Monthly Tips Roundup

We’ve curated our weekly tips shared on LinkedIn every Tuesday into this monthly blog for your convenience.

September 1, 2026

Advice from NIST For Healthcare Providers

Core NIST Guidance for Healthcare

  • Govern & Manage Risk: Use NIST SP 800-39 for ongoing, organization-wide risk management instead of one-time annual reviews. Implement NIST SP 800-66 Rev. 2(opens in new tab) to map HIPAA Security Rule compliance to modern technical controls.
  • Identify Assets: Catalog all connected medical devices, IoT systems (like wireless infusion pumps via NIST SP 800-213), and third-party software vendors to eliminate hidden blind spots.
  • Protect Systems: Enforce Multi-Factor Authentication (MFA), strict role-based access controls, and data encryption for all electronic Protected Health Information (ePHI). 

Key Action Steps for Providers

  • Map to HIPAA: Align NIST practices with the HIPAA Security Rule to satisfy legal standards while building deeper security.
  • Segment Networks: Isolate non-clinical operational technology (like guest Wi-Fi, HVAC, or building management) away from critical clinical systems.
  • Manage Vendor Risk: Regularly evaluate third-party software and legacy medical device security before connecting them to the main enterprise network.

August 25, 2026

Summer is the Best Time To…

Get your Compliance House in order. How does that old saying go: “There’s no time like the present!”

Think of the following as your Gap Assessment – the review between the annual Risk Analysis.

  • Start with the required Administrative, Physical and Technical Safeguard(s) policies under the HIPAA Security Rule. Are all policies along with the organization’s procedures in place? Do they need updating and/or editing?
  • Walk through the facility, and if there are multiple locations, visit those as well. What physical security measures can be tightened? Have older medical records been reviewed and purged per State retention regulations? Is it time to change alarm codes if multiple staff share the code? Could the auto-lock for computers be shortened (10-15 minutes)?
  • Review users in all systems and applications containing ePHI i.e., EMR, Practice Management, billing, medical devices, business email accounts, Windows Active Directory, to ensure any staff member no longer with the organization has been disabled. At the same time confirm current roles in these systems/applications reflect their position and privileges (minimum necessary rule).
  • Set up a meeting with your IT Team to evaluate stronger security measures that may have been recommended after the annual Risk Analysis: Endpoint Detection Response (EDR) solution, multifactor authentication for remote and email access, annual Vulnerability Scan, security monitoring for systems and applications containing ePHI.

August 18, 2026

Don’t Give Up!

From Forbes magazine on July 28, 2026: Last week, U.K. based healthcare billing software provider Craneware announced that it had been impacted by a serious cybersecurity event, indicating that a significant amount of customer and employee data was compromised. https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/(opens in new tab)

According to Becker’s “the U.S. recorded 1,803 total data compromises across all sectors in the first half of 2026, affecting an estimated 471.2 million individuals — a total that already exceeds all of 2025’s 297.5 million victim notices in just six months.” https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/healthcare-data-breaches-climb-to-281-in-1st-half-of-2026-report/(opens in new tab)

𝗠𝗶𝗻𝗻𝗲𝘀𝗼𝘁𝗮 𝗪𝗮𝘁𝗲𝗿 𝗨𝘁𝗶𝗹𝗶𝘁𝗶𝗲𝘀 (𝗝𝘂𝗹𝘆 𝟮𝟬𝟮𝟲): More than 30 municipal water and wastewater systems across Minnesota experienced coordinated operational technology (OT) disruptions and automated control failures.

𝗦𝘁𝗿𝘆𝗸𝗲𝗿 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝘆𝘀𝘁𝗲𝗺𝘀 (𝗠𝗮𝗿𝗰𝗵 𝟮𝟬𝟮𝟲): Medical device maker Stryker suffered a cyberattack on its Microsoft environments, disrupting shipping and order processing after factor resets hit over 200,000 corporate devices.

Take steps now to further protect the organization’s environment and patient data. Follow recommendations from CISA and their Healthcare and Public Health (HPH) Cybersecurity Performance Essential and Enhanced Goals: HPH

Cybersecurity Performance Goals: https://hhscyber.hhs.gov/cybersecurity-performance-goals.html(opens in new tab)


August 11, 2026

Listen to HHS Office for Civil Rights

HHS Office for Civil Rights (OCR) recommends that regulated entities, including health care providers, health plans, health care clearinghouses, and business associates take the following steps to mitigate or prevent cyber-threats:

  • Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
  • Annually conduct, and update as needed, a Risk Analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the Confidentiality, Integrity, and Availability (CIA Triad) of ePHI.
  • Ensure audit controls are in place to record and examine information system activity.
  • Implement regular review of information system activity.
  • Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
  • Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
  • Incorporate lessons learned from incidents into the organization’s overall security management process.
  • Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino(opens in new tab)
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.