Photo of Emma Trivax

Emma represents a wide range of health care providers, including physicians, management service organizations, dental service organizations, hospitals, clinical laboratories, skilled nursing facilities, ambulatory surgical centers, DMEPOS suppliers, and behavioral health providers.

Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.

Key Points

  • OCR’s proposed 2025 HIPAA Security Rule update has a projected finalization date of July 2027, moved from the original May 2026 target and classified as a “long-term action” in the OMB Unified Agenda.
  • The 2024 Change Healthcare ransomware attack — the largest protected health care data breach in U.S. history — has renewed pressure on OCR to modernize the HIPAA Security Rule’s cybersecurity requirements.
  • A coalition of more than 100 health care organizations, led by CHIME, sent a December 2025 letter to HHS Secretary Robert F. Kennedy Jr. urging full withdrawal of the proposed Security Rule update, citing its deregulatory inconsistency and compliance burden.
  • Prior HIPAA rulemaking history — including the 2013 Omnibus Rule and the court-vacated 2024 Reproductive Health Care Privacy Rule — suggests finalization in revised or consolidated form is more likely than adoption of the proposed rule as written.