
August 11, 2026
Posted by
Training & eTracking Solutions
If you work in home care, adult day services, or any corner of human services, you handle some of the most sensitive information a person can share: their diagnoses, their medications, their struggles, their story. Protecting that information isn't just a legal obligation under HIPAA — it's part of the same duty of care you bring to every shift. And in 2026, with regulators more active than they've been in years, the cost of getting it wrong has never been higher.
Protected Health Information (PHI) is any health information that can be tied to a specific person. That includes the obvious — diagnoses, lab results, medication lists, treatment notes — and the less obvious: names, addresses, birth dates, phone numbers, email addresses, Social Security numbers, insurance ID numbers, even photographs. When that information lives in electronic form (a scheduling app, an EHR, a text message, a spreadsheet), it's ePHI, and it's covered by HIPAA's Security Rule.
A useful frontline rule of thumb: if a piece of information could let someone figure out who a client is and something about their health or care, treat it as PHI. A first name plus a diagnosis in a group text is PHI. A photo of a whiteboard with client initials and med times is PHI. The "minimum necessary" standard applies to all of it — access and share only what you need to do your job.
HIPAA has three pillars that matter day to day. The Privacy Rule governs when PHI can be used and disclosed, and gives clients the right to see and get copies of their own records. The Security Rule requires administrative, physical, and technical safeguards for ePHI — including a documented, organization-wide risk analysis, the single requirement regulators cite most often when things go wrong. The Breach Notification Rule requires notifying affected individuals (and the government) within strict timelines — generally no later than 60 days after a breach is discovered.
Three developments make this a year to take HIPAA seriously:
1. Penalties went up. Effective January 28, 2026, HHS raised the civil penalty amounts for HIPAA violations under its annual inflation adjustment. Penalties are tiered by culpability, and at the top tier — willful neglect left uncorrected — they run to well over $2 million per violation category, per year.
2. Enforcement is accelerating. The HHS Office for Civil Rights (OCR) has now resolved more than 50 cases under its Risk Analysis and Right of Access enforcement initiatives, and OCR has confirmed the risk-analysis initiative is expanding in 2026 to include risk management — not just whether you assessed your vulnerabilities, but whether you actually did something about them.
3. A major Security Rule overhaul is coming. The proposed update to the Security Rule — the first major revision in over a decade — would make multi-factor authentication and encryption of ePHI mandatory rather than "addressable." Final action is currently targeted for 2027, but the direction is unmistakable, and organizations that wait to modernize will be playing catch-up under a deadline.
In one of 2026's most instructive enforcement actions, OCR imposed a $375,000 civil monetary penalty on Assured Imaging, a mobile diagnostic imaging provider, after a ransomware attack compromised the records of 244,813 people — names, birth dates, diagnoses, lab results, medications, and treatment information.
Here's the part worth sitting with: the penalty wasn't really about the ransomware. OCR's investigation found the organization had never completed an accurate, thorough risk analysis — the foundational Security Rule requirement — and then failed to notify affected individuals within the required 60 days. The attackers exploited weaknesses that a basic risk analysis is designed to surface. On top of the fine, the organization is now under a corrective action plan with two years of OCR monitoring.
The pattern is bigger than one case. OCR announced this penalty alongside three other ransomware-related enforcement actions — $320,000, $245,000, and $225,000 against a women's health group, an employee health plan, and a benefits administrator — more than $1.1 million in total. Every one of them traced back to the same root failure: an inadequate or missing risk analysis.
Most HIPAA violations don't start with hackers — they start with everyday habits. The behaviors that protect your clients and your organization are simple and learnable: follow the minimum-necessary rule; never share logins or leave screens unlocked; keep PHI out of personal texts, email, and social media; verify before you disclose; and report anything suspicious immediately — the 60-day breach clock starts at discovery, and fast internal reporting is what keeps organizations on the right side of it.
Train your team on it — the right way. Our HIPAA course walks direct care staff through PHI, the Privacy and Security Rules, and the real-world do's and don'ts of protecting client information — with a scored assessment and automatic completion tracking, built for annual refresher cycles. It's one course in a compliance platform that tracks every requirement, renewal, and certificate for your whole team.
HIPAA compliance isn't a binder on a shelf. It's a yearly rhythm of training, an honest look at your risks, and a culture where protecting a client's information is treated as part of protecting the client. The organizations paying six-figure penalties in 2026 aren't the ones that had a bad day — they're the ones that skipped the fundamentals. We can help you get them right.