Key Takeaways:
- Risk analysis remains the foundation of HIPAA Security Rule compliance and continues to be a key OCR enforcement focus.
- Business associates and vendors are a major source of healthcare cybersecurity risk, making third-party oversight essential.
- Incident response, workforce training and documented security decisions are now critical markers of a defensible compliance program.
After more than two decades, the Security Rule of the Health Insurance Portability and Accountability Act (HIPAA) has proven both durable and demanding. As healthcare organizations confront escalating cyberthreats and rising regulatory expectations, the lessons of past enforcement offer a road map forward. This 21st anniversary is both a moment for reflection and a call to prepare deliberately for what comes next.
April 2026 marks 21 years since the HIPAA Security Rule’s original compliance date in 2005, a milestone that arrives at a consequential moment for healthcare cybersecurity. For more than two decades, the Security Rule has served as the foundation for protecting electronic protected health information (ePHI), even as healthcare delivery, technology and cyberthreats have evolved dramatically. This milestone also coincides with the first meaningful effort in more than two decades to modernize the Security Rule, signaling a potential shift toward more prescriptive regulatory expectations. In BakerHostetler’s 2026 Data Security Incident Response Report (DSIR), healthcare was the industry with the highest percentage of privacy and security incidents handled by BakerHostetler in 2025.
The same report describes 2025 as “a year of heightened scrutiny and operational pressure” in healthcare privacy, driven by enforcement initiatives by the Office for Civil Rights (OCR), major vendor breaches, evolving HIPAA requirements and state attorney general (AG) investigations. That combination makes this anniversary more than retrospective. It is a reminder that healthcare organizations should be reassessing the maturity of their security programs now.
To understand where the Security Rule is headed, it helps to look at how far it has come.
1. Security Is a Process, Not a Project
Organizations that treat the Security Rule as a one-time compliance exercise often struggle as systems, vendors and threats change. The Security Rule requires continuous evaluation and adjustment. Effective programs treat security as an ongoing life cycle that evolves alongside technology, operations and risk. Compliance is not achieved once and forgotten. It must be maintained deliberately over time.
That point is especially important in an environment where operational and enforcement pressures are increasing. BakerHostetler’s DSIR characterizes 2025 as a period of heightened scrutiny and operational pressure regarding healthcare privacy, underscoring the need for sustained program attention rather than episodic compliance efforts.
2. Security Risk Analysis Is the Foundation of Everything
A comprehensive and accurate risk analysis, together with a well-defined risk management plan, is the cornerstone of Security Rule compliance. Yet this requirement remains one of the deficiencies most frequently cited by OCR in investigations, technical assistance and enforcement actions. Without a clear understanding of where ePHI resides, how it flows and what vulnerabilities affect it, organizations cannot reasonably implement safeguards.
Risk analysis is not merely a regulatory requirement. It is the blueprint for security decision-making. The corresponding risk management plan translates those findings into actionable steps for the entity to mitigate the identified risks. Failing to conduct an accurate and thorough risk analysis, and to implement an effective risk management plan, continues to be a common Security Rule violation.
That enforcement focus remains current. The DSIR states that OCR continued to focus on the security risk analysis, including by imposing more penalties and resolution agreements under its Risk Analysis Initiative, with findings that organizations failed to conduct proper enterprise security risk analyses.
A recent OCR settlement with BST & Co. CPAs LLP illustrates the point. OCR determined that the organization, which was a business associate, had not conducted a sufficient risk analysis or developed a corresponding risk management plan before a ransomware incident, resulting in a $175,000 settlement and a two-year corrective action plan. The message is familiar but still important: Risk analysis and risk management must be performed proactively, not only after an incident occurs. OCR views the security risk analysis as the foundation for HIPAA compliance with the Security Rule.
3. Business Associates Are a Primary Risk Vector
As healthcare organizations increasingly rely on third parties for technology, hosting, claims processing, analytics and other operational functions, business associates have become a significant source of risk. The Security Rule does not allow covered entities to outsource responsibility for ePHI, yet data breach investigations frequently reveal vendors with broad access and insufficient security controls. Business associate risk is enterprise risk and should be managed with the same rigor as internal operations.
The DSIR strongly supports that point. Across all matters BakerHostetler handled in 2025, 25 percent of incidents were caused by a vendor. For healthcare clients specifically, 35 percent of 2025 incidents were attributed to vendors. The report also states that OCR made clear in 2025 that business associates are “firmly in the enforcement spotlight,” reporting seven resolution agreements against business associates between November 2024 and December 2025.
Vendor breaches remain among the defining risks in healthcare. The DSIR describes the February 2024 Change Healthcare ransomware attack as “catastrophic,” ultimately exposing 192.7 million individuals’ data, and identifies Conduent, Episource and Oracle Health breaches as other major vendor incidents affecting healthcare entities.
4. ‘Addressable’ Does Not Mean Optional
One of the most persistent misconceptions about the Security Rule concerns the meaning of “addressable safeguards.” Addressable does not mean discretionary. It means an organization must assess whether the safeguard is reasonable and appropriate in its environment and, if not, document why an equivalent alternative is appropriate. Informal decisions, assumptions or silence do not satisfy the Security Rule. Enforcement history consistently shows that undocumented discretion is difficult to defend.
5. Documentation Is Compliance Control
More than two decades of OCR enforcement have made one point unmistakably clear: Documentation is evidence. Policies, procedures, risk analyses, training records and decision rationales are not administrative formalities. They are how compliance is demonstrated. Even well-designed safeguards lose value when organizations cannot show how and why they were implemented. Regulators evaluate proof rather than promises.
6. Technology Does Not Equal Compliance
Security tools are essential, but technology alone does not ensure compliance. Firewalls, endpoint protection, monitoring platforms and encryption tools must be implemented and governed within a broader security program. Many enforcement actions involve situations where tools existed but were misconfigured, inconsistently applied or disconnected from risk management decisions. Governance and oversight remain critical.
The DSIR also reflects how attack patterns are changing in ways that make governance more important than any single technical tool. It reveals that fewer incidents involve malware, with threat actors focusing more on identity by leveraging existing accounts to access data and key systems.
7. Workforce Behavior Remains the Greatest Risk
Despite advances in cybersecurity technology, human behavior continues to drive many security incidents. Phishing attacks, credential misuse, improper access and misdirected disclosures remain common causes of breaches. The Security Rule’s emphasis on administrative safeguards reflects the reality that people, not just systems, determine outcomes.
The DSIR’s incident data reinforces that point. Across all incidents BakerHostetler handled in 2025, phishing accounted for 30 percent of root causes, social engineering for 8 percent and human error/unintended recipient for 8 percent. Further, the report notes that phishing has remained the leading cause of incidents for all 12 years of the report.
8. Training Must Be Ongoing and Meaningful
Annual, generic HIPAA training is no longer sufficient. Workforce members must understand current threats and how their specific roles intersect with ePHI security. Training should address phishing, credential security, social engineering, escalation expectations and the practical realities of day-to-day system use. Continuous, role-relevant training reduces both operational and regulatory risk.
That is especially true in light of the DSIR’s broader findings. The report states that “the inbox remains a battleground” and that social engineering continues to increase as a root cause, including attacks targeting functions at the perimeter such as help desks.
9. Encryption Has Become a Baseline Expectation
While encryption has long been classified as an addressable safeguard, enforcement history has effectively elevated it to a baseline expectation in many settings. OCR settlements frequently involve unencrypted laptops or mobile devices, with encryption failures influencing both breach analysis and enforcement outcomes. In practice, encryption often determines whether an incident becomes a reportable breach at all.
10. Incident Response Plans Must Be Operational
An incident response plan that exists only on paper provides little protection. Effective response requires clearly defined roles, escalation paths, communication protocols, decision authority, and tested coordination among legal, privacy, security, compliance, communications and business leadership. Organizations that regularly exercise their plans are generally better positioned to contain incidents and make defensible decisions under pressure.
The DSIR shows how compressed response windows have become. In 2025, the time from occurrence to discovery was three days, the time from discovery to containment was zero days, the time to complete the forensic investigation was 23 days and the time from discovery to notification was 59 days. Those timelines leave little room for uncertainty or improvisation.
11. Detection and Response Matter as Much as Prevention
Even mature security programs experience incidents. Increasingly, the critical questions are how quickly the organization detected the issue, how effectively it investigated it and how decisively it responded. Delayed identification or delayed containment can amplify legal, operational and patient-care consequences.
The DSIR underscores that dynamic, noting that “dwell time has gotten shorter, with threat actors moving faster from initial compromise to data theft and/or encryption.” Prevention still matters, but speed of detection and containment increasingly determines outcome.
12. Executive (and Board) Engagement Is Nonnegotiable
Security programs without leadership support often lack funding, authority and sustainability. The Security Rule places responsibility squarely on organizational leadership to ensure safeguards are reasonable and appropriate. Enforcement activity increasingly reflects expectations for executive and board oversight and accountability.
13. Compliance Is the Floor, Not the Ceiling
HIPAA sets minimum requirements, not best practices. Organizations that aim only for technical compliance often fail to build meaningful resilience. Mature programs use the Security Rule as a foundation while layering governance, testing, monitoring and operational discipline to address evolving threats.
The DSIR reflects this broader shift. It notes that the convergence of regulatory expectations and litigation risk means security teams, internal legal staff and external counsel are spending more time designing, updating and testing security programs, not just responding after a breach.
14. Size Does Not Excuse Inaction
HIPAA applies to organizations of all sizes. While safeguards may scale based on resources and complexity, core obligations do not disappear. Enforcement actions consistently demonstrate that smaller organizations are held to the same standard as larger entities.
15. Flexibility Requires Defensibility
The Security Rule’s flexibility allows organizations to tailor safeguards to their environment, but it also requires defensible decision-making. Organizations must be prepared to explain why safeguards were implemented, modified or not adopted. Undocumented discretion has repeatedly proven difficult to defend.
16. Threats Evolve Faster Than Regulations
The Security Rule’s principle-based structure has allowed it to remain relevant through major changes in technology. But that same flexibility requires organizations to keep pace with emerging threats. Programs that fail to adapt often find themselves exposed during incident response or enforcement review.
The DSIR highlights several examples. It notes a rise in employees uploading or pasting company data into unapproved generative artificial intelligence (AI) tools, creating confidentiality and privacy risks, and it describes AI as moving beyond simply enhancing phishing toward more sophisticated social engineering support and automation.
17. Cybersecurity Is Now a Patient Safety Issue
Ransomware, system outages and data integrity failures directly affect patient care. Security incidents are no longer viewed solely as privacy issues. They are operational and clinical risks that can affect scheduling, pharmacy workflows, clinical documentation, communications and access to care.
The DSIR underscores that ransomware and operational disruption remain central healthcare risks. For healthcare incidents in 2025, the average initial ransom demand was $18,186,494, the average ransom paid was $1,154,245 and the average number of days to acceptable restoration was 12.7. In a healthcare setting, those restoration timelines are not just information technology metrics. They can directly affect continuity of care.
18. Enforcement Reflects Rising Expectations
Early enforcement often focused on basic compliance failures. Today, regulators increasingly expect mature, risk-based security programs supported by governance, documentation and accountability. Long-standing deficiencies carry greater consequences than isolated missteps.
That trend is not limited to OCR. The DSIR notes that state AGs are increasingly filling enforcement gaps in healthcare privacy and security and that multiple state AGs launched investigations despite concurrent or even closed OCR investigations. Healthcare organizations therefore face layered scrutiny that may test not only HIPAA compliance, but also broader state privacy, security and consumer protection expectations.
19. Early Investment Pays Long-Term Dividends
Organizations that invest early in governance, risk management and security culture consistently fare better during audits and investigations. Security maturity compounds over time by reducing disruption and limiting liability.
20. Preparing for Change Requires More Than Waiting
Regulatory change rarely arrives with generous timelines. Organizations that wait for final rules before beginning preparation often face compressed implementation schedules. Proactive planning grounded in risk analysis produces better outcomes than reactive compliance efforts.
21. The Future Is More Operational, More Defensible and More Demanding
The next phase of Security Rule compliance is likely to place even greater weight on whether an organization’s safeguards are operational, documented and defensible in practice. The lessons of the past 21 years point in the same direction: the need to understand where ePHI resides, know your risks, govern your vendors, train your workforce, exercise your incident response plan and document the reasoning behind key security decisions.
BakerHostetler’s 2026 DSIR suggests that healthcare organizations should respond to this moment with urgency. Healthcare remained the most frequently affected industry in the firm’s 2025 incident data; OCR continued to emphasize security risk analysis deficiencies; vendors and business associates remained a major source of exposure; and major incidents continued to create operational pressure across the sector. In that environment, strengthening the security program is not a future-facing exercise – it is a present governance priority.
Conclusion
Healthcare organizations should consider reassessing their enterprise risk analysis, strengthening business associate and vendor risk management, and reviewing the implementation and testing of core safeguards such as access controls, encryption, workforce training and incident response readiness.
BakerHostetler’s Healthcare Privacy and Compliance team helps organizations translate evolving Security Rule expectations into practical, defensible security programs. If your organization is preparing for regulatory change or seeking to strengthen its security posture, we are here to help navigate what comes next.