OCR HIPAA Enforcement Priorities in 2026 and Risk Management Recommendations

Earlier this month, the Director of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) confirmed in an interview with Rachel Klugman Seeger of North Country Communications some of OCR’s key HIPAA enforcement priorities in 2026. The enforcement initiative targeting the HIPAA Rights of Access is continuing, and has so far resulted in more than 50 settlements and civil monetary penalties. These enforcement actions stem from complaints from individuals who have been denied access to their health records or have not been provided with a copy of their protected health information within the 30 days allowed.

The enforcement initiative targeting the risk analysis provision of the HIPAA Security Rule will also continue. This is the most commonly identified HIPAA Security Rule violation resulting in financial penalties for noncompliance. This enforcement initiative will also evolve, as OCR will expand this initiative to also cover risk management. In addition to ensuring that HIPAA-regulated entities conduct comprehensive, organization-wide risk analyses, OCR will require documentation demonstrating that identified risks and vulnerabilities have been managed and reduced to an acceptable level. OCR is also preparing to start enforcing the recently updated Part 2 regulations, violations of which are subject to the same penalty amounts as HIPAA violations.

Given OCR’s HIPAA enforcement plans in 2026, HIPAA-regulated entities should give careful consideration to OCR’s Q1, 2026 cybersecurity newsletter, which focuses on areas of risk management that HIPAA-regulated entities should focus on – hardening system security and reducing the attack surface. System hardening is the term used for customizing electronic information systems to address vulnerabilities and weaknesses and reduce the attack surface to make it more difficult for malicious actors to infiltrate information systems and access patient data. While the term is not specifically mentioned in the HIPAA Security Rule text by name, system hardening is necessary to reduce risks and vulnerabilities to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI).

OCR reminds regulated entities that the risk analysis provision of the HIPAA Security Rule requires risks and vulnerabilities to all ePHI to be identified, which includes identifying risks and vulnerabilities to ePHI from unpatched software. To aid vulnerability identification, regulated entities can sign up for vulnerability alerts from manufacturers and vendors, participate in an information sharing and analysis center (ISAC) or an information sharing and analysis organization (ISAO), conduct vulnerability scans, and monitor authoritative sources for vulnerabilities, such as CISA’s Known Exploited Vulnerability Catalog and the NIST National Vulnerability Database.

To ensure that risks are identified across the entire organization, risk analyses should be based on a comprehensive, accurate, and up-to-date IT asset inventory. Policies and procedures must be developed for addressing identified vulnerabilities, which require regular updates of software and firmware, prompt patching, and the implementation of mitigations when patches for known vulnerabilities are not yet available.

Unneeded software, services, and unused networked devices increase the risk of compromise and should be disabled or removed as part of risk management processes. That includes games, social media, utilities, laptops, smart phones, and unused accounts and services, including unnecessary services and software automatically installed with operating systems. Oftentimes, when operating systems and software are installed, accounts are created. These accounts may be necessary; however, they often have default passwords. If those accounts are required, the default passwords should be changed to strong, unique passwords. Removing unnecessary software and accounts will help to reduce the attack surface and the risk of vulnerabilities in software that cannot be patched.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

The third key area of system hardening involves enabling and configuring security measures, especially those related to access controls, encryption, audit controls, and authentication, as required by the HIPAA Security Rule. Many data breaches are reported each year that are due to misconfigurations and missing security software and features.

“System hardening and security baselines can be an effective means to enhance security, and for regulated entities to protect ePHI. However, defining, creating, and applying system hardening techniques is not a one-and-done exercise. Evaluating the ongoing effectiveness of implemented security measures is important to ensure such measures remain effective over time,” explained OCR. “The periodic review and modification, as needed, of security measures implemented under the HIPAA Security Rule is a requirement to maintain protection of ePHI.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/