritized investigations of Change Healthcare and UnitedHealth Group after the sector‑wide disruption, and the volume of individual notices tied to that breach has continued to climb. Regulators are now scrutinizing how programs work in real life—before, during, and after an incident—not just what’s on paper. (hhs.gov)

What regulators expect from your practice

  • A risk analysis that fits your practice. OCR’s guidance stresses an “accurate and thorough” assessment of risks to ePHI, documented and kept current. Treat it as a living process that drives concrete remediation—owners, timelines, and proof of progress. (hhs.gov)

  • Active oversight of your vendors. Your HIPAA obligations extend to Business Associates. Regulators expect signed BAAs with real security obligations and evidence of ongoing oversight, not just a file copy. HHS provides model BAA provisions you can adapt. (hhs.gov)

  • Incident readiness you can demonstrate. Plans should be tested, roles rehearsed, and timelines measurable. NIST’s updated incident‑response guidance (SP 800‑61r3) aligns drills and documentation with CSF 2.0. (nist.gov)

  • Timely breach notification. Build your workflows around HIPAA’s “without unreasonable delay and no later than 60 days” standard for individual, media (when applicable), and HHS notices. Templates and checklists help you beat the clock. (hhs.gov)

Trends to watch

  • State AG actions alongside HIPAA. Multistate settlements continue to use consumer‑protection and breach‑notification laws—plus HIPAA—especially where vendor failures ripple into healthcare. The Blackbaud settlement required security upgrades, board reporting, and years of independent assessments.

  • The vendor “blast radius.” OCR’s Change Healthcare FAQ underscores that while OCR prioritized Change/UHG, covered entities and BAs tied to the incident still have obligations. Map these relationships and clarify who will notify whom before a crisis. (hhs.gov

  • Governance at the top. CSF 2.0 adds a “Govern” function and squarely places cybersecurity on leadership agendas—right alongside financial and legal risk. Expect questions about board visibility and accountability. (nist.gov)

  • Converging standards and expectations. HHS’s Healthcare/Public Health Cybersecurity Performance Goals (CPGs) translate common best practices—MFA, email security, incident planning, vendor requirements—into a practical, sector‑specific roadmap many regulators and insurers now reference. (hhscyber.hhs.gov)

  • Parallel enforcement outside HIPAA. The FTC’s updated Health Breach Notification Rule reaches health apps and similar technologies that fall outside HIPAA; if your practice uses consumer‑facing tools, confirm which regime applies. (ftc.gov)

Concrete examples (and what would have helped)

  • Behavioral health provider. Deer Oaks resolved OCR findings after failing to conduct a HIPAA risk analysis before investigation—underscoring that even smaller providers must keep a current, tailored analysis. A living risk register with owners and deadlines would have helped. (hhs.gov)

  • Public hospital. Guam Memorial Hospital’s ransomware matter resulted in an OCR settlement focused on Security Rule compliance and risk analysis—documentation of backups, recovery testing, and user access hygiene can change the trajectory of these cases. (hhs.gov)

  • Phishing‑driven breach. PIH Health settled after email compromises exposed ePHI. Phishing‑resistant MFA, role‑based access, and rehearsed response timelines are increasingly table‑stakes. (hhs.gov)

  • Small imaging provider. Vision Upright MRI’s unsecured server breach shows why “we’re small” is not a defense; OCR expects the same core safeguards scaled to size and risk. (hhs.gov)

  • Business associate exposure. OCR’s settlement with Health Fitness Corporation reinforces that BAs must meet Security Rule requirements—and that covered entities should verify, not assume, BA security. (hhs.gov)

Immediate action items for your team

  • Refresh your risk analysis. Inventory systems and data flows, rank threats, and tie each risk to a remediation owner, plan, and due date. Keep evidence of progress and periodic review. (hhs.gov)

  • Map your vendors and your PHI. Identify every vendor touching PHI. Confirm a current BAA with security provisions, define escalation and termination rights, and document due diligence (e.g., SOC 2s, pen‑test summaries, corrective‑action follow‑ups). (hhs.gov)

  • Run a tabletop exercise. Simulate a ransomware‑on‑EHR day. Assign roles, rehearse decisions (is it a reportable breach? when do we notify?), and time every step. Capture lessons learned and update your plan—then do it again. (nist.gov)

  • Implement CPG “essentials.” Confirm phishing‑resistant MFA, tighten email security and endpoint protection, test backups, and set vendor cyber requirements. These controls are the first questions you’ll face after an event. (hhscyber.hhs.gov)

  • Pre‑script communications. Maintain current notice templates for patients, HHS, media (when applicable), and insurers so you can meet HIPAA’s 60‑day notification rule even under pressure. (hhs.gov)

Vendor vulnerabilities: how to show active oversight

  • Before onboarding: require a BAA with security obligations; review security reports and remediation plans; define breach cooperation duties and timelines; and reserve rights to audit or terminate for material security failures. HHS’s sample BAA provisions are a helpful starting point. (hhs.gov)

  • During the relationship: track access, service changes, and attestations; rehearse vendor‑failure scenarios in your tabletop; and align oversight with HHS’s CPG focus on vendor/supplier security. (hhscyber.hhs.gov)

A note on tracking technologies In June 2024, a federal court vacated OCR’s revised bulletin on online tracking technologies as beyond the agency’s HIPAA authority; HHS did not appeal. That ruling addressed public‑facing webpages, not your HIPAA duties in authenticated environments such as patient portals. Review where pixels/analytics run, what data they collect, and whether you need a BAA or patient authorization. (aha.org)

Why this all matters Between CSF 2.0’s renewed emphasis on governance and OCR’s steady drumbeat of Security Rule settlements, 2026 will reward practices that can show specific, repeatable security outcomes—aligned to modern frameworks and backed by documentation. Your performance on the worst day often matters as much as the policies in your manual. (nist.gov)

We will continue to monitor these developments and share updates. If you’d like help assessing HIPAA readiness, updating incident plans, or tightening vendor contracts and oversight, contact our healthcare team at (212) 668-0200 or info@mdrxlaw.com.