- VanRein Compliance
- Posts
- What We Heard — HHS OCR and NIST Wrap-Up
What We Heard — HHS OCR and NIST Wrap-Up
We spent Sep 2–3 with HHS OCR and NIST on Building Assurance through HIPAA Security.
We blocked two days for Safeguarding Health Information: Building Assurance through HIPAA Security 2026 — HHS OCR and NIST ITL on the same stream.
The room was full. The livestream was fuller. We came to listen. We're not going to send you what we wish they'd said. Here's what we actually heard.
Three things landed hard.
1. OCR told you where it is looking
Paula Stannard named four enforcement priorities:
HIPAA right of access, including a sharper focus on parental access to children's records
Risk analysis and risk management (not just the analysis checkbox)
Hacking and ransomware enforcement
42 CFR Part 2 (substance use disorder record confidentiality)
That is not a vibe. It is a map of what is drawing actions.
OCR also put a slide of recent settlements on the table, spanning July 2025 through August 2026. Named organizations. Real dollars. From ambulatory surgery centers and imaging groups to health systems and benefits plans. The point is not the logo list. The point is: these are not hypotheticals.
If your risk analysis is missing, stale, or "executive summary only," you already know what OCR keeps finding. They said it again. Thorough means you can trace ePHI as it enters, moves, and leaves: uploads, EHR hops, backups, logs, email, fax, file transfer, collaboration tools, and disposal. Heat maps are not the work product.
2. The FTC track is not OCR, and buyers recognize the names
Separately from HIPAA OCR actions, the FTC has been active on health and sensitive data cases that show up in consumer headlines: GoodRx, BetterHelp, Cerebral, Monument, Hims & Hers, fertility and period-tracking apps, camera vendors, genetic testing firms. Treat those carefully in copy: alleged/complaint language, public-record framing. The compliance lesson for our readers is simpler than the brand drama:
If you touch sensitive health information, "we thought we were only marketing" is not a defense. BAAs, disclosures, and what you tell people about where their data goes still matter, including when the platform feels like an app, not a covered entity.
3. The threat picture got more specific
Health-ISAC and HHS briefings did not talk in abstractions. Named state-linked actor families ("Typhoon" groups in Microsoft's naming), DPRK IT-worker fraud aimed at remote hiring, dangling DNS and adversary-in-the-middle phishing kits among the top targeted alerts, plus newer social-engineering tricks like ClickFix and quishing.
Medical devices stayed on stage too: legacy gear with hard-coded passwords, long patch lag after a Microsoft Tuesday, exposed imaging systems. AI did not get a free pass. OCR was direct that the Security Rule already applies to AI tools that touch ePHI. BAA before the vendor. Risk analysis that includes poisoning, leakage, and prompt injection. NIST's AI RMF is voluntary guidance (Govern / Map / Measure / Manage); it is not a nap from HIPAA.
What did not change
The proposed Security Rule rewrite (RIN 0945-AA22) is still a proposal. July 2027 is HHS's planning estimate for final action on the Unified Agenda. It is not a statute. It can move again. Encryption moving from addressable to required is still "would," not "is."
The current Security Rule remains in force. OCR did not take Labor Day off the books. Neither did the people who want your proof.
You still need:
A current inventory of systems and vendors that touch ePHI
MFA on the platforms that actually hold that data
A backup and incident-response plan you have tested, with the date written down
Signed BAAs with a last-reviewed date
A risk analysis that is real work product, not a slide for the board
What we want you to do this week
Pick one. Do not stack five:
Name the owner of your risk analysis in writing: person, next date, evidence location.
Pull the vendor list. Mark anything with no BAA last-reviewed date.
Restore one backup. Write how long it took.
List every AI tool in use that can see PHI. If it is not on the inventory, put it there before you write another policy.
Two days of federal briefings didn't hand anyone a shortcut. They handed us a clearer picture of where the scrutiny is landing, and confirmed that the fundamentals nobody wants to redo are still the fundamentals that matter most. The rules around AI, quantum, and enforcement priorities will keep shifting. Inventory, MFA, tested backups, and a real risk analysis won't stop being the baseline anytime soon.
If you want a second set of eyes on which of those is your real gap, book 30 minutes with us. No deck. A punch list you can use this quarter.









Reply