HIPAA Tightens Health Data Security
Coverage from The HIPAA Journal, CDT, and others

U.
S. health data regulators and lawmakers are moving toward stronger security, privacy, breach notification, and vendor oversight requirements. Proposed HIPAA Security Rule revisions would emphasize measurable controls such as multifactor authentication, encryption, vulnerability management, testing, segmentation, incident response, and documented risk decisions, while enforcement increasingly examines ransomware resilience, patient access, health apps, tracking technologies, and third-party practices. Separate Senate legislation would address consumer health data that falls outside HIPAA, but it remains at an early procedural stage.
The story broadens from HIPAA-focused security and privacy changes to a wider regulatory push that now explicitly includes FTC and DOJ scrutiny, plus additional 2026 agenda items affecting interoperability and health IT.
The story now extends beyond HIPAA rulemaking to explicitly include consumer health data protections outside traditional covered entities, especially wearable, fertility, mental health, fitness, and wellness data. It also sharpens the procedural status of the Senate bill and adds more specific enforcement priorities around ransomware, access, tracking technologies, and AI.
