For Clarity’s Sake: Feedback on Recent OCR Recommendations

New Rule OCR Recommendations Clarified

OCR just signaled where HIPAA enforcement is heading and healthcare organizations should take note. In an April 23, 2026 news release re four ransomware investigation settlements, the OCR outlined 8 cybersecurity recommendations for covered entities and business associates. Learn more>

You Have Time, HIPAA’s Security Rule Hasn’t Changed Yet

NPRM Security Rule proposed

You’re fine, really. No need to panic. Yes, the NPRM is [finally] progressing. BUT – it’s not yet time to overhaul HIPAA Security Policies & Procedures, or buy new tools. Read my latest article to learn why (and DM me if you’d like a free copy of my latest webinar material relating to the NPRM). Read on to learn more.

Policies & Procedures: The Rulebook that Applies to Everyone

policies procedures rulebook that applies to everyone

Regardless of what happens with the current NPRM, the HIPAA Security Rule still stands, just like it has since 2005.  I feel as though the OCR has clearly demonstrated that their focus on compliance with the Security Rule, particularly in regard to a comprehensive Security Risk Analysis, is not a passing fancy. So, treat your … Read more

If the NPRM Becomes Law, Will Your Security Risk Analysis Hold Up?

NPRM Carrot with Stick Security Risk Analysis

Let’s look at the historical approach from OCR when it comes to HIPAA Security Rule enforcement. Since 2005, the Office for Civil Rights (OCR) has relied on the carrot approach rather than the stick. The existing Security Rule defines risk analysis as the first required implementation of the first required standard. But the existing language … Read more

Reproductive Health & HIPAA: Key Takeaways from the New Rule

HIPAA New Rule Reproductive Health

With states weighing in on their own versions of how to handle reproductive health, there’s been confusion about what is and isn’t PHI when it comes to women’s healthcare since the overturn of Roe v Wade – the phrase “clear as mud” comes to mind. The Biden-Harris Administration’s “New Rule” for HIPAA helps clear the … Read more

Did you know? OCR has a new Risk Analysis Enforcement Initiative

HIPAA Summit 41 OCR risk analysis enforcement

View OCR Director Melanie Fontes Rainer’s presentation deck here. At the HIPAA Summit 41 in late February, she spoke on “spoke on recent OCR rulemakings, trends in health data breaches, recent HIPAA enforcement actions, new HIPAA enforcement initiatives (think risk analysis enforcement), best practices, and available cybersecurity resources to improve the protection and security of … Read more

How is OCR handling Women’s Reproductive Healthcare challenges as relates to PHI?

OCR PHI and reproductive health

With every new headline about women’s reproductive health, providers and patients have been left wondering what’s next legally. Will they be protected or prosecuted? The answer could be down to interpretation of HIPAA’s Privacy Rule. To that end, OCR’s taken the position of clarification and strengthening PHI protections from the HIPAA perspective. On April 12, … Read more

How can you assure remote employees’ HIPAA compliance?

remote workers hipaa compliance essentials

Remember the days of “Never gonna happen” when people wanted to work from home, even occasionally?  All the compliance focus was on what was happening at the office, or during business travel. Then came the pandemic, and the organizations that would have fallen on their swords to prohibit all remote work for coders, or customer … Read more

With Eyes Wide Open: How to Manage Vendor Compliance Liability

manage vendor compliance liability

Ever feel like your efforts to avoid compliance liability just turned into a game of hot potato? Is it a vendor responsibility (business associate or other third party) or yours? Consider cloud service providers (CSPs) as an example. Maintaining HIPAA compliance brings unique challenges to anyone working in or with the cloud. Don’t assume your … Read more

Are Business Associates Taking the Hit for CEs?

HIPAA and business associates

Looks like it could be a thing. All business associates (BAs), from super small, like small agency web hosting companies or medical transcriptionists, to large TPAs or data aggregation services, need to pay attention.  The recent settlement of Jelly Bean Communications LLC with the Department of Justice – yes, you read that right, the DOJ … Read more