Healthcare has been the number one targeted industry for cyberattacks for 13 consecutive years. Now, the federal government is finally overhauling the rules - and the penalties for non-compliance are steeper than ever.
In this Q1 2026 HIPAA update, I break down the massive regulatory shifts hitting the healthcare industry right now.
I covers the newly proposed HIPAA Security Rule that eliminates "optional" IT controls, the February 2026 Notice of Privacy Practices deadline that most clinics have already missed, and the exploding legal risks surrounding Artificial Intelligence in healthcare. From staff members putting PHI into public ChatGPT servers to class-action wiretapping lawsuits over AI medical scribes, the compliance landscape has completely changed.
Episode Chapters:
(00:00:00) Q1 2026 HIPAA Landscape Overview
(00:02:35) The Proposed HIPAA Security Rule Overhaul
(00:07:25) Mandatory Patching & IT Vulnerability Rules
(00:09:09) The Missed Notice of Privacy Practices Deadline
(00:12:29) The Massive Legal Risks of AI in Healthcare
(00:14:44) AI Scribes and Wiretapping Class Action Lawsuits
(00:17:24) OCR Enforcement & Multi-Million Dollar Fines
(00:22:09) Vendor Breaches and Tracking Pixel Liability
(00:26:11) Legacy Email Systems: The Ticking Time Bomb
(00:31:24) 6 Immediate Action Items for Your Clinic