VanRein Compliance Podcast

What We're Listening for at this Week's HHS + NIST HIPAA Security Conference

Rob & Dawn Van Buskirk

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 20:26

Send us Fan Mail

A major HIPAA reset is brewing, and the timing couldn’t be more urgent. We’re headed to the HHS, OCR, and NIST Safeguarding Health Information conference to hear directly from the people shaping what “good” looks like for HIPAA Security Rule compliance in 2026 and beyond, and we’re sharing exactly what we’re listening for.

We talk through the likely headline items: OCR updates after a long gap, a stronger push toward risk analysis that behaves like a real audit, and the patterns OCR keeps calling out when organizations fall short. We also dig into the controls that keep coming up in real enforcement and real breaches: multi-factor authentication, penetration testing, incident response planning, and disaster recovery testing. If your security work is still “we did it once and filed it,” this conversation is your nudge to build ongoing evidence and remediation into the way you operate.

Then we zoom out to the messy, modern reality of healthcare data. Vendor risk management is still a huge weak spot, especially as third parties, subprocessors, and AI tools multiply the paths ePHI can travel. We also get nerdy about what’s next with AI in healthcare, the NIST AI Risk Management Framework, and why regulation will struggle to keep pace. And we don’t ignore the physical world: medical device cybersecurity and IoT mean ePHI no longer lives only inside an EHR or EMR.

Subscribe so you don’t miss our post-conference breakdown, and if this helped, share it with a teammate and leave a quick review so more healthcare teams can find it.

Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook