HIPAA Biannual Update

Digital Debut

HIPAA Biannual Update

January to June 2026

During the first half of 2026, healthcare organizations across the country posted 248 breaches of protected health information affecting 500 or more individuals. This is the lowest number of breaches reported in a six-month span since the last half of 2020, and is a 31% decrease from the first half of 2024.

Consistent with previous updates, rises in unauthorized access or hacking now comprise almost all — 99% — of the breaches. The percentage of breach investigations due to improper disposal, loss or theft of PHI continues to decrease. For the first time since ASCA began providing its Health Insurance Portability and Accountability Act of 1996 biannual update, neither loss nor improper disposal of PHI were cited as the cause of a breach investigation.

Pie chart showing OCR breach investigations, January to June 2026: Hacking/IT Incident 94%, Unauthorized Access/Disclosure 5%, Theft 1%.

Within the Department of Health and Human Services, the Office for Civil Rights is the enforcement agency responsible for protecting rights related to health information privacy. This includes enforcement actions for violations of HIPAA, which delineates who can view or receive an individual’s PHI and sets standards for security of PHI when being stored or transferred electronically.

ASCs can take important steps to help prevent breaches and limit their liability. They can review and update policies and procedures frequently to help prevent unauthorized access, improper disposal, loss and theft of PHI. ASCs also can visit the OCR website to review enforcement actions and consider how they can avoid the mistakes made by others.

Although it was not included as an enforcement action in the first half of 2026, many recent enforcement actions have been through the HIPAA Right of Access Initiative. Introduced by OCR in 2019, this specific provision of the HIPAA Privacy Rule related to health information technology helps enforce and support individuals’ right to timely access their health records at a reasonable cost. Since 2019, OCR has announced 54 enforcement actions as part of this initiative. ASCs should review their policies and training programs to ensure that they are able to meet all HIPAA obligations when a patient requests access to their medical records.

Two examples of recent resolution agreements are provided below, along with precautions ASCs can take to avoid similar violations.

Top of the World Ranch Treatment Center

What happened: Top of the World Ranch Treatment Center is a substance use disorder treatment provider in Illinois. In 2023, the facility filed a breach report with OCR alleging that an unauthorized third party accessed electronic PHI through a workforce member’s email account via a phishing attack that compromised the ePHI of more than 1,900 patients. OCR’s investigation concluded that the facility failed to adequately address potential risks and vulnerabilities to the confidentiality, integrity and availability of its ePHI. Top of the World Ranch Treatment Center agreed to a $103,000 monetary penalty and a corrective action plan, with two years of monitoring by OCR.

Takeaways for ASCs: Phishing schemes now often target healthcare providers and are becoming more sophisticated in nature. As it becomes increasingly more challenging to differentiate authentic emails from those sent by bad actors, ASCs should regularly conduct comprehensive risk analyses to identify potential threats and vulnerabilities to ePHI and implement plans to address identified risks. Facilities should also maintain and update written HIPAA policies and procedures as needed and provide annual HIPAA training to staff with access to ePHI.

Continue Reading Below

Assured Imaging Affiliated Covered Entities

What happened: Assured Imaging is a medical imaging and screening service provider headquartered in Arizona and California. In May 2020, Assured Imaging reported that a server on its network was infected with ransomware, compromising the ePHI of more than 244,000 individuals. OCR’s investigation found that Assured Imaging impermissibly disclosed PHI, failed to conduct an adequate risk analysis and did not timely notify affected individuals of the breach. Assured Imaging agreed to a corrective action plan with two years of monitoring and paid $375,000 to OCR.

Takeaway for ASCs: In 2024, OCR launched its Risk Analysis Initiative, focused on enforcing the HIPAA Security Rule’s risk analysis requirement. Since launching the initiative, OCR has announced 14 enforcement actions. ASC staff and patients alike should be confident that ePHI is secured and inaccessible from bad actors, both internally and externally.

While the task of safeguarding PHI in an increasingly targeted sector might feel onerous, OCR has shared several strategies that all healthcare entities covered by HIPAA, including ASCs and business associates, can implement now to strengthen their defenses.

  • Identify where ePHI is located in the organization, including how ePHI enters, flows through and leaves the organization’s information systems.
  • Periodically conduct, and update as needed, a risk analysis and develop and implement risk management measures to address identified risks and vulnerabilities to the confidentiality, integrity and availability of ePHI.
  • Ensure audit controls are in place to record and examine information system activity.
  • Implement regular review of information system activity.
  • Utilize mechanisms to authenticate users seeking access to ePHI.
  • Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
  • Incorporate lessons learned from incidents into the organization’s overall security management process.
  • Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.

Hacking and ransomware have quickly become the most pressing cyber threats in healthcare. As threats to ASCs continue, OCR continues to stress the importance of HIPAA Security Rule compliance in all three areas of information security: administrative, physical and technical safeguards. While the timing of its release has been postponed a year, OCR expects to issue a final HIPAA Security Rule in July 2027.

To help ASCs remain compliant with HIPAA, ASCA provides the HIPAA Resources page that can be found in the federal regulations section of ASCA’s main site. It provides background on the act itself, as well as the four key provisions: privacy, security, enforcement and breach notification.

Write Maia Kunkel at mkunkel@ascassociation.org with questions.