Photo of Brent Hoard

Clients rely on Brent’s unique legal and consulting experience to find practical solutions to today’s complex and evolving privacy and data protection issues.

Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.

Key Points

  • OCR’s proposed 2025 HIPAA Security Rule update has a projected finalization date of July 2027, moved from the original May 2026 target and classified as a “long-term action” in the OMB Unified Agenda.
  • The 2024 Change Healthcare ransomware attack — the largest protected health care data breach in U.S. history — has renewed pressure on OCR to modernize the HIPAA Security Rule’s cybersecurity requirements.
  • A coalition of more than 100 health care organizations, led by CHIME, sent a December 2025 letter to HHS Secretary Robert F. Kennedy Jr. urging full withdrawal of the proposed Security Rule update, citing its deregulatory inconsistency and compliance burden.
  • Prior HIPAA rulemaking history — including the 2013 Omnibus Rule and the court-vacated 2024 Reproductive Health Care Privacy Rule — suggests finalization in revised or consolidated form is more likely than adoption of the proposed rule as written.

In this episode of The Consumer Finance Podcast, Chris Willis is joined by Troutman Pepper Locke Partners Stefanie Jackman and Brent Hoard to take a close look at the world of medical debt collection. The discussion covers how HIPAA applies to medical debt, what it really means to be a “business associate,” and common privacy challenges that can turn routine collection efforts into regulatory headaches. They also focus on key federal and state debt collection regimes, including the FDCPA, the No Surprises Act, and increasingly complex credit reporting requirements. The group provides insight on collection strategies for health care providers and third-party collectors that are both compliant and workable in practice. For anyone handling medical-related receivables, this episode serves as a practical guide to safeguarding patient information, maintaining tax-exempt status, and enhancing collections while staying within regulatory boundaries.

Key point: Tennessee’s new law prohibits parties that develop or deploy AI systems from advertising or representing to the public that the AI systems can act as a qualified mental health professional. 

On April 1, 2026, Tennessee Governor Bill Lee signed SB 1580 into law, and it will go into effect on July 1, 2026. The new law is short — less than one page — but has potentially significant consequences given that it includes a private right of action.

In the following post, we provide an overview of the new law.

In Part One of this FAQ series, we break down Virginia’s Senate Bill 754, Consumer Protection Act; prohibited practices, etc., reproductive or sexual health information (Act), which amends the Virginia Consumer Protection Act (VCPA). The law goes into effect on July 1. Overall, given the broad definitions used in the Act, the law likely regulates organizations that are not traditional health care companies, and goes beyond traditional health information.