HIPAA governs how providers, health plans, and their vendors handle protected health information, and HHS Office for Civil Rights enforcement continues to focus on risk analysis failures and unsecured PHI. This hub covers rule changes, settlements, and the guidance that tells covered entities what OCR actually expects.

Ransomware

When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works

September 14, 2026

HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.

Read more →
HIPAA

What OCR's Right of Access Settlements Say About Getting Your Own Medical Records

September 1, 2026

In 2019 the Office for Civil Rights announced that enforcing a patient's right to their own records would be an enforcement priority. The resulting settlements had reached 41 cases by September 2022 and have continued since. Read together they describe an unusually repetitive fact pattern: a person asks for records, months pass, and the file arrives only after a federal complaint.

Read more →
HIPAA

HHS Has Proposed the First Real Rewrite of the HIPAA Security Rule Since 2013

September 1, 2026

In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.

Read more →
Consumer Health Data

Health Data Laws That Reach the Companies HIPAA Never Touched

August 24, 2026

HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.

Read more →
HIPAA

HIPAA in Practice: The Privacy, Security and Breach Notification Rules

August 12, 2026

HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.

Read more →
HIPAA

The HIPAA Security Rule Requirement That OCR Cites Most Often

August 12, 2026

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.

Read more →

Related pages