HIPAA governs how providers, health plans, and their vendors handle protected health information, and HHS Office for Civil Rights enforcement continues to focus on risk analysis failures and unsecured PHI. This hub covers rule changes, settlements, and the guidance that tells covered entities what OCR actually expects.
Ransomware
September 14, 2026
HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.
Read more →
HIPAA
September 1, 2026
HHS finalised a rule in April 2024 restricting disclosure of information about reproductive health care to law enforcement and in litigation. In June 2025 a federal judge in Amarillo vacated nearly all of it, holding HHS had exceeded its authority. The government did not appeal, and the Fifth Circuit dismissed the intervenors' appeal in September 2025.
Read more →
HIPAA
September 1, 2026
In 2019 the Office for Civil Rights announced that enforcing a patient's right to their own records would be an enforcement priority. The resulting settlements had reached 41 cases by September 2022 and have continued since. Read together they describe an unusually repetitive fact pattern: a person asks for records, months pass, and the file arrives only after a federal complaint.
Read more →
HIPAA
September 1, 2026
In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.
Read more →
Consumer Health Data
August 24, 2026
HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.
Read more →
HIPAA
August 12, 2026
HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.
Read more →
HIPAA
August 12, 2026
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.
Read more →