The loudest fight over HIPAA security right now is about a proposed rule, but the compliance problem the Office for Civil Rights keeps finding is older than the proposal.
Writing in the HIPAA Journal, compliance attorney Jake Dewberry, JD, recounted two days at the NIST campus in Gaithersburg, Maryland, where the standards agency co-hosts a HIPAA security conference with OCR. The gathering draws the people who write guidance, enforce it, and carry compliance responsibility inside healthcare organizations.
Dewberry expected most of the attention to fall on the proposed Security Rule overhaul, which was published in January 2025 and has drawn roughly 4,745 comments, many arguing the requirements would cost too much and hit the least-resourced organizations hardest. He found the objections partly correct, but noted that a significant share of the pushback is aimed at obligations that already exist.
What OCR’s own sessions kept returning to was the risk analysis. It has been mandatory since 2005 and turns up missing or deficient in nearly every enforcement action the agency brings. For security leaders, that is the uncomfortable part: the debate over what compliance will cost in 2027 can obscure the fact that many organizations are not meeting the requirements already on the books. Risk analysis is also the control that makes the rest of a security program defensible, because it ties spending to identified threats.
Dewberry’s takeaway is less about the rulemaking calendar than about sequencing: fix the baseline first.