Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: What Has and Hasn’t Changed with HIPAA

Major HIPAA Developments in 2024

The answer to the million dollar question?! A lot of changes came through in 2024:

TL;DR – What Changed with HIPAA in 2024:

  • Change Healthcare breach: 190M individuals affected, widespread healthcare disruptions
  • OCR Risk Analysis Initiative: Addressing “failure to conduct accurate risk analysis” violations
  • HIPAA Security Rule NPRM: Proposed modifications to strengthen ePHI protections
  • 2024-2025 OCR Audits: 50 entities reviewed for hacking/ransomware defenses
  • Heightened focus: Cybersecurity training, 2FA/MFA, encryption, password policies
  • Key takeaway: Robust security posture is now essential to beat threat actors

The Change Healthcare Cyber Attack

Change Healthcare Cyber Attack. In February 2024, the cyber attack resulted in the exfiltration of personal and medical information from an estimated 190 million individuals, leading to widespread disruptions in healthcare billing and operations for healthcare providers. Every hospital in the country felt the impact either directly or indirectly, to pay clinician and care team salaries, acquire necessary medicine supplies, pay for critical physical security, dietary and environmental services contract work.

OCR’s Risk Analysis Initiatives

Risk Analysis Initiatives. Office for Civil Rights (OCR) created this initiative due to the overwhelming number of violations in HIPAA breaches from a “failure to conduct an accurate and thorough risk analysis,….” cited with fines and corrective action plans. OCR found that if conducted the Risk Analysis was actually a “gap analysis” and contained insufficient inventory of the entity’s ePHI.

HIPAA Security Rule Notice of Proposed Rulemaking

HIPAA Security Rule Notice of Proposed Rulemaking. OCR issued the Notice of Proposed Rulemaking (NPRM) to modify the HIPAA Security Rule to strengthen overall protections for ePHI, and to better address ever-increasing cybersecurity threats to the health care sector.

2024-2025 OCR HIPAA Audits

OCR Audits. The 2024-2025 HIPAA Audits will review 50 Covered Entities’ and Business Associates’ compliance with selected provisions of the HIPAA Security Rule most relevant to hacking and ransomware attacks, giving OCR the opportunity to examine mechanisms for compliance and discover risks and vulnerabilities that may have not been revealed by enforcement activities.

The Path Forward for Healthcare Security

There is no certainty that anything will happen with the NPRM, either changes or approvals, and whether the HIPAA Security Rule will see updates after all these years. What hopefully changed for Covered Entities and Business Associates is their heightened awareness to educate all team members on cyber security training and the use of additional security measures (2FA/MFA, encryption, stricter password policies). The healthcare industry must embrace a robust security posture in order to start beating the threat actors at their own game.

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.