If I run HIPAA work for an HDO in 2026, I need to focus on four things right now: the February 16, 2026 Notice of Privacy Practices deadline, Part 2 notice changes for SUD records, OCR scrutiny of website and portal tracking tools, and tighter cybersecurity expectations even though the Security Rule update is still not final.

Here’s the short version:

  • Update NPPs by February 16, 2026
  • Remove or revise reproductive-health language affected by the June 18, 2025 court ruling
  • Check every pixel, tag, cookie, and SDK on websites, portals, and apps
  • Tighten security controls like MFA, encryption, risk analysis, backups, and incident response
  • Review vendors and BAAs, since third parties keep showing up in major breach data
  • Treat telehealth and remote work under normal HIPAA rules, with no pandemic-era leeway

The pressure is not theoretical. In 2024, 663 large breaches affected about 242.9 million people, and in H1 2025, 379 large breaches exposed more than 31,052,837 people. On top of that, hacking and IT events made up 96.8% of breached records in that 2025 period.

What I take from all of this is simple: finish the items with hard dates, clean up patient-facing notices, lock down digital tools, and keep records that show what was done.

Area What I’d treat as the main 2026 issue Status
Privacy notices NPP updates tied to Part 2 and related notice changes Due by February 16, 2026
Reproductive health privacy Review language after the June 18, 2025 court decision Active review item
Tracking tools OCR focus on portals, care-related pages, and analytics tags Active enforcement
Security Rule NPRM points to stricter security controls, but not final yet Proposed
Telehealth HIPAA rules apply in full after flexibilities ended on August 9, 2023 In effect
Vendor oversight BAAs, reassessments, and proof of follow-up High-risk area

If I were summarizing the whole article in one line, it would be this: 2026 is less about new theory and more about showing clear proof that privacy, security, vendor, and digital-health controls are in place and current.

2026 HIPAA Compliance: Key Breach Stats & Deadlines for HDOs

2026 HIPAA Compliance: Key Breach Stats & Deadlines for HDOs

HIPAA Security Rule Enforcement in 2026: Proposed Changes, Current Expectations, and Risk Management

Security Rule Modernization and Rising Cybersecurity Expectations

On Dec. 27, 2024, HHS/OCR issued an NPRM aimed at tightening cybersecurity protections for ePHI. The rule is not final, and the current Security Rule still applies. HHS has pushed expected final action to July 2027 on its Unified Regulatory Agenda.[22][23][13]

But “not final” doesn’t mean HDOs get a pass for now. OCR, auditors, and private plaintiffs are already looking to the NPRM and HHS’s Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs) as a yardstick for what reasonable security looks like today.[19][20][21] So even though the proposal hasn’t crossed the finish line, it’s already shaping day-to-day decisions.

For HDOs, the issue isn’t whether expectations will get tighter. It’s how fast current controls need to catch up.

You can already see that pressure in the numbers. In 2024, OCR received 663 large breach notifications affecting about 242.9 million individuals, much of that tied to a single ransomware attack on a healthcare clearinghouse that exposed ePHI for about 192 million people.[26][29] Business associates were the location of 30% of large healthcare data breaches that year.[27]

The table below shows where the current rule stands and where things are heading:

Requirement Current HIPAA Baseline Emerging 2026 Expectation Likely HDO Operational Change
Risk Analysis Flexible methodology; accurate and thorough assessment required System-level risk documentation that identifies threats, likelihood, impact, and mitigation [11][12][14] Shift from periodic assessments to continuous, system-level risk records with assigned owners
MFA Addressable - entities decide if reasonable and appropriate Effectively mandatory for ePHI access under the NPRM; narrow exceptions only [11][12] MFA gap analysis, prioritized rollout to EHRs, remote access, and email
Encryption Addressable - alternatives permitted with documentation Effectively required for ePHI at rest and in transit [11][12] Enterprise encryption program across endpoints, servers, and databases
Asset Inventory Implied control; no explicit requirement Documented technology asset inventory and network map required [11][12] Deploy discovery tools; assign ownership for keeping inventories current
Vulnerability Management No defined cadence specified Regular vulnerability scanning and annual penetration testing [12][17] Formalized scan cycles, remediation SLAs, and integration with change management
Incident Response Documented policies and procedures required Documented plans with roles, escalation paths, and tabletop exercises [11][17] Recurring drills, runbooks for frontline staff, logged evidence for audits

The pattern is pretty clear: less room for judgment calls, more controls that can be tested, logged, and checked later.

What the Proposed Security Rule Changes Would Require

The biggest change in the NPRM is the move away from the addressable-versus-required model that has long shaped the Security Rule.[12][23][24] Under the proposal, controls such as encryption, MFA, and vulnerability scanning would shift from optional in practice to expected in practice. HDOs would also need a documented technology asset inventory and network map covering every system that creates, receives, maintains, or transmits ePHI.[11][12]

Risk analysis would change too. The current rule requires an accurate and thorough assessment, but it leaves the method open. The NPRM tightens that up by calling for direct documentation of threat identification, likelihood and impact judgments, and chosen mitigations for each major system, not just for the organization as a whole.[11][12][14] It also proposes annual compliance audits and periodic expert validation of business associate technical safeguards.[12][14]

That’s a big shift. It means teams can’t just say, “We assessed risk.” They’d need records that show what system was reviewed, what threat was found, what the likely harm was, and what was done about it.

How HHS Cybersecurity Guidance Affects Day-to-Day Operations

HHS

Even without a final rule, HHS’s HPH Cybersecurity Performance Goals are already shaping what compliance teams need to prove. The CPGs group controls into 10 essential goals and 10 enhanced goals, aligned to NIST CSF and the 405(d) Health Industry Cybersecurity Practices (HICP).[18][19][20][21] Essential goals include MFA, email security, patch management, backups, and vendor risk management. Enhanced goals cover network segmentation, advanced monitoring, and configuration management.

On the ground, this changes the kind of proof HDO IT and security teams need to show. A written policy by itself doesn’t carry much weight if the control behind it hasn’t been tested. Scheduled phishing simulations, documented backup restoration tests, and recurring incident response tabletop exercises are turning into standard evidence items in audits and incident investigations.[11][16][17]

That’s the shift in plain English: from policy on paper to controls that work and leave a trail.

Third-Party Risk Management as a Core HIPAA Control

This becomes even more concrete with vendors. In 2023, business associates accounted for 37.4% of breaches but 69% of PHI records lost, the highest third-party exposure on record, highlighting the economic impact of these breaches.[25] The NPRM makes clear that HDOs still carry responsibility for ePHI even when a vendor, cloud provider, or digital health platform handles it.[11][12][15]

A 2024 OCR settlement with Cascade Eye and Skin Centers shows what that can look like in enforcement. The organization paid $250,000 and entered a corrective action plan after a ransomware attack affecting about 291,000 ePHI files. OCR pointed to failure to conduct an enterprise-wide risk analysis and weak system activity review.[28]

So vendor oversight now has to be more than a signed agreement and a file folder. It calls for pre-onboarding review, periodic reassessment, and tracked remediation. That’s where the Security Rule is heading in plain terms: away from paperwork alone and toward direct accountability.

Privacy Rule Changes with Direct 2026 Compliance Impact

For HDOs, 2026 Privacy Rule work comes down to two near-term jobs: remove vacated reproductive-health language and update Part 2 notices by February 16, 2026. In practice, this is day-to-day compliance work. Teams need to clean up policies, notices, and the scripts staff use with patients.

What Changed After the Reproductive Health Privacy Rule Litigation

HHS finalized the HIPAA Privacy Rule to Support Reproductive Health Care Privacy on April 26, 2024. The rule limited how PHI tied to reproductive health care could be disclosed in law-enforcement or legal proceedings involving lawful care.[30][31] Then, on June 18, 2025, the U.S. District Court for the Northern District of Texas in Carmen Purl et al. v. HHS vacated most of those reproductive-health-specific amendments nationwide.[32][33][35][36]

So what does that mean for HDOs? Put simply: treat those vacated provisions as inactive federal requirements. At the same time, keep baseline HIPAA safeguards, patient rights, and minimum-necessary rules in place. And if state law is stricter, follow that too.[30][33][34]

Before deleting policy language, compliance teams should sort each clause into three buckets:

  • clearly vacated
  • still required under HIPAA
  • required by state law or enterprise risk policies

That extra check matters. If a team deletes language too fast, it can remove text tied to a separate rule that still applies.

Notice of Privacy Practices Updates Due by February 16, 2026

The same common-sense rule applies to Part 2: patient-facing documents need to match the law as it stands now. Separate from the litigation, HDOs that handle Part 2 SUD records must update their Notices of Privacy Practices by February 16, 2026.[6][37][38][39]

HHS has released revised model NPPs and a federal Part 2 patient notice.[37][40][2] The updated NPP must do a few specific things. It needs to explain that SUD records carry added federal confidentiality protections beyond standard HIPAA. It also needs to describe allowed uses and disclosures, including treatment, payment, and health care operations. On top of that, it must state that SUD records generally cannot be used in legal proceedings against a patient without specific consent or a Part 2-compliant court order, and it must spell out patient rights tied to those records.[4][5][3]

Drafting the notice is only half the job. Distribution matters just as much. Registration desks, patient portals, admissions packets, and reception areas all need to show the same current NPP.[37] Here's how the required updates line up with operational owners:

NPP Element Required 2026 Update Operational Owner
SUD record confidentiality Explicit statement that SUD records may be subject to additional federal protections under 42 C.F.R. Part 2, beyond standard HIPAA[37][4] Privacy/Compliance Officer
Permitted uses and disclosures of SUD records Clarified language describing permitted SUD record uses (TPO) and limits on further disclosure to third parties[4][5][3] Legal Counsel + Privacy Officer
SUD records in legal proceedings Statement that SUD records generally cannot be used in legal proceedings against the patient without consent or a Part 2-compliant court order[4][5][3] Legal Counsel
Patient rights related to SUD records Updated rights language specific to SUD records, including right to file complaints with OCR[37][4][5] Privacy/Compliance Officer
NPP posting and distribution Simultaneous update across all channels: portals, registration, admissions, reception areas[37] Communications / Patient Experience
Workforce training Updated scripts and onboarding materials aligned to current NPP; retirement of outdated versions Training / Operations

One issue deserves close attention: some organizations have already changed release-of-information procedures to match newer Part 2 practices, but they still have an old NPP in circulation. That kind of mismatch can lead to patient complaints and OCR review.[40][3]

Digital Health, Tracking Technologies, and Telehealth Compliance

Paper notices are only half the story. The other half sits in the digital stack: websites, patient portals, telehealth platforms, mobile apps, and the third-party scripts running behind them. OCR has drawn a sharper line around how these tools should be handled, and the dollar amounts tied to mistakes are hard to ignore.

OCR Tracking Technology Guidance for Websites and Patient Portals

OCR

OCR separates authenticated pages from public-facing ones. That split matters.

On patient portals, login pages, and test result pages, tracking tags, cookies, and session replay tools will often touch PHI. Public pages are less simple. If a page relates to care, login, scheduling, or reminders, it can still point to a patient’s link to care and expose PHI.[53][42][54]

The legal risk isn’t abstract. Advocate Aurora Health settled a pixel-related class action for $12.225 million, and Allina Health reportedly agreed to a $12.5 million settlement.[55][56][57] One study found that 99% of U.S. hospitals used pixels or other tracking tools on websites, apps, or patient portals that collected visitor data and sent it to third parties.[58]

That’s why this can’t be handled with guesswork. Teams should:

  • Inventory every tracking tag on every patient-facing page
  • Block ad-tech pixels on authenticated pages unless the vendor has a BAA and a HIPAA-permitted purpose
  • Document the risk analysis for any page that falls into a gray area[1][42][43][44]

The same vendor and access rules don’t stop at the website. They follow the patient into live digital care too.

Telehealth and Remote Communication Tools After Enforcement Flexibilities Ended

OCR ended its COVID-era telehealth enforcement discretion on August 9, 2023. Since then, telehealth has needed to run on non-public-facing platforms under normal HIPAA rules.[9]

If a vendor receives, creates, transmits, or maintains ePHI, that vendor needs a BAA. Platforms should also support encryption, strong access controls, and secure authentication.[43][49] For audio-only telehealth, the basics matter more than people think: verify the patient’s identity, use a private setting, and stay away from speakerphone or any setup where others could overhear the call.[41][45][51]

Remote work adds another layer. HDOs should treat the home office like an extension of the clinical network. In plain English, that means VPNs for EHR access, MDM on smartphones used for telehealth, and clear rules about where sessions can happen so staff don’t expose PHI by accident.[9][45][50][52]

Governance for AI-Enabled and Vendor-Supported Digital Health Tools

AI changes the risk picture because vendors may handle PHI in ways the HDO can’t easily see. OCR hasn’t issued AI-specific HIPAA rules, but HIPAA still applies when AI-enabled tools, cloud services, and other vendors process ePHI. That includes tools working with structured EHR data, free-text notes, and imaging data. It also includes fourth-party risk through model hosts, analytics services, and sub-processors.[46][47][48]

Good governance starts with PHI mapping. An HDO needs to know exactly what each AI tool gets, why it gets it, and whether that access is limited to the minimum necessary for the tool’s stated job. If a vendor processes PHI, it should be treated as a business associate. The BAA should clearly address data use, model training, retention, and onward transfers to sub-processors.[46][48]

Tools such as Censinet RiskOps™ can help with standardized questionnaires, evidence collection, and continuous monitoring across the vendor ecosystem.[46][47][48]

The table below maps common digital health tools to their main PHI risks, the OCR or HIPAA guidance tied to them, and the controls that matter most:

Digital Health Tool Primary PHI Risks Relevant HIPAA/OCR Guidance Key Controls
Patient portal analytics Login data, appointment details, diagnosis/billing info, portal activity OCR online tracking bulletin; authenticated-page guidance[1][42][43][44] BAA, minimize tags, block ad-tech pixels, access review
Public website tracking Potential IIHI/PHI if page is tied to care or payment OCR 2024 update on unauthenticated webpages[53][42][54] Page-by-page classification, suppress identifiers on care-related pages
Telehealth video platform Audio/video content, visit metadata, session interception OCR telehealth guidance[9][43][49] Non-public-facing platform, encryption, BAA, secure identity verification
Audio-only telehealth Call content, metadata, device and network exposure OCR audio-only telehealth guidance[41][45][51] Private setting, identity verification, avoid speakerphone, secure device use
Mobile app SDKs Location, device IDs, in-app behavior, appointment data OCR online tracking bulletin[1][44] SDK inventory, vendor review, data-flow mapping, minimum necessary data sharing
AI-enabled clinical tools EHR data, imaging, free-text notes, fourth-party model training exposure HIPAA's technology-neutral application to AI[46][47][48] PHI mapping, BAA covering sub-processors, minimum necessary access, ongoing monitoring
Remote work tools Unsecured home networks, personal devices, overheard PHI HIPAA Security Rule and telehealth guidance[9][45][52] MFA, encryption, VPN, MDM, workspace privacy controls

What HDO Leaders Should Do Next in 2026

2026 brings hard deadlines, proposed rule changes, and more pressure to show your work. The pattern across security, privacy, and digital health is pretty clear: handle what is already required, prepare for what may land next, and document every move. HDOs that build defensible programs now will be in a much better spot. The next move is to turn all of that into a short, usable action list.

Priority Actions for Compliance, Security, and Documentation

The February 16, 2026 NPP deadline is the clearest fixed date on the calendar. Covered entities must post updated notices on their websites and at service locations, share them with patients, and keep version-controlled proof showing approval and posting. Part 2 organizations also need to update redisclosure and legal-proceeding language.[7][10][8]

Recent settlements send another plain message: risk analysis remains a top enforcement focus. A good way to prioritize spending is to line up controls with the HHS Healthcare and Public Health Cybersecurity Performance Goals (HPH CPGs). That means phishing-resistant MFA, tested backups, vulnerability patching SLAs, and centralized logging. Censinet RiskOps™ can help standardize vendor assessments, remediation tracking, and audit evidence.

These actions fit into five core operational controls:

Area Regulatory Driver 2026 Expectation Evidence of Compliance
NPP Updates 2024 HIPAA Privacy Rule; 42 CFR Part 2 alignment Updated NPP posted and distributed by Feb. 16, 2026 Version-controlled proof of approval and posting
Vendor Risk Management HIPAA Security Rule; HPH CPGs; third-party breach trends Current BAA coverage and risk-tiered reassessments for all PHI-handling vendors Signed BAA coverage; remediation closure rate
Tracking Technology Governance OCR online tracking guidance; litigation settlements Inventory, classify, and control all pixels and tags on portals and public pages Tracker inventory completed; evidence of tag removal or reconfiguration
Telehealth Security OCR telehealth guidance; end of enforcement flexibilities (Aug. 9, 2023) Verified encryption, access controls, BAAs, and approved workflows for all remote care tools Access logs; staff training completion rate
Incident Response HIPAA Breach Notification Rule and ransomware response Tested playbooks covering ransomware, vendor compromise, and web portal incidents Tabletop exercise results; breach notification drill completion

Leaders should track these items together, not as separate projects. If each team works in its own lane, gaps show up fast. A missed BAA, an old tracker on a patient portal, or an untested ransomware playbook can turn into the weak link.

Key Points Leaders Should Track Through the Rest of 2026

Some changes are already in effect. The NPP deadline is set, the telehealth enforcement flexibilities ended long ago, and OCR's tracking-technology guidance still creates compliance and lawsuit risk. The proposed Security Rule overhaul is not final yet. Even so, the controls tied to that proposal - stronger risk analysis, documented safeguards, encryption, and MFA - match what OCR already looks at in investigations.

The breach numbers make the pressure hard to ignore. In H1 2025 alone, 379 large healthcare breaches exposed more than 31,052,837 individuals, and hacking and IT incidents accounted for 96.8% of all breached records.[59] That is why proof matters almost as much as the control itself. OCR and plaintiffs' attorneys both look for the paper trail: risk analyses, training logs, BAA records, and exercise after-action reports.

FAQs

What should HDOs prioritize first for 2026 HIPAA compliance?

HDOs should begin with a thorough, enterprise-wide risk assessment to spot gaps across administrative, physical, and technical safeguards.

From there, they should focus on a live inventory of systems, devices, and vendors that handle protected health information. That work should sit alongside core controls like multi-factor authentication, encryption, and testable restoration plans for critical systems within 72 hours.

Does the February 16, 2026 deadline apply to every HDO?

No. The February 16, 2026, deadline does not apply to every healthcare delivery organization (HDO).

It applies to vendors and manufacturers that act as business associates and handle sensitive information, including substance use disorder data and reproductive or behavioral health protected health information.

Other HIPAA updates follow different timelines. For example, the Security Rule overhaul is currently projected for 2027.

How can HDOs check whether website tracking tools create HIPAA risk?

Add website tracking tools to your PHI/ePHI system inventory. Don’t treat them like harmless add-ons. If a tracker sits on pages where patients book visits, log in, fill out forms, or view care details, it may touch PHI/ePHI.

Run a documented risk analysis for each tool. The goal is simple: determine whether the tracker receives, processes, transmits, or can infer PHI, including through third-party access. That means looking beyond obvious data fields. A tool might not collect a diagnosis code directly, but it may still hint at health details based on page URLs, button clicks, search terms, form activity, or user flow.

Ask vendors for evidence, not just broad claims. You’ll want materials that show how the tool handles data, what it stores, where it sends it, and what outside parties can see. If the vendor says access is controlled and monitored, verify that your audit logging can prove it.

Audit logs should show:

  • who accessed what
  • when the access happened
  • what system, record, or data set was involved

Track all findings in a risk register. Keep it practical and easy to review, with assigned owners, remediation timelines, and status updates. And don’t let it go stale. Update the register when websites, tags, pixels, scripts, forms, or integrations change, because even a small site update can shift your risk in a big way.

Related Blog Posts