HIPAA Tip: What Are You Waiting For?

NOW is the time to finish the Disaster Recovery Plan. TODAY is the day to review policies and procedures that have been pushed to the side for the last two years. Before Q4 2026 book the annual Security Risk Analysis (SRA).

What are you waiting for? If a breach occurs can you produce the required last three years of SRAs? Can you show you have been updating policies and procedures which outline the organization’s position on what is expected for computer security measures, facility access and responsibilities with key codes, badges, and paper PHI? Can you provide documentation that all management and staff have reviewed and signed off on these policies?

Here are a few reminders:

  • A breach of 500+ individuals must be submitted to HHS Office for Civil Rights. Federal law requires notification to media outlets (press release) to include contact information, which necessitates a toll-free call center.
  • A settlement will be included in the resolution where the organization must pay a fine for violations of the HIPAA Privacy and Security Rules.
  • Two- or three-year corrective action plan (CAP) monitored by OCR will follow to scrutinize the healthcare business’ operations, ensuring compliance to the HIPAA Rules.
  • The reputation of the organization will certainly be blemished, and loss of business is a guarantee.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.