Blog Post

Recent HIPAA Enforcement Trends and Compliance Considerations

Demi-lee Mpati | August 2026

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) continues to actively enforce the Health Insurance Portability and Accountability Act (HIPAA), with recent enforcement actions addressing requirements under both the Privacy Rule and the Security Rule. Healthcare organizations should monitor these enforcement trends and assess whether their HIPAA compliance programs adequately address the areas receiving OCR scrutiny.

OCR continues to enforce individuals’ rights under the HIPAA Privacy Rule to obtain timely access to their medical records. Through its Right of Access Initiative, OCR has taken enforcement action against healthcare providers that delayed or failed to provide individuals with access to their protected health information (PHI) within required timeframes.

In December 2025, OCR announced its 54th enforcement action under the Right of Access Initiative, resolving an investigation involving Concentra, Inc. for $112,500. OCR determined that Concentra failed to provide an individual with timely access to PHI after the individual made six requests beginning in February 2018. The individual did not receive the requested information until March 2019, more than one year after the initial request.

Healthcare organizations should periodically review their medical record request procedures, ensure staff understand applicable response timeframes, and verify that unnecessary administrative barriers do not delay patient access.

Cybersecurity remains an OCR enforcement priority. In April 2026, OCR announced settlements totaling $1.165 million with four regulated entities following separate ransomware investigations. The breaches collectively affected more than 427,000 individuals. The settlements included:

  • Regional Women’s Health Group, LLC, doing business as Axia Women’s Health — $320,000, involving 37,989 individuals;
  • Assured Imaging Affiliated Covered Entities — $375,000, involving 244,813 individuals;
  • Consociate, Inc., doing business as Consociate Health — $225,000, involving approximately 136,539 individuals; and
  • Star Group, L.P. Health Benefits Plan — $245,000, involving approximately 9,316 individuals.

OCR found that each entity failed to conduct an accurate and thorough risk analysis to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of its electronic protected health information. OCR also identified additional potential HIPAA violations in some investigations, including impermissible disclosures of PHI and failure to provide timely breach notification.

The four settlements also resulted in corrective action plans subject to OCR monitoring for two years. Healthcare organizations should periodically conduct and update risk analyses, develop and implement risk management plans to address identified risks and vulnerabilities, and ensure appropriate safeguards are in place. OCR also recommends authentication mechanisms, encryption of ePHI in transit and at rest when appropriate, regular review of information system activity, and workforce training specific to employees’ job duties.

OCR’s enforcement activity also extends directly to business associates. In March 2026, OCR announced a settlement with MMG Fusion, LLC, a Maryland software company and HIPAA business associate, following a security incident affecting approximately 15 million individuals.

OCR’s investigation began after it received a complaint concerning an unreported security incident and the posting of PHI on the dark web. OCR determined that MMG Fusion potentially violated provisions of the HIPAA Privacy, Security, and Breach Notification Rules by impermissibly disclosing the PHI of approximately 15 million individuals, failing to conduct an accurate and thorough risk analysis, and failing to notify affected covered entities of the breach. MMG Fusion agreed to pay $10,000 and implement a corrective action plan that OCR will monitor for three years.

Business associates should ensure they understand and comply with their HIPAA obligations, including requirements related to risk analysis and breach notification. Covered entities should also review their business associate agreements to ensure that responsibilities for reporting security incidents and breaches are clearly addressed.

Recent enforcement actions highlight several areas healthcare organizations should consider when evaluating their HIPAA compliance programs. Patient access procedures, risk analysis, breach notification, workforce training, policies and procedures, and business associate oversight should all be included as part of an effective HIPAA compliance program.

A Privacy Program Evaluation can help organizations move beyond a check-the-box approach by providing an independent review of their privacy programs against HIPAA requirements, OCR guidance, and enforcement expectations. The evaluation may include a review of program governance, policies and procedures, workforce training, patient rights processes, business associate oversight, breach response practices, and safeguards for protecting PHI. Periodic evaluations can help organizations identify areas for improvement and determine whether existing privacy practices remain consistent with HIPAA requirements and OCR guidance.

If your organization has not recently assessed its HIPAA privacy and security program, now is an opportune time to do so. Strategic Management can help evaluate current practices, identify areas of potential risk, and support practical steps to strengthen compliance before regulatory scrutiny occurs.

For more information on this topic, please contact Demi Mpati at [email protected]. To learn more about Strategic Management’s privacy and security program evaluation services, please connect with us.

About the Author

Demi Mpati serves as an Associate Consultant at Strategic Management Services, where she supports clients in navigating complex healthcare regulatory requirements and strengthening their compliance programs. In this role, she conducts in-depth research and analysis of federal and state healthcare laws, including the False Claims Act, Anti-Kickback Statute, Stark Law, HIPAA, and CMS regulations. Ms. Mapti's work enables Senior Consultants advise their clients and keep them informed and compliant in a rapidly evolving regulatory environment.

Subscribe to blog