<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Health Insurance Portability and Accountability Act (HIPAA) news from Infosec Standards</title>
    <link>https://infosecstandards.org/standards/hipaa</link>
    <description>News about Health Insurance Portability and Accountability Act (HIPAA), including major updates to our page on it.</description>
    <language>en-us</language>
    <atom:link href="https://infosecstandards.org/standards/hipaa/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Standard pages now say who decides your obligation, and what to ask them</title>
      <link>https://infosecstandards.org/news/who-decides-what-to-ask</link>
      <guid>https://infosecstandards.org/news/who-decides-what-to-ask</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.</description>
    </item>
    <item>
      <title>Infosec Standards now has a free, browser-only risk assessment tool</title>
      <link>https://infosecstandards.org/news/risk-assessment-tool</link>
      <guid>https://infosecstandards.org/news/risk-assessment-tool</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.</description>
    </item>
    <item>
      <title>OCR settles HIPAA ransomware case with OSF Healthcare for $552,250</title>
      <link>https://infosecstandards.org/news/hipaa-osf-settlement</link>
      <guid>https://infosecstandards.org/news/hipaa-osf-settlement</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description>HHS OCR resolved a 2021 ransomware investigation with OSF Healthcare System for risk analysis, impermissible disclosure, and late breach-notification failures.</description>
    </item>
    <item>
      <title>HIPAA Security Rule overhaul pushed to July 2027 on the federal agenda</title>
      <link>https://infosecstandards.org/news/hipaa-security-rule-delay</link>
      <guid>https://infosecstandards.org/news/hipaa-security-rule-delay</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
      <description>HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.</description>
    </item>
    <item>
      <title>HIPAA Omnibus Rule is the current HIPAA rule set</title>
      <link>https://infosecstandards.org/news/hipaa-omnibus-rule</link>
      <guid>https://infosecstandards.org/news/hipaa-omnibus-rule</guid>
      <pubDate>Fri, 25 Jan 2013 00:00:00 GMT</pubDate>
      <description>On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.</description>
    </item>
  </channel>
</rss>
