healthcare regulatory compliance

Waiting and Waiting for Security Updates

By Matt Fisher – The biggest recent news for HIPAA is the quiet reveal that updates to the Security Rule are now delayed until sometime in the middle of 2027. The update was made on an Office of Management and Budget webpage, which now shows expected final action as an undefined date in July 2027.


Free the Data

By Matt Fisher – Access to data and the enablement of data flow are significant issues and concerns within healthcare. In particular, individuals often have a hard time getting to their own data. Those difficulties exist even with different regulations in place designed to promote and require access to data.


Do Your Risk Analysis

By Matt Fisher – The drumbeat of settlement agreements for alleged HIPAA violations by the Office for Civil Rights is continuing along with the consistent finding that the required risk analysis did not occur. The consistent announcement of settlements offers regular reminders to the healthcare industry that OCR is watching and expecting compliance to improve.


Be Truthful to Get Patients

By Matt Fisher – Imagine this scenario: an individual is suffering from substance use disorder and decides to seek help. A big reason for not getting treatment is reportedly not knowing how or where to get treatment, not being able to afford the treatment, and/or not finding a program or clinician where they wanted to be able to go.


Insider Risks

By Matt Fisher – The risk to privacy and security of healthcare information, despite all of the headlines, does not only come from outside attackers. Inside threats are real and can go undetected for potentially longer periods of time.



Always Listening, Always Leaking?

By Matt Fisher – Ambient listening technology is growing in many areas and being incorporated into a lot of different applications. What does the ambient listening do? It automatically picks up conversations and other sounds around it to be processed for one purpose or another.