PrivacySignal
Healthcare

HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes

HIPAA Journal · · US Federal · Healthcare Privacy

Federal regulators have extended the timeline for HIPAA-regulated entities to comply with proposed updates to the HIPAA Security Rule, giving covered organizations additional time to prepare for the changes. The postponement applies broadly to entities subject to HIPAA, including healthcare providers, insurers, and their business associates.

Why this matters: Health data is some of the most sensitive information that exists about you. The HIPAA Security Rule is supposed to set the floor for how organizations protect it. A delay in tightening those rules means more time where healthcare providers, insurers, and their vendors can continue operating under older, weaker standards. That may feel like relief for compliance teams. For patients, it means the clock on better protections keeps running without moving. The question is whether the delay serves organizations that genuinely need time to adapt, or ones that were hoping the pressure would just go away.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
IAPP · · International

PIAs, shared custody, AI highlight changes to Alberta's Health Information Act

Alberta has made changes to its Health Information Act, with updates touching on privacy impact assessments, shared custody arrangements, and the use of artificial intelligence in handling health data.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Healthcare
Nextgov/FCW · · US Federal

VA boosts EHR modernization contract with Oracle by $17B

The Department of Veterans Affairs has expanded its electronic health records modernization contract with Oracle, raising the total value to nearly $27 billion. The modification represents a roughly $17 billion increase to the existing agreement.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
M Modern Healthcare · · International

Senate eyes a health privacy upgrade for your Apple Watch

The U.S. Senate is considering legislation that would strengthen privacy protections for health data collected by consumer wearables such as the Apple Watch. The move would extend health privacy rules beyond traditional medical providers to cover the growing market of personal health tracking devices.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
Nextgov/FCW · · US Federal

Social Security expands electronic health record sharing to speed up disability claims adjudication

The Social Security Administration has expanded a system that pulls structured electronic health records directly from providers, giving the agency near-instant access to medical data for people applying for disability benefits. The goal is to cut the notoriously long wait times for disability claim decisions.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

American Addiction Centers & Oculus Pathology Disclose Hacking Incidents

American Addiction Centers in Tennessee and Oculus Pathology in Texas have each disclosed separate hacking incidents. Both organizations operate in healthcare, meaning the breached data likely includes sensitive medical and personal information covered under HIPAA.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight

A large-scale audit of over 80,000 online review responses from nearly 4,000 medical and dental practices found an estimated 21,000 public replies that likely disclosed patient information in violation of HIPAA. The violations were not hidden in back-end systems — they were sitting in publicly visible responses to patient reviews.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →