For Clarity’s Sake: Feedback on Recent OCR Recommendations

New Rule OCR Recommendations Clarified

OCR just signaled where HIPAA enforcement is heading and healthcare organizations should take note. In an April 23, 2026 news release re four ransomware investigation settlements, the OCR outlined 8 cybersecurity recommendations for covered entities and business associates. Learn more>

You Have Time, HIPAA’s Security Rule Hasn’t Changed Yet

NPRM Security Rule proposed

You’re fine, really. No need to panic. Yes, the NPRM is [finally] progressing. BUT – it’s not yet time to overhaul HIPAA Security Policies & Procedures, or buy new tools. Read my latest article to learn why (and DM me if you’d like a free copy of my latest webinar material relating to the NPRM). Read on to learn more.

Proposed HIPAA Rule Changes – Presentation Clip

HIPAA Changes HCCA webinar

I recently had the opportunity to present an HCCA continuing education webinar on the NPRM related to the proposed changes to the HIPAA Rule. I invite you to watch the 5-minute clip here, where I talk about proposed patching expectations and touch on the Security Risk Analysis’s emphasis. Here at Apgar and Associates, we’re scheduling … Read more

What is Network Segmentation & Why does it matter in Cybersecurity?

network segmentation cybersecurity

Introduction: The Security Rule NPRM modifies numerous administrative safeguards and introduces several new technical safeguard requirements. One of those new technical requirements involves network segmentation. Our colleague Liam Dwyer explains what network segmentation is in this post.  When developing a strong cybersecurity program, particularly one that needs to support privacy and security compliance requirements, you’ll … Read more

Vendor and Supplier Privacy & Security Questionnaire

vendor supplier security risk checklist

Early last year, I posted an article about Vendor Risk. One of the items that got a lot of attention was the Questionnaire. I’m sharing it again here – no paywall, insistence to provide contact information, etc. Just something that may be helpful to you and your organization as you navigate risk management (along with … Read more

Policies & Procedures: The Rulebook that Applies to Everyone

policies procedures rulebook that applies to everyone

Regardless of what happens with the current NPRM, the HIPAA Security Rule still stands, just like it has since 2005.  I feel as though the OCR has clearly demonstrated that their focus on compliance with the Security Rule, particularly in regard to a comprehensive Security Risk Analysis, is not a passing fancy. So, treat your … Read more

If the NPRM Becomes Law, Will Your Security Risk Analysis Hold Up?

NPRM Carrot with Stick Security Risk Analysis

Let’s look at the historical approach from OCR when it comes to HIPAA Security Rule enforcement. Since 2005, the Office for Civil Rights (OCR) has relied on the carrot approach rather than the stick. The existing Security Rule defines risk analysis as the first required implementation of the first required standard. But the existing language … Read more

Change Healthcare Lessons Learned: What happened to Basic Security Controls?

Change Healthcare Lessons learned basic security

The Wall Street Journal scoop from April 22nd about what led to the Change Healthcare breach came after HHS created an FAQ about the incident. The scoop summary pulled these top 3 points about basic security: Compromised credentials to log into an application that allowed Change staff members to remotely access the network Multifactor authentication … Read more