Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.

Key Points

  • OCR’s proposed 2025 HIPAA Security Rule update has a projected finalization date of July 2027, moved from the original May 2026 target and classified as a “long-term action” in the OMB Unified Agenda.
  • The 2024 Change Healthcare ransomware attack — the largest protected health care data breach in U.S. history — has renewed pressure on OCR to modernize the HIPAA Security Rule’s cybersecurity requirements.
  • A coalition of more than 100 health care organizations, led by CHIME, sent a December 2025 letter to HHS Secretary Robert F. Kennedy Jr. urging full withdrawal of the proposed Security Rule update, citing its deregulatory inconsistency and compliance burden.
  • Prior HIPAA rulemaking history — including the 2013 Omnibus Rule and the court-vacated 2024 Reproductive Health Care Privacy Rule — suggests finalization in revised or consolidated form is more likely than adoption of the proposed rule as written.

Key point: Plaintiffs in Virginia have focused on a rarely tested state privacy statute with statutory damages that imposes notice-and-consent obligations on retailers that share or sell in-store customer data.

Most retailers have spent the last several years building their privacy compliance programs around the major comprehensive state privacy laws, such as Virginia’s Consumer Data Protection Act (CDPA), California’s Consumer Privacy Act (CCPA), and their counterparts in a dozen other states. A recent lawsuit filed in the Eastern District of Virginia is a reminder that older, narrower statutes can carry just as much litigation risk, and that the plaintiffs’ bar is actively looking for the next viable theory.

The statute at issue is the Virginia Personal Information Privacy Act (VPIPA). It has been on the books for decades. Until recently, however, it had produced exactly one lawsuit. That may be changing.

Key Point: A multistate coalition of 42 state AGs reached a landmark $150 million settlement with 23andMe over a 2023 data breach affecting 6.9 million customers, marking the largest AG multistate settlement involving consumer genetic data to date. This resolution signals heightened regulatory scrutiny of genetic data security practices and establishes a precedent for state enforcement authority in bankruptcy proceedings.

Key points: Troutman Pepper Locke’s Regulatory Investigations, Strategy + Enforcement (RISE) and Privacy + Cyber + AI practice groups worked with the firm’s innovation team using AI to collect and curate five years of data concerning state AG activities and actions related to privacy, security, and AI. This Regulatory

On June 26, 2026, Florida Attorney General (AG) James Uthmeier and Roku, Inc. announced a negotiated resolution of Florida’s enforcement action filed under the Florida Digital Bill of Rights (FDBR). Under the agreement, Roku will enhance its child protection features by giving parents greater control over their children’s streaming experience.

On June 30, 2026, New Jersey enacted legislation A5328 (P.L.2026, c.25), which will expose a broad swath of U.S. companies to data broker registration fees ranging from $5,000 to $1.5 million annually. The new legislation is not limited to data brokers in the conventional sense. It applies generally to any company that sells or licenses personal data of New Jersey residents, including those with direct customer relationships. Much of the law takes effect immediately, so companies should begin reviewing the requirements now to comply.

Key point: Amendments to California Senate Bill (SB) 690 would foreclose private rights of action for pen register and trap and trace law and apply to cases brought within previous two years.

The Privacy and Consumer Protection Committee of the California State Assembly heard testimony on support and opposition to SB 690 late Wednesday, July 1.

In the prior Part 4 of this series, we explained how CCPA cybersecurity audits are likely to surface in CalPrivacy and California Attorney General enforcement actions, and how that regime impacts governance and executive responsibility.