Regulatory alerts

HHS & state privacy/security feed

Curated federal and state rule changes that affect HIPAA-covered practices — enforcement actions, Security Rule NPRMs, breach notification amendments, and adjacent FDA / 42 CFR Part 2 updates. Each row has a per-browser “Mark as read” toggle stored in localStorage; nothing is sent to the server.

Unread

Unread

  • HHS Office for Civil Rights

    High
    Federal

    OCR settles multi-state pharmacy chain breach — $1.9M resolution

    OCR announced a $1.9M settlement with a regional pharmacy chain over a 2024 ransomware incident that exposed prescription data for ~85,000 patients. The cited deficiencies include a failure to conduct a thorough risk analysis under §164.308(a)(1)(ii)(A) and missing encryption-at-rest controls on legacy dispensing endpoints. Corrective action plan requires a full enterprise risk analysis within 180 days and quarterly OCR progress reporting for two years.

    Posted Jul 22, 2026

    Mark as read
  • California Attorney General

    Medium
    State

    California finalizes amendments to medical breach notification statute

    The California AG finalized amendments to the medical information breach notification statute effective January 1, 2027. Key changes: the electronic-notice threshold drops from 500 to 250 California residents, the AG must be notified within 30 days (down from 60) for breaches exceeding 1,000 residents, and substitute notice must now include a posted conspicuous banner on the entity's homepage for at least 90 days.

    Posted Jul 15, 2026

    Mark as read
  • HHS Office for Civil Rights

    High
    Federal

    OCR resolves right-of-access case with specialty clinic — $84,000

    OCR closed its 42nd right-of-access enforcement action, this time against a single-specialty clinic that failed to provide a patient with copies of their designated record set within the 30-day window across three requests. The settlement underscores continued OCR focus on patient access timing even at small practices and includes a two-year monitoring period.

    Posted Jun 30, 2026

    Mark as read
  • HHS Office for Civil Rights

    High
    Federal

    Notice of Proposed Rulemaking — HIPAA Security Rule modernization

    OCR published a long-anticipated Notice of Proposed Rulemaking to strengthen the HIPAA Security Rule. Notable proposals: mandatory multi-factor authentication for all remote access to ePHI, a 72-hour breach notification window for unauthorized disclosures of more than 500 records, encryption of ePHI at rest as an addressable implementation specification becoming required, and an annual penetration-test requirement for covered entities with more than 25 staff. The 90-day public comment window closes August 6, 2026.

    Posted May 8, 2026

    Mark as read
  • FDA Center for Devices and Radiological Health

    Medium
    Federal

    FDA finalizes cybersecurity guidance for premarket medical-device submissions

    The FDA finalized its 2026 premarket cybersecurity guidance for medical-device manufacturers. Submissions must now include a software bill of materials (SBOM) covering all third-party components, a threat model with documented mitigations, and a post-market vulnerability-handling plan with a defined coordinated disclosure timeline. The guidance applies to all 510(k) and De Novo submissions received on or after September 1, 2026.

    Posted Apr 19, 2026

    Mark as read
  • HHS Office for Civil Rights

    Low
    Federal

    HHS finalizes 42 CFR Part 2 alignment rule — narrower than proposed

    HHS finalized a rule aligning a portion of 42 CFR Part 2 (federal substance-use disorder records) with HIPAA for uses and disclosures involving care coordination. The final rule is modestly narrower than the 2024 NPRM; notably, a separate patient consent remains required for SUD records used in civil or criminal proceedings against the patient. Effective date is February 16, 2027; covered entities may comply voluntarily in the interim.

    Posted Feb 14, 2026

    Mark as read

Read state is per-browser. Clearing site data resets every toggle.