• VanRein Compliance
  • Posts
  • OCR and NIST are on stage this week. The Security Rule you are under did not move.

OCR and NIST are on stage this week. The Security Rule you are under did not move.

We're at the HHS+NIST HIPAA Security conference. Here's what we're watching, and what still has to be true on Monday.


We're at HHS + NIST Conference this week.

HHS Office for Civil Rights and the NIST Information Technology Laboratory are hosting Safeguarding Health Information: Building Assurance through HIPAA Security 2026. September 2–3. NIST campus, Gaithersburg. 9:00am–4:00pm ET both days.

This is the office that enforces the Security Rule sitting next to the lab that writes the playbooks.

The current HIPAA Security Rule did not get a day off for the conference. OCR did not either. A proposed rewrite (RIN 0945-AA22) is still a proposal. The current 2026 agenda has final action as a July 2027 planning estimate. That is not a statute. It can move again.

What the official agenda is actually covering (NIST page, sessions marked tentative):

Wednesday 9/2: OCR welcome, health-sector threat briefing (H-ISAC), ASPR, an HHS cyber panel (OCR, ASPR, ARPA-H, ONC), post-quantum cryptography, privacy-enhancing technologies and genomic data, FTC health privacy/security, OCR HIPDC closeout.

Thursday 9/3: ONC / future of health IT, CFIUS and protecting health information, AI metrology in healthcare, medical device cybersecurity, the healthcare cybersecurity workforce, NIST AI Risk Management Framework, AI in healthcare, NIST CSF profiles / risk analysis / risk management.

We will not invent what someone said on stage. After sessions, we'll send what we actually heard.

What still has to be true when you get back to your desk:

You still need a current inventory of every system and vendor that touches ePHI.

You still need MFA on the platforms that hold that data, not just a policy that says you will.

You still need a backup and incident-response plan you have tested, with the date written down.

You still need signed BAAs and a last-reviewed date on each vendor.

Those are the same items auditors already ask for. Two days in Gaithersburg does not replace them.

If you want a second set of eyes on which of those is your real gap against this week's federal conversation, book 30 minutes with us. No deck. A punch list you can use this quarter.

Event:

We'll send more from the floor.

Rob and Dawn

Reply

or to participate.