The Department of Health and Human Services Office for Civil Rights (OCR) has signaled aggressive HIPAA enforcement in 2026, with record penalties and expanded audit programs. Healthcare organizations must adapt to evolving compliance requirements across medical device security, cloud and SaaS governance, and ransomware preparedness — while modernizing the technical safeguards examiners now expect as baseline.
2026 OCR Enforcement Priorities
Three areas are drawing the most audit and enforcement attention this year.
Medical Device Security (IoMT)
OCR is now scrutinizing Internet of Medical Things (IoMT) security after several high-profile breaches involving connected medical devices.
- •Medical device inventory and risk assessment
- •Network segmentation for medical devices
- •Vulnerability management programs
- •Vendor security assessments
Cloud Security & SaaS Applications
Healthcare’s rapid cloud adoption has created new compliance challenges.
- •Business Associate Agreements (BAAs) for all cloud vendors
- •Encryption of ePHI at rest and in transit
- •Access controls and audit logging
- •Data residency and sovereignty
Ransomware Preparedness
Following devastating healthcare ransomware attacks, OCR now evaluates incident response preparedness during audits.
- •Incident response plan specific to ransomware
- •Offline, immutable backups
- •Regular backup testing
- •Cyber insurance coverage
These three priorities aren’t arbitrary — each maps directly to where OCR has had to update its own playbook because the underlying risk changed shape. IoMT devices didn’t exist in meaningful numbers when the HIPAA Security Rule was written in 2003; a connected infusion pump or imaging system is now a general-purpose computer running an OS that needs patching, sitting on the same network segment as everything else, and most healthcare IT teams still don’t have a complete inventory of what’s actually plugged in. OCR’s emphasis on device inventory and segmentation exists because the agency has seen, repeatedly, that organizations can’t assess a risk they can’t enumerate.
Cloud and SaaS scrutiny follows the same logic from a different direction. Every SaaS tool a clinical or billing team adopts without IT’s knowledge is a potential Business Associate that never signed a BAA, and OCR treats a missing or stale BAA as evidence the covered entity doesn’t know where its own ePHI lives — which is precisely the finding that turns a routine incident into a Security Rule violation, because it means the risk analysis was incomplete by definition.
Ransomware preparedness is the one OCR now audits proactively rather than waiting for a breach report, because the agency has learned that the gap between having a written incident response plan and having a tested one is exactly where healthcare organizations keep failing. A plan nobody has rehearsed reliably produces a slower, more damaging response than no plan at all — it creates false confidence at the leadership level while the technical team improvises. That’s why OCR audits now probe for evidence of tabletop exercises and validated backup restoration, not just the existence of a policy document.
The Penalty Landscape
2025 was OCR’s second-busiest enforcement year on record — and the case detail matters more than any single average.
2025 OCR Settlements & CMPs
Second-highest annual total on record, per legal-industry tracking of HHS resolution agreements
Largest 2025 Settlement
Solara Medical Supplies (Jan. 14, 2025) — traced to a 2019 phishing attack that sat undetected in employee email for months, exposing 114,007 records
Largest HIPAA Settlement Ever
Anthem, 2018 — still the record, for a breach traced to a failure to identify and respond to a known intrusion in progress
Criminal Penalties
Up to $250,000 and 10 years imprisonment under 42 U.S.C. §1320d-6 for offenses committed for commercial gain or malicious harm
The through-line in nearly every OCR settlement, 2025 included, is not a novel attack technique. It’s a documented failure to do the basics: an incomplete or missing risk analysis, a breach notification that went out late, or access controls that existed on paper but weren’t enforced. Attackers don’t need a zero-day when the risk analysis was never finished.
Technical Safeguards Modernization
Access Controls — §164.312(a)(1)
Username and password
- •Phishing-resistant MFA (FIDO2, passkeys)
- •Risk-based authentication
- •Privileged Access Management (PAM)
- •Just-in-time access provisioning
Audit Controls — §164.312(b)
Local event logs
- •Centralized SIEM with long-term retention
- •Real-time security monitoring (24/7 SOC)
- •Automated compliance reporting
- •Tamper-proof audit logs
Transmission Security — §164.312(e)(1)
VPN for remote access
- •Zero Trust Network Access (ZTNA)
- •TLS 1.3 for all data in transit
- •End-to-end encryption
- •Secure email with DLP
Armorstack Healthcare Security Stack
Healthcare-specialized services spanning SENTRY, VERITY, and CORE.
SENTRY HEALTH
- •HIPAA-compliant 24/7 security monitoring
- •EHR security monitoring (Epic, Cerner, PCC)
- •Medical device security program
- •Healthcare-specific threat intelligence
VERITY GOVERN
- •Continuous compliance monitoring
- •Automated audit evidence collection
- •HIPAA Security Risk Assessment (SRA)
- •Policy management and updates
CORE
- •Encrypted backup with offsite replication
- •Disaster Recovery with <4-hour RTO
- •Regular backup testing and validation
- •Immutable backups for ransomware protection
2026 Action Items for Healthcare CISOs
- ☐Conduct comprehensive medical device inventory
- ☐Implement network segmentation for IoMT
- ☐Review and update Business Associate Agreements
- ☐Deploy phishing-resistant MFA organization-wide
- ☐Implement centralized SIEM with 6-year retention
- ☐Conduct HIPAA Security Risk Assessment
- ☐Test incident response plan with tabletop exercise
- ☐Validate backup recovery procedures
- ☐Complete security awareness training for all staff
- ☐Execute penetration testing
- ☐Prepare for potential OCR audit
- ☐Review and update security policies
HIPAA Compliance Is a Continuous Program, Not a Checklist
HIPAA compliance in 2026 requires more than checking boxes — it demands continuous monitoring, proactive risk management, and integration of security across your entire healthcare ecosystem.
Armorstack’s healthcare-specialized services across SENTRY HEALTH, VERITY GOVERN, and CORE operations provide the protection healthcare organizations need. Talk to our healthcare security team about scheduling your HIPAA Security Risk Assessment.