
Two notable HIPAA items from HHS-OCR
HHS-OCR ramps up HIPAA enforcement: phishing settlement spotlights risk analyses, Security Rule gaps and urgent 2026 Part 2 NPP updates.
As March begins, two notable items that were released in February by the U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR). First, HHS-OCR announced HIPAA enforcement action related to a phishing attack and the lack of fundamental Security Rule safeguards, including an annual risk analysis. Second, HIPAA Notice of Privacy Practices (NPPs), which now include 42 CFR Part 2 - The Confidentiality of Alcohol and Drug Abuse Patient Records regulations - (Part 2) were required to be updated by February 16, 2026 and HHS-OCR recently
On February 19, 2026,
As HHS-OCR highlighted in its press release, knowing the ingress and egress of data, ensuring that system activity is reviewed regularly, encrypting data both at rest and in transit and providing workforce members HIPAA training that is specific to the organization and curtailing or highlighting how risks emerge in different roles and departments can mitigate the risk of attack and an enforcement action. Additionally, organizations should consider the likelihood of a class action lawsuit.
In addition to the February 16, 2026 deadline to revise NPPs to align Part 2 with HIPAA, HHS-
Importantly,
In sum, these two notable items underscore the importance of re-reading the February 2024 Final Rule to update training and policies and procedures, in addition to NPPs. They also underscore HHS-OCR’s continuing commitment to enforcing HIPAA and urging both covered entities and business associates to take proactive measures, which have been required for over 20 years by the HIPAA Privacy Rule and Security Rule.
Related to this article









