Monthly Tips Roundup
We’ve curated our weekly tips shared on LinkedIn every Tuesday into this monthly blog for your convenience.
Risk Assessment Process for Breaches
A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI. An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless the Covered Entity or Business Associate demonstrates (based on a risk assessment) that there is a low probability that the PHI has been compromised. When a breach of unsecured PHI occurs, the Rules require your organization to notify affected individuals, the Secretary of HHS, and in some cases, the media.
When a suspected breach of PHI has occurred, first conduct a risk assessment to examine the likelihood that the PHI has been compromised. In order to demonstrate a breach has not compromised PHI, your organization must thoroughly assess at least the four required elements:
- The nature and extent of the PHI involved in the use or disclosure, including the types of identifiers and the likelihood that PHI could be re-identified. NOTE: if the organization has a breach of encrypted data (standard encryption specifications), it would not be considered a breach of unsecured data.
- The unauthorized person who used the PHI or to whom the disclosure was made.
- The likelihood that any PHI was actually acquired or viewed (audit trail).
- The extent to which the risk to the PHI has been mitigated (passwords, encryption keys changed).
On a last note, be diligent and proactive. Conduct an annual Risk Analysis for your organization to identify risks and vulnerabilities before they turn into a security incident, or worse, a breach.
Compliance Checklists
In my opinion we overthink and create our own roadblocks when trying to achieve HIPAA Compliance. Instead of sitting down for the day after your annual Security Risk Analysis (SRA) has been completed and delivered to resolve the list of risks and vulnerabilities, why not address the following categories – one each month?
- Policies. Don’t tackle the whole manual all at the same time. Choose the most important to begin with: Acceptable Use of Information and Assets, Sanction Policy, Remote/Work from Home Policy. Review carefully, update if necessary and present to all staff for sign-off and confirmation.
- Procedures. Specific company procedures would include the Facility Access Policy/Facility Security Plan, Background Checks, Termination/Exit Interviews – all of which would be unique to your organization and potentially change frequently.
- EDR Solutions. Check with your IT team to ensure Endpoint Detection Response (EDR) solutions are deployed on all business devices and have replaced outdated antivirus software.
- Vulnerability Scans. Don’t consider this an option in your annual budget. Vulnerability Scans identify weaknesses in systems containing ePHI, maintaining an auditable compliance posture.
- Disaster Recovery Plan / DRP Testing. Extremely important (and also a HIPAA requirement) to put together a plan on how the organization will continue running in the event of a disaster, which could be on a vendor level (EMR, PM). Review as environments change and test the plan with all staff!”
HIPAA Security Rule Update
In the recently released Fall 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, HHS moved the proposed HIPAA Security Rule amendments (RIN 0945-AA22) to its Long-Term Actions agenda and identified July 2027 as the agency’s anticipated timeframe for final action. Although Unified Agenda dates are planning estimates rather than binding deadlines, placement on the Long-Term Actions agenda generally indicates that HHS does not anticipate issuing a final rule within the next 12 months.
Why the delay? HHS may be continuing to evaluate more than 4,000 public comments to the 2025 Notice of Proposed Rulemaking (NPRM), showing widespread interest across the healthcare industry. Another possibility could be that HHS is considering modifying portions of the proposal. They may determine that certain provisions – network mapping, expanded encryption requirements, more prescriptive risk analyses, frequent vulnerability testing – should be revised, delayed, or customized before publication of the final rule.
Do NOT step back and relax efforts within your organization for cybersecurity and security awareness steps. OCR’s enforcement actions continue to focus on fundamental compliance obligations, including conducting accurate and thorough risk analyses, implementing appropriate security measures, managing vendor risk, training workforce members, and responding to known vulnerabilities.
Make HIPAA Compliance a Team Effort
Whether your organization is a Hospital, Ambulatory Surgery Center or a two-doctor practice, achieving HIPAA compliance should not fall on one individual simply because they are the designated Security or Privacy Officer.
Engaging multiple staff members and management and creating a team supports compliance and reminds all involved of the importance of patient privacy and security of medical data.
How can you go about this:
- Rotate staff members to present at monthly or quarterly meetings on a HIPAA or cybersecurity topic. This could include reviewing red flags in phishing emails, to the importance of responding in a timely manner to a patient’s request for their medical records, or the company’s policy on workstation security.
- Designate one coworker each month to serve as the “HIPAA Police”: making sure staff are logging out of their computers at the end of the business day, putting away all papers that contain PHI (in desks, cabinets, medical records rooms), and maintaining a clean desk policy, and the ultimate – NO passwords posted anywhere!
- Enlist staff who love to write and review. Have them go through some of the older or outdated policies and procedures for the organization and let them offer up changes and suggestions. You may be surprised at how willing the team will be to support compliance efforts.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.