Hayden Crabb Hayden Crabb

Issue #6: Health Privacy Changed in 2026 — What Providers Need to Know About Part 2

Most healthcare organizations have built their privacy programs around HIPAA. That foundation matters. But HIPAA is not the only federal confidentiality framework that can affect how sensitive patient information is handled.

As of February 16, 2026, organizations subject to updated federal requirements for substance use disorder records under 42 CFR Part 2 must comply with significant changes intended to align portions of Part 2 more closely with HIPAA. At the same time, the HHS Office for Civil Rights has begun accepting Part 2 complaints and breach reports under a new civil enforcement program.

For healthcare leadership, the practical issue is not simply that the regulation changed. The more useful question is whether Part 2-protected information enters the organization, how it moves through existing workflows, and whether current privacy practices account for the additional protections that may apply.

Top 4 Part 2 Issues to Watch

1. HIPAA-Compliant Handling Is Not Automatically Part 2-Compliant Handling
The updated rule brings Part 2 closer to HIPAA in several important areas. Patients can now provide a single consent for future uses and disclosures of Part 2 records for treatment, payment, and healthcare operations, and certain recipients may generally redisclose those records as permitted by HIPAA.

But Part 2 has not simply become HIPAA.

Important confidentiality protections remain, particularly around the use of substance use disorder records in civil, criminal, administrative, and legislative proceedings against a patient. In practice, a disclosure that appears routine under HIPAA may still require a closer look if Part 2 information is involved.

The organization needs a practical way to recognize when those additional restrictions apply and route the records accordingly.

2. Part 2 Exposure Can Extend Beyond the Treatment Program
Not every healthcare provider is a Part 2 program. The regulation principally applies to federally assisted programs that provide substance use disorder diagnosis, treatment, or referral for treatment.

However, Part 2 responsibilities do not necessarily end when information leaves the originating program. Qualified service organizations, lawful holders of Part 2 records, and other organizations or persons holding protected records may also have responsibilities under the regulation.

That makes applicability a record-flow question as much as an organizational-label question.

It is not enough to ask, “Are we a substance use disorder treatment program?” A more useful question is, “Do Part 2-protected records enter our environment, and if they do, where do they go?”

Without that visibility, an organization may be managing information subject to heightened confidentiality requirements without recognizing the distinction.

3. Privacy Classification Now Matters During Incident Response
Beginning February 16, 2026, OCR began accepting complaints alleging Part 2 violations and breach reports involving protected substance use disorder records. Civil enforcement mechanisms can include corrective action, settlements, and civil money penalties.

This moves Part 2 identification out of the realm of legal interpretation alone and into daily operations.

During an incident, the organization may need to determine what information was involved, where it originated, which privacy requirements apply, who must be notified, and which response process governs the event. Those decisions become much harder if the team does not know whether Part 2 records are present in the affected system.

A mature incident-response process should therefore account for what kind of health information is involved, not just whether PHI was exposed.

It is far better to establish privacy classification before an incident occurs than to reconstruct it after a complaint or breach has already created regulatory pressure.

4. Written Privacy Documentation Must Match Day-to-Day Operations
Part 2 readiness is not accomplished by updating a policy and placing it back on the shelf.

Organizations subject to the requirements should look at how protected records are identified, how consent is managed, who may access or disclose the information, how legal requests are handled, how incidents are escalated, and whether workforce members recognize when additional confidentiality protections apply.

The 2026 requirements also affect patient privacy notices. Part 2 programs have specific patient-notice obligations, while HIPAA covered healthcare providers and health plans that create or maintain Part 2 records have corresponding Notice of Privacy Practices requirements.

The key test is whether the written privacy program reflects what actually happens in daily operations.

A policy may say that Part 2 records receive appropriate protections. Leadership should also be able to show where those records exist, who handles them, what controls apply, and how exceptions are escalated. That operational evidence is what turns written compliance into defensible privacy governance.

How SecureHealth Can Help

  • Part 2 Applicability & Record-Flow Review – Evaluate where substance use disorder information enters, moves through, or is maintained within healthcare workflows, and identify areas that warrant closer review

  • Privacy Policy & Workflow Alignment – Review consent, use and disclosure, escalation, legal-request handling, and incident-response procedures against applicable privacy requirements

  • Administrative Readiness Support – Help privacy, records, clinical, and operational personnel understand when heightened confidentiality requirements may apply and how those responsibilities can be documented and managed

What to Do This Month

1. Determine Applicability: Identify whether your organization operates a Part 2 program or receives and maintains records that originated from one.

2. Map Part 2 Record Flows: Document where applicable records enter the organization, where they are stored, who can access them, and when they may be disclosed or redisclosed.

3. Test Current Privacy Procedures: Confirm that consent, legal-request handling, incident response, escalation, and patient-notice processes can account for Part 2 requirements when they apply

Final Thought

The 2026 Part 2 changes reinforce a practical privacy-management principle: healthcare information does not always carry the same legal requirements simply because it sits in the same EHR, inbox, document repository, or workflow.

Organizations that understand what sensitive information they hold, which requirements apply to it, and how those requirements show up in routine operations are better positioned to protect patients, respond appropriately when incidents occur, and demonstrate stronger privacy governance.

The goal is not to create another layer of paperwork. It is to ensure that sensitive information receives the protections the law requires throughout its lifecycle.

Read More
Hayden Crabb Hayden Crabb

Issue #5: Downtime Preparedness Is a HIPAA Readiness Issue

Many healthcare organizations focus on preventing incidents but devote less attention to how operations continue when systems become unavailable. Whether caused by ransomware, EHR outages, internet disruptions, or vendor failures, downtime events can quickly affect scheduling, documentation, communications, and patient care workflows. This issue explores four operational risks that clinics should evaluate to strengthen continuity, reduce compliance exposure, and improve organizational resilience.

When healthcare organizations think about HIPAA readiness, many focus primarily on preventing incidents. Yet for clinics, operational disruption can create just as much exposure as the original event itself. Whether caused by ransomware, internet outages, EHR failures, vendor disruptions, or internal technical issues, downtime events can quickly affect scheduling, documentation access, patient communications, and clinical workflows.

From a compliance perspective, these situations are not simply IT interruptions. They test whether the organization can continue operating safely, maintain appropriate safeguards, and execute defined contingency procedures under pressure.

Many clinics have backup technologies in place. Far fewer have operationally mature downtime processes that staff can execute consistently during a real disruption. When procedures are unclear, responsibilities are undefined, or workflows have never been exercised, even short outages can create patient safety concerns, documentation gaps, privacy risks, and operational instability.

Top 4 Downtime Risks to Watch

1. Downtime Procedures Often Exist Only on Paper
Many organizations maintain contingency policies to satisfy compliance requirements, but fewer validate whether operational staff can realistically execute those procedures during a live disruption. In practice, downtime events often expose gaps between written policy and operational readiness. Staff may know a policy exists while remaining uncertain about responsibilities, escalation paths, manual workflows, or recovery expectations.

When that uncertainty appears during an outage, delays and inconsistent handling tend to follow quickly.

2. Operational Dependency on EHR Access Is Frequently Underestimated
Modern clinics rely heavily on continuous access to electronic systems for scheduling, intake, documentation, communications, prescribing, and coordination of care. Yet many organizations do not fully evaluate how dependent daily operations have become on uninterrupted technology availability.

In many cases, clinics only discover the extent of that dependency after access is disrupted. Even relatively short outages can create cascading operational issues when alternative workflows are incomplete, inaccessible, or unfamiliar to staff.

3. Front-End Administrative Breakdowns Can Create Compliance Exposure
Many healthcare organizations now depend on cloud-hosted EHR platforms, third-party communication tools, managed service providers, and external infrastructure vendors to support routine operations. While these relationships can improve efficiency, they also increase operational dependency on systems outside the clinic’s direct control.

Even when a disruption originates externally, the clinic remains responsible for maintaining continuity, safeguarding patient information, and coordinating response activities internally. Organizations that do not plan for vendor-side outages may find themselves without clear communication paths, escalation procedures, or operational alternatives during critical periods.

4. Privacy Compliance Is Also a Trust and Service Function
When systems become unavailable, personnel naturally attempt to maintain operations through temporary workarounds. Without clear guidance, however, those workarounds can introduce additional exposure. Staff may begin using unsecured communication methods, delay documentation, rely on personal devices, or create inconsistent tracking processes that complicate recovery and reconciliation later.

In many environments, the greatest operational risk during downtime is not the outage itself, but the lack of a coordinated and standardized response process surrounding it.

How SecureHealth Can Help

  • Downtime Readiness Review – Evaluate operational continuity procedures for EHR outages, communication disruptions, and workflow interruption scenarios

  • HIPAA Contingency Workflow Support – Help develop structured downtime, escalation, recovery, and documentation procedures aligned with operational realities

  • Tabletop and Response Readiness Exercises – Assess how administrative and operational teams respond during realistic disruption scenarios

What to Do This Month

1. Identify Critical Workflow Dependencies: Document which daily operations rely on EHR, internet, cloud, or vendor availability
2. Review Downtime Procedures with Staff: Ensure personnel understand how scheduling, intake, documentation, and communications would continue during an outage
3. Evaluate Manual and Backup Processes: Determine whether alternative workflows are realistic, accessible, and operationally sustainable during a prolonged disruption

Final Thought

Downtime preparedness should not be treated as a technical afterthought or a compliance checkbox. In healthcare environments, operational interruptions test how well an organization can maintain continuity, coordinate staff, protect information, and continue serving patients under pressure.

Organizations that approach downtime readiness as an operational discipline—not merely an IT function—are generally better positioned to reduce disruption, respond more consistently, and demonstrate stronger resilience when unexpected events occur.

Read More
Hayden Crabb Hayden Crabb

Issue #4: Patient Access Failures Remain a Real HIPAA Enforcement Risk

Patient access failures remain a real HIPAA risk when records requests are delayed, inconsistently handled, or poorly tracked. This issue explains where right-of-access workflows commonly break down and what clinics should review now.

When healthcare organizations think about HIPAA exposure, they often focus first on cybersecurity incidents, breach reporting, or technical safeguards. Those areas matter, but they are not the only enforcement risks that warrant leadership attention. OCR has continued to make clear that patient access failures remain a live compliance issue, particularly when organizations cannot provide records in a timely, consistent, and well-managed manner.

In practical terms, right-of-access compliance is not just a privacy requirement. It is an operational discipline. When record requests are handled through inconsistent workflows, unclear ownership, manual follow-up, or fragmented coordination, routine administrative activity can quickly become regulatory exposure. For clinics, this is not merely a documentation problem; it is a governance and process control issue.

Top 4 Patient Access Risks to Watch

1. Timeliness Failures Often Reflect Weak Process Control
The HIPAA right of access is one of the clearest administrative obligations facing regulated healthcare organizations. Yet in many environments, request handling still depends too heavily on ad hoc staff judgment, inbox monitoring, or informal handoffs. When deadlines are missed, the underlying issue is often not legal misunderstanding, but weak workflow design and insufficient accountability.

2. Repeated Patient Follow-Up Is an Early Warning Indicator
When a patient must call back multiple times, resubmit requests, or escalate concerns to obtain records, leadership should view that as more than a service issue. It is often a signal that the organization lacks effective request tracking, ownership clarity, or escalation discipline. By the time a complaint reaches OCR, the operational failure has usually been present for some time.

3. Front-End Administrative Breakdowns Can Create Compliance Exposure
Many patient access issues begin at the intake stage rather than at final fulfillment. Requests may be logged inconsistently, routed incorrectly, delayed pending avoidable clarification, or left without active monitoring. In those cases, the organization may believe it has a records process, while in reality it has a series of disconnected tasks. That distinction matters when timeliness and defensibility are tested.

4. Privacy Compliance Is Also a Trust and Service Function
A clinic may have strong technical safeguards and still create unnecessary exposure if patients cannot obtain their own information without delay or friction. Access failures erode trust quickly. They also suggest that privacy operations may not be sufficiently mature, measured, or standardized. From a leadership perspective, right-of-access performance should be treated as both a compliance indicator and a reflection of operational reliability.

How SecureHealth Can Help

  • Patient Access Workflow Review – Evaluate how requests are received, documented, routed, fulfilled, and closed

  • Records Request SOP Development – Standardize intake, identity verification, logging, escalation, extension handling, and completion steps

  • Administrative Readiness Support – Help front-desk, records, and operational staff understand their role in timely, compliant response execution

What to Do This Month

1. Map the Current Process: Document how patient requests move from intake through fulfillment
2. Assign Clear Accountability: Identify who owns request receipt, tracking, escalation, and completion
3. Review Aging Requests: Look for bottlenecks, repeated follow-up, and points where requests are commonly delayed

Final Thought

Patient access compliance should not be treated as a secondary administrative task. It is a visible, enforceable, and operationally sensitive part of HIPAA performance. Organizations that standardize the process, define ownership clearly, and monitor execution consistently are in a stronger position to reduce complaint risk, respond more reliably, and demonstrate better privacy governance overall.

Read More
Hayden Crabb Hayden Crabb

Issue #3: Your Vendors May Be Your Biggest HIPAA Risk

Third-party vendors can create significant HIPAA exposure for clinics when oversight stops at the contract. This issue explains where vendor risk most often breaks down and what leadership should review now.

For many healthcare organizations, third-party vendors now represent one of the most significant sources of HIPAA exposure. Billing firms, managed service providers, cloud platforms, patient communication tools, and other business associates often handle sensitive data or support critical workflows, yet many clinics still evaluate vendor risk too narrowly. A signed Business Associate Agreement is necessary, but it is not a substitute for meaningful oversight.

Recent OCR enforcement activity continues to reinforce a broader compliance reality: when a vendor experiences a security failure, the operational, regulatory, and reputational consequences often extend directly to the covered entity. In practice, that means vendor risk should no longer be treated as a procurement formality. It should be managed as a core component of security, compliance, and organizational resilience.

 

Top 4 Vendor Risks to Watch

1. Business Associate Oversight Often Stops at the Contract
Many organizations can identify which vendors have signed BAAs, but fewer can clearly explain how those vendors store, access, secure, or transmit ePHI in practice. That gap matters. Effective oversight requires more than executed paperwork; it requires a working understanding of data flows, service dependencies, and control expectations. Where that visibility is weak, risk is often being accepted without being formally recognized.

2. Third-Party Disruptions Can Become Immediate Clinic-Level Events
A vendor-side security incident can quickly disrupt scheduling, billing, patient communications, documentation access, or other core operations. Even where the breach originates outside the clinic, the downstream impact may still be felt internally through service interruption, delayed response, patient complaints, or reporting pressure. From an operational standpoint, vendor incidents should be treated as business continuity concerns, not just external IT events.

3. Risk Analysis Frequently Undervalues Vendor Exposure
Many risk assessments focus heavily on internal systems and devices while giving comparatively limited attention to external service providers. That approach can leave material exposure underrepresented. If a third party creates, receives, maintains, or transmits ePHI—or supports a system that does—its role should be reflected in the organization’s risk analysis, review cadence, and mitigation planning. Otherwise, a significant portion of the threat surface may remain insufficiently examined.

4. Incident Notification Language Is Often Too Weak or Too Vague
In many vendor relationships, breach notification and escalation terms are either generic or insufficiently operationalized. That creates avoidable risk. If a vendor delays notifying the clinic, provides incomplete information, or lacks a clear escalation path, the covered entity may lose critical time needed to assess scope, initiate internal response, and meet downstream obligations. Notification terms should be treated as response controls, not merely contract language.

 

How SecureHealth Can Help

  • Vendor Risk Review Framework – Identify and prioritize third parties that introduce meaningful HIPAA, security, or operational risk

  • BAA + Safeguards Review – Evaluate whether vendor agreements and control expectations align with actual service delivery and data handling practices

  • Third-Party Incident Readiness Support – Strengthen escalation paths, notification expectations, and response planning for vendor-related events

 

What to Do This Month

1. Revalidate Your Vendor Inventory: Confirm which third parties actually create, receive, maintain, or transmit ePHI
2. Review Critical Vendor Relationships: Focus first on EHR, billing, IT, hosting, and patient communications vendors
3. Examine Notification and Escalation Terms: Ensure vendor response obligations are clear enough to support timely decision-making

 

Final Thought

Vendor risk is no longer a peripheral compliance issue. For many clinics, it is one of the most practical and least mature areas of HIPAA risk management. Organizations that treat third-party oversight as a standing management function—not a one-time contracting task—are better positioned to reduce exposure, respond faster, and demonstrate stronger compliance discipline when incidents occur.

Read More
Hayden Crabb Hayden Crabb

Issue #2: What the ‘Big Beautiful Bill’ Means for Clinics Like Yours 

Congress’s new “Big Beautiful Bill” brings $1.5T in Medicaid and Medicare cuts. Here’s what small and rural clinics need to know—and how to prepare for the ripple effects.

On July 4, 2025, Congress passed the One Big Beautiful Bill Act (Public Law 119-21)—a sweeping law combining historic tax reforms with over $1.5 trillion in cuts to Medicaid and Medicare over the next decade. While political headlines focused on tax relief, the ripple effects for healthcare providers—especially small and rural clinics—are significant and immediate. 

 

Top 4 Impacts to Watch 

1. Medicaid Cuts Mean More Uninsured Patients 

With work requirements, 6-month re-verifications, and tightened eligibility, many clinics will see a spike in self-pay or unbilled care. 
Risk: Increased bad debt, strained staff, and overwhelmed intake workflows. 

2. Medicare Rate Adjustments Aren’t Guaranteed to Help 

A proposed 2.5% rate bump in 2026 may not offset the long-term $500B+ in program reductions. 
Risk: Ambiguity in reimbursements complicates budget planning and risk modeling. 

3. Compliance Complexity Is Growing 

New verification rules, tighter eligibility audits, and more frequent documentation reviews raise the stakes for privacy, access control, and patient data handling. 
Risk: Failing to adjust access and record retention policies could trigger OCR scrutiny. 

4. Operational Gaps Will Be Exposed 

Clinics that rely on outdated intake systems or undertrained staff will struggle to adapt. 
Risk: Gaps in documentation and role-based access controls increase the likelihood of HIPAA violations under 45 CFR §164.308(a)(3). 

 

How SecureHealth Can Help 

Our GRC approach is built for this environment. Here's what we're offering in light of the new law: 
📊 Medicare/Medicaid Revenue Exposure Review – See how coverage changes might affect your cash flow 
🧩 Policy + Workflow Gap Assessment – Align your staff access and documentation with updated HIPAA/NIST expectations 
🧠 Staff Briefing Kit – Educate your team on what the new rules mean for intake, billing, and patient data 

 

What to Do This Month 

1. Review Patient Mix: Estimate how many Medicaid patients may be affected 
2. Update Role-Based Access Policies: Ensure only current staff have EMR access (HIPAA §164.308(a)(3)) 
3. Audit Billing & Intake Workflows: Are you prepared for more manual verifications and billing holds? 

 

Final Thought 

Regulatory change doesn’t just affect policy—it impacts how you run your clinic every day. Now’s the time to build resilience, tighten compliance, and protect your bottom line. SecureHealth is here to help. 
 

Read More
Hayden Crabb Hayden Crabb

Issue #1: HIPAA Enforcement Trends – What 2025 Is Teaching Us

OCR enforcement in 2025 is targeting small clinics with outdated policies and missing breach plans. Here's what to fix before your next audit.

2025 has become a defining year in HIPAA enforcement. From six-figure penalties levied against small practices to public breach settlements, OCR’s message is clear: compliance is not optional—and outdated policies are no longer defensible.

SecureHealth is tracking these patterns to help clinics like yours stay not just compliant, but resilient.

Enforcement Snapshot (Q3)

  • $22.4M in fines issued so far

  • 80% of recent OCR actions targeted small to mid-sized clinics

  • Top violations:

    • Incomplete or outdated risk analyses

    • Weak access controls and offboarding

    • Missing or untested breach response plans

What We’re Seeing (and Why It Matters)

1. Outdated or Superficial Risk Analyses

  • OCR continues to cite violations of 45 CFR §164.308(a)(1)(ii)(A) when entities fail to conduct a thorough and accurate risk analysis. Many clinics either use outdated templates or skip documentation altogether. This is one of the most cited deficiencies in 2025. 

2. Weak Access Controls & Poor Offboarding

  • Under §164.308(a)(3)(ii)(B), covered entities must implement procedures for workforce access management. Yet enforcement reveals lingering access rights for terminated staff and insufficient role-based restrictions—direct HIPAA violations. 

3. Breach Response Plans Still Missing or Untested

  • OCR expects documented and tested incident response procedures per §164.308(a)(6)(ii). Lack of these plans can lead to both compliance penalties and extended patient harm—especially in ransomware and misdirected email scenarios. 

✅ What Clinics Can Do Right Now 

1. Refresh Your Risk Analysis: Ensure it’s updated, documented, and tied to your current environment. 
2. Review User Access Monthly: Terminate inactive or unnecessary accounts immediately. 
3. Develop & Test Your Breach Response Plan: Include a call tree, containment steps, and PHI impact assessment. 

🛡️ How SecureHealth Risk Advisors Can Help 

- HIPAA-Aligned Security Risk Analysis (SRA) – Built on NIST SP 800-30, tailored to your environment 
- Access Control Playbook – Templates and guidance for least privilege, revocation, and audit trails 
- Incident Response SOP Kit – Customized workflows and readiness training 

📬 Final Thought 

Enforcement in 2025 is no longer just about large hospitals or blatant negligence—OCR is now focused on routine failures in small practices. If you're still relying on old policies or haven’t tested your breach response plan, the time to act is now.

Read More