25% off all training courses Offer ends April 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends April 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

HIPAA Compliance News

Our HIPAA enforcement news section keeps you up to date with HIPAA breaches, OCR updates and HITECH compliance issues. Make sure you remain up to date with the latest HIPAA compliance news by subscribing to our newsletter or follow us on Twitter @HIPAAJournal.

FREE Webinar Next Week: 2025 HIPAA Breaches & Fines: What Went Wrong and Your 2026 Action Plan

Workforce Compliance

In 2025, hundreds of healthcare data breaches exposed tens of millions of patient records — and the OCR enforcement record...

OPM’s Plan to Collect Federal Employees’ Health Insurance Data Attracts Strong Criticism

OPM collection of federal employee's health information

A proposal to allow the Office of Personnel Management (OPM) to collect the personally identifiable health information of federal employees...

Lawsuit Alleges AI Platform Illegally Recorded Patient-Clinician Conversations

A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations...

February 2026 Healthcare Data Breach Report

February 2026 Healthcare data breach report

In February 2026, 63 data breaches were reported to the Department of Health and Human Services (HHS) Office for Civil...

OCR Releases Video on HIPAA Security Rule Risk Management Requirements

HIPAA Risk management guidance

Earlier this year, Paula M. Stannard, Director of the Department of Health and Human Services (HHS) Office for Civil Rights...

Trump Administration Proposes 12.5% Cut to HHS Budget for FY 2027

The HHS’ Office for Civil Rights (OCR) has long been seeking an increase to its budget to support its HIPAA...

News Categories

Notices

CMS Releases Final Rule Implementing HIPAA Standards for Health Care Claims Attachments

The U.S. Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) released a final rule...

Final Rule Implementing HIPAA Security Rule Updates Edges Closer

HIPAA Security Rule update

The HIPAA Security Rule update proposed by OCR in the final days of the Biden administration is only two months...

Business Associate Settles HIPAA Violations Related to Unreported Breach Affecting 15 Million Individuals

MMG Fusion HIPAA settlement

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its second enforcement action of...

January 2026 Healthcare Data Breach Report

January 2026 Healthcare data breach report

The HHS’ Office for Civil Rights (OCR) healthcare data breach portal shows a slight month-over-month decline in large healthcare data...

Top of the World Ranch Treatment Center Settles Alleged Risk Analysis HIPAA Violation

Top of The World Treatment Center HIPAA penalty

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first financial penalty of...

March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline

HIOPAA Breach Notification Rule reporting deadline small data breaches

Healthcare data breaches discovered in calendar year 2025 that affected fewer than 500 individuals must be reported to the HHS’...

What is Protected Health Information?

Protected Health Information is an individual’s health, treatment, or payment for treatment information – and certain information maintained in the...

What is the Purpose of HIPAA?

The purpose of HIPAA was originally to ensure more employees could continue to receive health insurance coverage when they were...

What is a HIPAA Violation?

A HIPAA violation is any failure to comply with the HIPAA regulations – which can include the unauthorized access, use,...

What is Considered PHI Under HIPAA?

Under HIPAA PHI is considered to be an individual’s health, treatment, and payment information, and any related information maintained in...

New HIPAA Regulations in 2026

New HIPAA regulations may be implemented in 2026, such as the proposed update to the HIPAA Privacy Rule,  a final...

July 2025 Healthcare Data Breach Report

U.S. healthcare data breaches are down 34.1% month-over-month, and 44.5% fewer individuals had their healthcare data exposed. HIPAA-regulated entities reported...

HIPAA Policies and Procedures

HIPAA policies and procedures are “work rules” healthcare organizations must implement and regularly update to ensure the confidentiality, integrity, and...

What Does HIPAA Cover?

HIPAA – via the Administrative Simplification Regulations – covers the privacy of individually identifiable health information when it is created,...

Is iCloud HIPAA Compliant?

iCloud is not HIPAA compliant and cannot be used to store, sync, or share media containing Protected Health Information (PHI)...

What is a HIPAA Subpoena?

A HIPAA subpoena is a legal document that compels HIPAA-regulated entities to release information such as patient medical records that...

What is a HIPAA Security Incident?

A HIPAA security incident is an event that threatens the confidentiality, integrity, or availability of electronic Protected Health Information (PHI)...

Is WebEx HIPAA Compliant?

Webex is HIPAA compliant and, provided policies relating to disclosures are complied with, can be used to disclose PHI during...

Is Dropbox HIPAA Compliant?

Dropbox is HIPAA compliant and can be used to store, sync, and share Protected Health Information provided organizations subscribe to...

Can HIPAA be Waived?

Although HIPAA cannot be waived in its entirety, some provisions of the Privacy Rule can be waived in certain circumstances...

What Does PHI Stand For?

PHI stands for Protected Health Information – a term is commonly referred to in connection with the Health Insurance Portability...

What Does HIPAA Mean?

HIPAA stands for the Health Insurance Portability and Accountability Act – an Act passed by Congress in 1996 with the...

Is Zapier HIPAA Compliant?

Zapier is not HIPAA compliant due to the number of applications that integrate with the online automation platform and the...

Is HIPAA a Federal Law?

HIPAA is a Federal law that was passed in 1996 with the objective of reforming the health insurance industry in...

Is Uber Health HIPAA Compliant?

Uber Health is HIPAA compliant and can be used by healthcare providers to organize transport for patients or to arrange...

Is Google Slides HIPAA Compliant?

Google Slides is HIPAA compliant and can be used to create slides and presentations containing Protected Health Information provided the...

How to File a HIPAA Complaint

HIPAA gives individuals the right to file a HIPAA complaint against Covered Entities and Business Associates if they believe their...

HIPAA Violation Reporting

The process for HIPAA violation reporting varies according to who is reporting a HIPAA violation, the nature of the HIPAA...

Is Trello HIPAA compliant?

Trello is not HIPAA compliant and the platform cannot be used to receive, store, or share Protected Health Information due...

Is Google Keep HIPAA Compliant?

Google Keep is HIPAA compliant and can be used to create notes containing Protected Health Information and share them via...

Is AWS HIPAA Compliant?

AWS supports HIPAA compliance for customers required to comply with the Health Insurance Portability and Accountability Act and will enter...

Is doxy.me HIPAA Compliant?

On paper, doxy.me is HIPAA compliant and – subject to an organization subscribing to a business plan that supports HIPAA...

When Was HIPAA Enacted?

HIPAA was enacted at various stages following the passage of the Health Insurance Portability and Accountability Act in 1996, with...

Is Evernote HIPAA Compliant?

Evernote is not HIPAA compliant and cannot be used to save, store, sync, or share documents and images containing Protected...

What is Medical Identity Theft?

Medical identity theft is the theft or misuse of an individual’s health information to fraudulently obtain treatment, prescription drugs, or...

When Can PHI be Disclosed?

Most sources of information answering the question when can PHI be disclosed refer to the standards of the HIPAA Privacy...

What Federal Department Regulates HIPAA?

Healthcare providers, health plans, healthcare clearinghouses, and business associates of those organizations must comply with the Health Insurance Portability and...

Is Cloud Computing HIPAA Compliant?

Cloud computing has revolutionized the way healthcare organizations operate, but ensuring cloud computing is HIPAA compliant can be a challenge....

HIPAA Enforcement Rule

The HIPAA Enforcement Rule of 2006 – and subsequent amendments attributable to the passage of HITECH – details the procedures...

What is Protected by HIPAA?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is an important legislative Act that requires healthcare organizations that...

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist