Highlights of the OCR/NIST HIPAA Security 2026 Conference

The Safeguarding Health Information: Building Assurance through HIPAA Security 2026 conference took place at the start of September 2026 at the NIST campus in Gaithersburg, Maryland. The event was co-hosted by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST).

Each year, the OCR and NIST use this conference to preview enforcement priorities, publish updated technical guidance, and surface where compliance programs continue to fall short. This year’s agenda spanned two full days and included briefings from OCR’s Director, threat intelligence from the Health Information Sharing and Analysis Center, four AI-focused sessions, and closing updates on the NIST Cybersecurity Framework’s Ransomware and Cyber AI Profiles.

Here is what you missed.

Day 1: Enforcement, Threat Intelligence, and Foundational Technical Risk

HHS Office for Civil Rights Welcome and Updates. Paula M. Stannard, Director of OCR, presented breach trend data spanning 2021 through 2025. Individuals affected by large breaches spiked to roughly 173 million in 2023 and 287 million in 2024 before falling to approximately 46 million in 2025, while the annual count of reported breaches stayed in a narrower band of 650 to 746. Stannard reviewed 13 enforcement actions dated between July 2025 and August 2026, ranging from $10,000 to $552,250, and detailed two standing initiatives: the Right of Access Initiative, with 55 completed enforcement actions and a new focus on parent and personal representative access, and the Risk Analysis and Management Initiative, with 14 completed enforcement actions and an expanded scope now covering risk management directly. On AI, Stannard stated that any new technology touching electronic protected health information (ePHI), including AI tools, must start with a current risk analysis, defined access controls, and a signed business associate agreement before the vendor’s service begins.

The presentation pushed for HIPAA-Covered Entities and their Business Associates to conduct HIPAA Security Risk Assessments, which was perhaps the most repeated idea throughout the conference.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Health Sector Cybersecurity Threat Briefing. Joshua Justice of the Health-Information Sharing and Analysis Center (H-ISAC) presented survey data from nearly 250 health sector security professionals. Ransomware, phishing, third-party breaches, data breaches, and zero-day exploits topped the 2025 threat list, while AI-enabled attacks entered the top five for the 2026 outlook for the first time. H-ISAC tracked 234 ransomware events against the health sector in 2026 to date, led by the groups Qilin, Gentlemen, INC Ransom, NightSpire, and Insomnia. Justice also covered nation-state activity, including North Korean IT worker fraud schemes, legacy medical device exposure following the 2025 end of Windows 10 support, and emerging social engineering tactics such as ClickFix and QR code “quishing.”

Administration for Strategic Preparedness and Response (ASPR) Cyber Updates. Dr. Brian Mazanec reported that ASPR’s cyber team triaged over 2,200 attacks against the health sector in 2025, with an average breach cost of $9.77 million. He noted that 85 percent of medical devices run on outdated legacy networks and pointed organizations to the HHS Cyber Gateway’s Cybersecurity Performance Goals (CPGs), divided into a baseline set of Essential Goals and a more advanced set of Enhanced Goals.

HHS Cybersecurity Activities and Resources Panel. Moderator Timothy Noonan led representatives from ASPR, ARPA-H, and ONC through the federal cybersecurity resources available to healthcare organizations, including ARPA-H’s DIGIHEALS and UPGRADE programs, which fund medical device security research.

Post-Quantum Cryptography Panel. NIST’s Dustin Moody reviewed the finalized post-quantum cryptography standards, FIPS 203, 204, and 205, alongside HQC, selected in 2025 as an additional algorithm. Executive Order 14412 sets a 2035 target for federal migration to quantum-resistant cryptography. Hospital CISOs from New York-Presbyterian and Children’s National discussed the practical difficulty of inventorying cryptographic assets in legacy healthcare environments ahead of that deadline.

Privacy Enhancing Technologies (PETs) and Genomic Data Threats. Dr. Gary Howarth and Dr. Christine Task demonstrated that simple redaction fails to protect identity, citing research showing 87 percent of the U.S. population can be re-identified using only three quasi-identifiers. They reviewed differential privacy, detailed in NIST Special Publication 800-226, and four vulnerability classes in federated learning: membership attacks, data reconstruction attacks, model inversion attacks, and model poisoning attacks.

FTC Health Privacy and Security Updates. Robin Rosen Spector reviewed FTC Section 5 enforcement actions against Hims & Hers, Monument, Cerebral, GoodRx, BetterHelp, Premom, Flo Health, Verkada, Vitagene, Chegg, SkyMed, and Henry Schein. Several cases centered on undisclosed data sharing with advertising platforms rather than a traditional data breach, and the SkyMed case specifically alleged that displaying an unearned HIPAA compliance seal was itself a deceptive practice.

HIPAA Enforcement Update from OCR. Timothy Noonan detailed three Security Rule settlements: OSF HealthCare ($552,250), Spencer Gifts, LLC ($450,000), and Star Group L.P. Health Benefits Plan ($245,000), each tied to a ransomware incident and a deficient risk analysis. He restated that OCR requests a risk analysis in every Security Rule investigation, that a gap analysis does not satisfy this requirement, and that breach notification to affected individuals is due no later than 60 calendar days after discovery.

Day 2: AI Governance, Medical Devices, and Updated NIST Frameworks

Future of Health IT: ONC Updates. Steven Posnack reviewed the Trusted Exchange Framework and Common Agreement (TEFCA), now connecting 11 Qualified Health Information Networks and more than 1.5 billion documents shared across roughly 21,000 organizations. He flagged chatbot and AI agent manipulation as a newly recognized attack surface for health IT systems.

A CFIUS Perspective. Tara Vayda outlined the Committee on Foreign Investment in the United States and its review authority over foreign transactions touching sensitive health data, pointing attendees to the 2025 Annual Report to Congress for recent case trends.

AI Metrology in Healthcare. Ram Sriram presented measurement approaches for AI reliability, including uncertainty quantification, which flags predictions that fall outside a model’s training distribution rather than returning an overconfident answer. For clinical decision support tools, he proposed tracking hallucination rate, omission rate, groundedness, and guideline adherence as core performance metrics.

Medical Device Cybersecurity Roundtable. Justin Post of the FDA reviewed Section 524B requirements for internet-connectable “cyber devices,” including mandatory cybersecurity management plans and software bills of materials. Connor Walsh of Siemens Healthineers presented proposed (not yet final) HIPAA Security Rule requirements for medical devices, including annual device inventories, network segmentation, semiannual vulnerability scans, and a 72-hour restoration target for critical systems after an incident. The panel closed on AI’s accelerating role in vulnerability discovery, illustrated by an AI-assisted finding that led to the withdrawal of HAWK, a post-quantum signature candidate, from NIST consideration.

Cybersecurity Workforce in Healthcare Panel. Panelists from CRISP, the University of Michigan Regional Health Network, CISA, and a legal practice discussed workforce development resources, including NIST’s National Initiative for Cybersecurity Education and the Health Sector Coordinating Council’s Workforce Guide.

NIST AI Risk Management Framework. Martin Stanley presented the AI RMF 1.0, structured around a Govern function at the center, supported by Map, Measure, and Manage. He noted that NIST is actively revising the framework under the White House AI Action Plan, with no release date yet confirmed, and that AI risk management is complicated by the fact that models are not deterministic and can change or be replaced unexpectedly.

AI in Healthcare Roundtable. Dr. Jesse Isaacman-Beck of ONC and private-sector panelists from McLaren Healthcare and CareFirst BlueCross BlueShield emphasized that AI governance must cover the full life cycle from procurement through deployment, and that evaluating AI tools requires measuring outcomes achieved, not just outputs generated.

NIST Cybersecurity Framework Profiles, Risk Analysis, and Risk Management. Nick Heesters of OCR restated the three-stage risk analysis standard: assessing risk to ePHI as it is created, as it flows through the organization, and as it leaves the organization. Bill Fisher of NCCoE presented the updated Ransomware CSF 2.0 Profile, published in June 2026, mapping CSF categories to specific ransomware mitigation activities. Ishika Khemani of MITRE presented the draft Cyber AI Profile (NIST IR 8596), organized around securing AI systems, conducting AI-enabled cyber defense, and protecting the enterprise from AI-enabled attacks, layered onto existing CSF 2.0 subcategories rather than replacing them.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/