Regulatory alerts
Curated federal and state rule changes that affect HIPAA-covered practices — enforcement actions, Security Rule NPRMs, breach notification amendments, and adjacent FDA / 42 CFR Part 2 updates. Each row has a per-browser “Mark as read” toggle stored in localStorage; nothing is sent to the server.
Unread
—
Unread
HHS Office for Civil Rights
HighFederalOCR settles multi-state pharmacy chain breach — $1.9M resolution
OCR announced a $1.9M settlement with a regional pharmacy chain over a 2024 ransomware incident that exposed prescription data for ~85,000 patients. The cited deficiencies include a failure to conduct a thorough risk analysis under §164.308(a)(1)(ii)(A) and missing encryption-at-rest controls on legacy dispensing endpoints. Corrective action plan requires a full enterprise risk analysis within 180 days and quarterly OCR progress reporting for two years.
Posted Jul 22, 2026
Mark as readCalifornia Attorney General
MediumStateCalifornia finalizes amendments to medical breach notification statute
The California AG finalized amendments to the medical information breach notification statute effective January 1, 2027. Key changes: the electronic-notice threshold drops from 500 to 250 California residents, the AG must be notified within 30 days (down from 60) for breaches exceeding 1,000 residents, and substitute notice must now include a posted conspicuous banner on the entity's homepage for at least 90 days.
Posted Jul 15, 2026
Mark as readHHS Office for Civil Rights
HighFederalOCR resolves right-of-access case with specialty clinic — $84,000
OCR closed its 42nd right-of-access enforcement action, this time against a single-specialty clinic that failed to provide a patient with copies of their designated record set within the 30-day window across three requests. The settlement underscores continued OCR focus on patient access timing even at small practices and includes a two-year monitoring period.
Posted Jun 30, 2026
Mark as readHHS Office for Civil Rights
HighFederalNotice of Proposed Rulemaking — HIPAA Security Rule modernization
OCR published a long-anticipated Notice of Proposed Rulemaking to strengthen the HIPAA Security Rule. Notable proposals: mandatory multi-factor authentication for all remote access to ePHI, a 72-hour breach notification window for unauthorized disclosures of more than 500 records, encryption of ePHI at rest as an addressable implementation specification becoming required, and an annual penetration-test requirement for covered entities with more than 25 staff. The 90-day public comment window closes August 6, 2026.
Posted May 8, 2026
Mark as readFDA Center for Devices and Radiological Health
MediumFederalFDA finalizes cybersecurity guidance for premarket medical-device submissions
The FDA finalized its 2026 premarket cybersecurity guidance for medical-device manufacturers. Submissions must now include a software bill of materials (SBOM) covering all third-party components, a threat model with documented mitigations, and a post-market vulnerability-handling plan with a defined coordinated disclosure timeline. The guidance applies to all 510(k) and De Novo submissions received on or after September 1, 2026.
Posted Apr 19, 2026
Mark as readHHS Office for Civil Rights
LowFederalHHS finalizes 42 CFR Part 2 alignment rule — narrower than proposed
HHS finalized a rule aligning a portion of 42 CFR Part 2 (federal substance-use disorder records) with HIPAA for uses and disclosures involving care coordination. The final rule is modestly narrower than the 2024 NPRM; notably, a separate patient consent remains required for SUD records used in civil or criminal proceedings against the patient. Effective date is February 16, 2027; covered entities may comply voluntarily in the interim.
Posted Feb 14, 2026
Mark as read
Read state is per-browser. Clearing site data resets every toggle.