VanRein Compliance Podcast
Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
VanRein Compliance Podcast
What We're Listening for at this Week's HHS + NIST HIPAA Security Conference
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
A major HIPAA reset is brewing, and the timing couldn’t be more urgent. We’re headed to the HHS, OCR, and NIST Safeguarding Health Information conference to hear directly from the people shaping what “good” looks like for HIPAA Security Rule compliance in 2026 and beyond, and we’re sharing exactly what we’re listening for.
We talk through the likely headline items: OCR updates after a long gap, a stronger push toward risk analysis that behaves like a real audit, and the patterns OCR keeps calling out when organizations fall short. We also dig into the controls that keep coming up in real enforcement and real breaches: multi-factor authentication, penetration testing, incident response planning, and disaster recovery testing. If your security work is still “we did it once and filed it,” this conversation is your nudge to build ongoing evidence and remediation into the way you operate.
Then we zoom out to the messy, modern reality of healthcare data. Vendor risk management is still a huge weak spot, especially as third parties, subprocessors, and AI tools multiply the paths ePHI can travel. We also get nerdy about what’s next with AI in healthcare, the NIST AI Risk Management Framework, and why regulation will struggle to keep pace. And we don’t ignore the physical world: medical device cybersecurity and IoT mean ePHI no longer lives only inside an EHR or EMR.
Subscribe so you don’t miss our post-conference breakdown, and if this helped, share it with a teammate and leave a quick review so more healthcare teams can find it.
Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook
Conference Week And The Big Players
RobWell, Don, this week is exciting because this week is conference week, isn't it?
DawnIt is, but not just any conference.
RobBoom. What a conference is it?
DawnIt is the HHS, OCR, and NIST safeguarding health information, building assurance through HIPAA security 2026. Boom.
RobThat's a big boom because we've been talking about this for like what two months? No longer than that. Talking about it. And I'm excited. I'm excited to get to uh to just be at the conference and go through this. This is just so people know, they haven't had a conference in two years. It just it hasn't happened. And all of a sudden, finally we're gonna have it this year. So here's some of the players that are gonna be there. First of all, we know OCR. Boom. Right, boom. HHS, boom.
DawnYeah.
RobNext, boom. A lot of HHS cybersecurity leadership because they're gonna tell us what they're looking for. And it goes to the FDA, the FTC. People forget FTC has jurisdiction over healthcare and the HIPAA. ONC, healthcare CISOs, and like us, amazing compliance guides and owners. We're just very excited to be there.
DawnYes, we'll be awesome.
SPEAKER_00Welcome to the Van Ryan Compliance Podcast with Rob and Don. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm.
RobAnd with that, welcome to the Van Ryan Compliance Podcast. I'm Rob. And I'm Don. And as Don said, we are excited this week because we are going to focus on uh this week's podcast will be focusing on what we anticipate as we attend the HHS OCR uh NIST conference this week. So there's there's a lot of expectations, at least I have expectations, so do you. So we're gonna go through what we're expecting to come out. And then obviously our team will come back and we will start putting information out this week of what was discussed, what was real, what's fake, right? And what do we need to do and how to help you, our listeners, get through the new regulations.
OCR Updates We Are Watching
DawnRight.
RobSo the first thing that I'm looking for really is OCR updates. That's usually the first thing they do. They haven't done this in a couple of years. So it's really going through what's the Office for Civil Rights done, what's updates to frameworks, what has the organization's done, and then moving into that, you know, HHS cybersecurity activities.
DawnMm-hmm. Mm-hmm.
RobSo what are you looking forward to, Don, as we go through days?
DawnWell, as we know, we we've heard that the security rule is getting updated. And we've heard, you know, and seen a bit of an outline, a preview, if you will, of what's to come. I really want uh to get specifics on that. And the big thing is is when? When is this going to go into law? Um, they're proposed right now. The other piece of that is I'm very excited about um because AI is a thing. It's here, it's here to stay. So, how is HIPAA and AI? How how is this gonna intersect? So, really excited to they've got some uh their cybersecurity folks on the forum. It'll be really exciting to hear about how it's going to tie in to HIPAA.
Security Rule Changes And Audit Focus
RobYeah, and I think a lot of the key pieces, there's a lot of talk about risk analysis and audits. I think they're gonna move the actual term from analysis to audit, which it really is anyway, but just really focusing on the different types of audits and really focusing on that risk management because there's with all the subprocessors and all the additional companies that are actually utilizing the data and the AI platforms and all of that, there's a lot more risk to health information than there has ever been. I also hope they address where organizations are falling short. They usually do. Two years ago, the education, the biggest issues that they they had noted were lack of audits and training and then very lackluster policies. Those are kind of the three trifectas that I I remember from two years ago going to DC and uh going through the conferences and then understanding what those are. What about like some of the vendors and evidence, Don? How about how about diving into some of that? What do you look forward to in there?
Vendor Risk And Third Party Breaches
DawnYeah, I look for, you know, the they to them to uh put stricter requirements on uh on third-party vendor risk assessments because as we have seen, that is the big, big gap of of all clients that I we talk to, prospects, just people in general, is that they're not vetting their vendors. They're just trusting, trusting they have what they need. So I'm I'm interested to see if they if they make a note of that. Because if we as we've seen on the Hippo Wall of Shame, which Rob showed last podcast, yeah, and it is a thing, the a lot of the hacking uh incidents are from third parties.
SPEAKER_03Well yeah, most of it is yeah.
DawnI mean, EMRs, I mean, there was that huge one just a little bit ago. They're doing it. And so um they're having issues. So that's gonna be I I'm interested to see about that, definitely.
RobYep. And then basic security hygiene is how do we how do we compute securely and how do we do this correctly? I think they're gonna dive into that. I also think they're gonna be diving into things they want to fix this year, you know. So I think the OCR get every healthcare organization to fix one thing. Let's see. If they can get us to fix one thing, I would say it's gonna be audit. Maybe remediation. What do you think of that?
DawnYeah, I think it is all that. Uh, I mean, yes, I think I they need to have just more robust. I think they need to add some some more robust controls to the security rule. Yeah.
RobYeah, definitely. Yep. And then the cyber threat piece, you know, as we as we dive a little bit deeper, one of the things that the HHS and and NIST is going to obviously focus on is a cybersecurity threat briefing. So the threat briefing is fun because we get to see the actual issues going on, you know, in the industry. We get to see what the problems that we're seeing. So it's so what I like when NIST does their cybersecurity threats, we're seeing it not just on the healthcare sector, but all sectors. What is NIST seeing in manufacturing and in energy and financials and all of that? Some of the big players in the US, what does that really look look like? And then, you know, that's really, really telling, isn't it, Don?
DawnSo yeah. Yeah. Yeah. Just uh the panels. Um, they're gonna have some panels and that's gonna be really great. It seems more uh expanded on the the forums this year panels, uh, and just more information than when you went two years ago, Rob. It seems like there's more that they're doing. Maybe, maybe y'all gave them feedback.
SPEAKER_03Oh, yeah.
DawnUm, maybe there's gonna be some more question answer. I'm really excited to see what industries are there, you know, and and really what they're seeing on their side and and hopefully they're they will allow some some questioning uh from the from the audience. So that's gonna be really cool to see. But yeah, it it's gonna be really exciting. I know we're getting nerdy, we're getting all excited about about a HIPAA conference, but we we do the HIPAA. It's the HIPAA. Yeah, we do we love the HIPAA. The HIPAA. And so um, yeah, we're just excited. We're excited to let everyone know what we find out.
Pen Testing MFA And Incident Response
DawnYeah, so what are some of the uh let's talk about some of the things we I guess we know um that they are proposing, if you will. The two things that stick out in my mind, uh number one, pen testing, which uh yeah, that is a huge gap. And the second one is MFA, which honestly, if you're not doing MFA, you know, that's been around for a while. But those are the two that stick out in my mind um on that kind of that, you know, this is the proposed. There's a whole lot of other ones, but it it'll be interesting you know, to see um what they end up putting into law of the items they propose. So what are the things are you are you seeing, Rob, that they're they're proposing that that you wanna hear about?
RobYeah, like you mentioned, pen testing, MFA, I think disaster recovery testing. Yes, the incident response is how you gonna respond to the incident right now. You there it's kind of vague and it's been vague, it's also been sitting for quite a few years. How are you gonna respond to the incident? How are you gonna engage your uh your customers, the media? How do you do that? How do you work with your your actual uh insurance companies and get through all that? And really, really focusing on you know that response. I think those are gonna be the the big areas. We'll probably get a little bit of an update from the insurance industry as well. NIST is usually pretty good about that because they talk about what they're seeing, we know what kind of what kind of claims you're paying out, and then what uh what I'm excited about is then they'll tell us what the insurance industry is looking for as they create new policies. Those are kind of the key pieces. Yeah. Absolutely.
AI Meets HIPAA And NIST Guidance
RobAnd then the day two topic is your AI, as you talked about. And I know it's it's you know, it's not just it's not just the hot topic. It's actually going to change how we work. We we were Don and I were talking about this the other day, is when we went to college, the internet was the thing data ourselves, 92, 3, 4, 5, right? And then technology was huge and it got into that. Then the dot-coms was expansive and great. And we've talked about Ethan in our on our podcast going to uh going to college. And now this is the what's exploding is AI. AI is the same trajectory uh to impact society as the internet uh was and is from the late 90s. So we're gonna see a lot of of AI focus on uh in healthcare, the NIST AI risk management framework, which we can already do today. Uh, they're probably gonna update that one. And then uh that round table you mentioned, the AI in healthcare, which is gonna be really critical to see see how that looks.
DawnSo yeah. And AI is moving so fast that what we talk about this week, it's gonna look different in a couple months.
RobSo look different next week.
DawnYep. Interested to see how they what they what they see, you know, on their end and what um, you know, how are they going to keep up with it? Now, how are they gonna keep up with these changing times, what the NIST is doing to keep up with the the controls and and that type of thing.
RobSo Yeah, I don't think there's gonna be an overall law. I think there'll be recommendations. I think there's gonna be guidance. I think they'll bake it into the already laws because if you you look at Europe, for example, there's certain models they can't use because they don't meet the EU or GDPR standards or location standards where the data has to reside in the EU. When that happens what happens if we do that here, then that stifles the innovation. So I don't think there's gonna be big changes like a new law, but I think they're gonna reinforce what's already done. So do you think AI is getting adopting quicker than regulation?
DawnMm-hmm.
unknownYeah.
RobYou're gonna cover that.
DawnI yeah, yeah. I think it's going faster than we've we're just doing it. And uh I think it's definitely faster than the internet. When the internet came on, it was kind of a little bit hit or miss. Well, remember it was the dial up. Remember the the A. You know, remember the like a fax machine kind of that sound?
SPEAKER_03Yeah.
DawnSo AI is just moving so fast. Um, but yeah, I I don't think that you know it's going to be this huge I I think it's just so it's changing so rapidly, but it's just going to be interested to see how they're gonna handle it. You know, so that's gonna be really good. But obviously we're we're talking about, you know, you know, the HIPAA. I mean, we're we're you know, that's the main the main focus. But yeah, and when they're going to what they're gonna put into law. What you know, what what does that look like?
RobYep.
DawnYeah.
RobAnd it's it's what's funny is the law hasn't changed. The data's still the data. It's just how we we leverage the data or the tools we use to access the data has changed. Yeah. But the law is still the same. Nothing's changed there. The keys are just understanding your risk and control access on document decisions. I think they're gonna really dive in, dive into those areas as well.
DawnYep.
Medical Device Cybersecurity Roundtable
RobThe you know, kind of that next piece, I think on that second day also dives into the attack surface. Remember, there's still a big issue with physical devices. And one we haven't talked about a lot is the medical device cybersecurity roundtable. That's gonna be interesting. So you know, you go to hospital, heck, you go to you go to the dentist now, and they they take your blood ox, right? These are all IoTs, Internet of Things. Everything is an IP, everything's connected. So what you know, what is that gonna look like? And and for the medical device roundtable, they've got, uh I was looking at the agenda. There's a representative from NIST, from FDA, obviously there's clinical engineering folks in there. Siemens is gonna be there, uh, the Health New Years, and then the cybersecurity researchers are gonna be there to really kind of dive into seeing, you know, how how are the devices at hospitals and medical practices leveraging technology and AI to be to have better outcomes, but that also gives bigger risk.
DawnSo well, and ePHI isn't just inside uh EHR or EMR anymore. It's in tons of devices. It's in uh translation devices. I mean, it's in it's in everything. And so, you know, basically, yeah, how what do we what what's new there? What's new? Is there any new controls, any new guidelines regarding that?
unknownYeah.
RobYeah, I think of like heart, you know, heart devices. You're you're you're plugged in when you're at the hospital, plugged into everything. You know, you've got to make sure where's that data going? And hospitals have Terra Petaf, I guess, petaflops, giga flops? Lots of data flops. I have to do my flops on a Monday. Yeah, I think they're gonna dive into the medical devices and the monitoring systems and the internet of things. And then it has to deal with the old legacy stuff. It's been there forever. That old stuff is just you know, the old platforms that someone built 10 years ago that nobody knows how to turn it off and keep it going. So um, but who who really owns the risk, Don, do you think, when it comes to the comes to this framework for these medical devices?
DawnWell, you go back to HIPAA, it's who creates the medical record.
RobYeah.
DawnRight?
SPEAKER_03Yep.
DawnSo who's creating the medical record? If the device is creating the medical record, there's a lot. And I I think the big thing is we have it's ePHI is what we're talking about. It's everywhere. It's on devices, it's in a EMR, EHR, it's in a cloud, it's in a file, it's in a it's all over. So it's it's how do we monitor it across all our technologies? And that is is again a huge gap. The vendor vendor management. We use things all over the place. How do we bring it together? How do we how do we monitor it you know overall everything?
SPEAKER_03Yeah.
DawnAnd that these gaps, and obviously not having a pen test and things like that, there's gaps and things people get in. Things leak, you know, and it's uh and so it's it's very interesting. There's just cybersecurity is uh yeah, that's gonna be that's gonna be a good conversation, is is kind of what are they, what do they see, what are they doing, what are what's what's to come, what's to be expected.
RobUm that's the that's I'm excited, the data leakage piece with the medical devices. Where is it all going? And I'll tell you right now, it's everywhere.
SPEAKER_03Yeah.
RobAnd we're in everything. Yep.
SPEAKER_03Yep.
RobThose are the key pieces.
SPEAKER_03Mm-hmm.
Remediation Evidence And Continuous Compliance
RobNow, you know, we'll go through the AI pieces, and but I think it's gonna keep coming back to the risk analysis. It usually does. Two years ago it does, it did. And they've hinted on this. HHS has hinted on this multiple times, but really talking about have you performed an audit? Have you gone through the controls and not just say, oh, you have a SOC2 or an ISO or a high trust? Those are all very valid and valuable frameworks, but there's only one law, and it's the HIPAA is the law. So take anything away from the podcast this week is HIPAA's a law. Put that on a bumper sticker, right? Uh actually we'll put that in our swag store. That'll be good.
DawnYeah.
RobBut it's the, you know, those cyber threats and the FTC privacy. People forget about FTC came in here about three years ago. So now they're looking at the privacy of everything.
SPEAKER_03Mm-hmm.
RobThose are the key pieces. But what do you think, Don, the the value of OCR and NIST coming together and presenting this thing?
DawnYeah, no, I think that's great. I think it's perfect because when you went, it was just HHS. It was just the yeah. No, I think it's great because the NIST is the foundation. You know, it's the backbone. And the foundation doesn't change. HIPAA, it the foundation has been built. It's just sure, you maybe have added controls, maybe you have things that you need to add, you know, add some requirements, but the foundation hasn't changed. And, you know, if you look at other compliance programs, you know, that aren't a law, you know, the foundation, some of them don't change either. And then they add on, you know, extensions and things like that of of certain of certain controls and and that type of thing. But HIPAA doesn't, it has not really changed. I really hope that that this isn't minor changes. I hope that there's some real, they put real teeth into it. Um, because folks, you're, you know, nothing will happen, nothing will ever. Those days are over. They've been over. People need to realize that they have any EPHI running through their their network. They need to have an audit. They need to have policies and procedures of if an incident happens, a breach occurs, and they need to have training. There, everyone needs to have training on what it is and what to do and and how to how to how to utilize it and not utilize it, you know. So this is gonna be great to see both those both organizations together.
RobYep.
DawnEveryone in one room, if you will.
RobIn one room. And I think you're also gonna focus on don't just do the assessment, what's remediation? You know, don't just check remediation implementation as well.
DawnHow many people have done something and then they just say, Well, I did it and I'm done? No, you have to do it every year. You have to implement it, you have to do it every year. And people know this, they just for some reason they they don't want to deal with it. Yeah.
RobWell, it's like I I read a SOC 2 report uh today, and this company did or did their 90-day uh evaluation period and they got their report, but there's no evidence after. Like, oh, we did it once, we're good. No, I want to see it, I want to see it like eight months down the road. I want to see it four months down the road.
SPEAKER_03Yeah.
RobLike, what are you really doing? What type of the software and vendors and migrations and everything are you really what have you really done? And then your strategic partners, I like to call them, the companies you work with, your vendors, a lot of people call them, they're rolling out AI, and that AI is rolling out that AI, and that AI is agentically talking to others. So there's the data link. Just keeps it keeps going.
DawnYep. Absolutely.
RobIt just keeps going.
DawnYeah.
RobSo those are some of the areas that that I think both you and I are excited about for the conference this
How We Will Report Back
Robweek. And of course, we're going to be taking notes, we're going to put it together. Uh, Jinny and the team here at Van Ryan will be blasting it out on social and our newsletter and everything that we see. And then what's great about what we do is we really help our clients guide through the new regulations. So we get the new regulation, well, we get the new information this week. Who knows if there's a change in a month and three months or a year? We don't know. And then our team will go through that regulation and put together the plan. We put together the audit requirements, you're going to put together the policies, procedures, any changes to training. We make the changes and you as a client get to reap the benefits. You don't have to deal with all of that.
DawnRight. Yep.
RobYep. Well, I think that's it, Dawn. I think we did really good this week. So thank you everybody for joining. We appreciate everybody popping in the Van Ryan Compliance podcast. And next time, we're going to bring everything we learned from the conference. And then this week we'll be pushing out information on uh day by day and what we learned. So hope you have a great week. Until next week, I'm Rob.
DawnI'm Don.
RobAlrighty.
DawnBye bye. Bye bye.