I recently asked #HHS #OCR how any personnel and regional cuts would affect their investigation of breaches of the #HIPAA #SecurityRule and #Notification Rule.

They didn't exactly answer my question as to how many investigators have been laid off, but they did outline their priorities for 2026.

You can read their response to my inquiries in my new post at:

https://databreaches.net/2026/01/15/hhs-ocr-comments-on-its-2026-priorities/

#databreach #healthsec #cybersecurity #ransomware #hacking #risk

HHS OCR comments on its 2026 priorities – DataBreaches.Net

In a recent interview with Rachel Klugman Seeger of North Country Communications, she raised the question of how the current administration's closures of six HH

DataBreaches.Net

Methodist Homes of Alabama and Northwest Florida is notifying residents and employees of its second data breach in seven months.

I wonder what #HHSOCR will do when they investigate.

https://databreaches.net/2026/01/08/methodist-homes-of-alabama-and-northwest-florida-is-notifying-residents-and-employees-of-its-second-data-breach-in-seven-months/

#HIPAA #SecurityRule #RiskAssessment #cybersecurity #healthsec

Methodist Homes of Alabama and Northwest Florida is notifying residents and employees of its second data breach in seven months. – DataBreaches.Net

On January 6, Methodist Homes of Alabama and Northwest Florida ('Methodist Homes') reported that a compromised employee email account had been accessed between

DataBreaches.Net

The second part of my interview with Rachel Seeger of North Country Communications is now online. If you know any HIPAA-regulated SMBs struggling with compliance issues or seeking great information and advice, point them to Rachel's consultancy.

HIPAA Compliance and Breach Communications: Helpful Tips for SMBs:
https://databreaches.net/2026/01/06/hipaa-compliance-and-breach-communications-helpful-tips-for-smbs/

or download a copy od the interview:
https://databreaches.net/wp-content/uploads/HIPAA-Compliance-and-Breach-Communications.pdf

Direct link to North Country Communications: https://northcountrycommunications.com/

#HIPAA #compliance #BreachNotification #PrivacyRule #SecurityRule #BusinessAssociates

HIPAA Compliance and Breach Communications: Helpful Tips for SMBs – DataBreaches.Net

Published by DataBreaches.net in collaboration with North Country Communications, LLC. January 6, 2026 On December 15, North Country Communications   launched a

DataBreaches.Net

Jackson Health System has disclosed another insider-wrongdoing breach. This one affected about 2000 patients. The employee's motivation was reportedly related to boosting their personal healthcare business.

In their notice, JHS tries to portray themself as a victim. That didn't go over too well with me, as this is not the first time they have had a long-running insider wrongdoing breach.

In 2019, they settled HHS OCR charges after three breaches -- one of which involved insider wrongdoing over 5 years that affected 24k patients. There was no corrective action plan as part of the settlement. Perhaps there should have been?

Read more:
https://databreaches.net/2025/06/07/data-breach-of-patient-info-ends-in-firing-of-miami-hospital-employee/

#databreach #healthsec #insiderthreat #HIPAA #SecurityRule #insiderwrongdoing

HHS OCR Settles HIPAA Security Rule Investigation of BayCare Health System for $800k and Corrective Action Plan

[It's an insider wrongdoing case from 2018 that we never heard about at the time]

https://databreaches.net/2025/05/29/hhs-ocr-settles-hipaa-security-rule-investigation-baycare-health-system-for-800k-and-corrective-action-plan/

#HIPAA #SecurityRule #InsiderThreat #HHS #HHSOCR #BayCare

Great thanks to @adamshostack for getting people together to think about this issue and to make recommendations to #HHS under the #HIPAA Security Rule.

https://shostack.org/blog/security-researcher-comment-on-hipaa-security-rules/

Direct link to comments to HHS by @adamshostack, @dykstra, Fred Jennings, Chloé Messdaghi, and me:

https://downloads.regulations.gov/HHS-OCR-2024-0020-4673/attachment_1.pdf

#GoodFaith #SecurityRule #ResponsibleDisclosure #VDP

Shostack + Friends Blog > Security Researcher Comments on HIPAA Security Rule

A group of us have urged HHS to require better handling of security reports