In an April 23, 2026, news release that discusses four ransomware investigation outcomes, OCR lists its prevention and mitigation recommendations for cyber threats. The agency advises that covered entities – healthcare providers, health plans, healthcare clearinghouses – and business associates that fall under the HIPAA Security Rule take the 8 actions.
We’re providing feedback on these. The reason is that while a number of recommendations are based on the current Rule, others are more explicitly stated in the New Proposed Rulemaking (NPRM), which has not yet been finalized. So, for clarity, here goes (in order of their appearance in the OCR release).
- Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
- While this is not explicitly stated in the current Rule, it has historically been part of the NIST guidance on how to conduct a Security Risk Analysis. However, it is explicitly stated in the proposed new Rule.
- Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Both parts of this recommendation appear in the requirements of the current Security Rule, and both parts of the recommended activities are enhanced in the proposed new Rule.
- Ensure audit controls are in place to record and examine information system activity.
- Implement regular review of information system activity.
- Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
- 3, 4 & 5: Just like risk analysis and risk management, these activities appear in the requirements of the current Security Rule, and are enhanced in the proposed new Rule.
- Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
- In the current Rule, this is an addressable spec; i.e., implement this or an equivalent, depending on your operations. Here, OCR is saying “implement this” just like they have for the past 10 years. In the new proposed new Rule, encryption is required of data in transit and at rest.
- Incorporate lessons learned from incidents into the organization’s overall security management process.
- This is not in the current Rule. It is implicit for good information security. However, in the proposed new Rule, it is explicitly defined.
- Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
- Regular HIPAA training is in the current Rule. For greater understanding, make it applicable not only to the organization’s operations, but also to your workforce’s specific duties. In other words, don’t merely expound on the history of HIPAA, make it relevant to the individual’s specific job function.
In closing, note that this press announcement is different from most of the recent we’ve seen coming from the OCR. With the current director, maybe take this as a sign of what we should start thinking of – we’ve gotten this far in the NPRM process. So why not do readiness?