Pull your cyber liability application. Check three claims against reality: encryption verified, risk assessment current with remediations, training that matches operations.
Paperwork that does not match how you work is how denials start.
Ask your MSP one question: which administrative safeguards do you own, and where is that written?
Firewalls and patches are security work. "We handle HIPAA" with no named admin controls is a hope, not a scope. Write the split down this week.
"Our IT company handles HIPAA" is the most expensive sentence in healthcare.
Ask them which administrative safeguards they own. Most MSPs cover some technical work. That is not Privacy Rule work. If they cannot name the admin controls in 30 seconds, you still own the gap.
Would you bet your audit on training nobody remembers by Friday?
Most HIPAA training is theater. Click, quiz, forget by Friday. Audits care about changed behavior, not completion rates. Completion is a checkbox. Retention is the actual control.
Ambry Genetics paying $700K and taking a 2-year CAP after phishing exposed 225,370 patients is the public Security Rule reminder: access control and workforce training are living controls. Someone still has to own them after the vendor pitch ends.
https://t.co/B8O9Sb3jU0
OCR listed a $700,000 Ambry Genetics settlement this week. Phishing. About 225,000 people. The attack started in 2020.
Compliance is a living thing. What changed in your org in the last 90 days, and what control did that change quietly break?
A healthcare software vendor settling nearly $3M after a cyberattack that hit almost 200k patients is the bill that arrives late. The expensive gap is earlier: what the paperwork said was in place versus what was actually running when attackers hit.
https://t.co/J01rBbGFie
The Florida-based healthcare software vendor Modernizing Medicine has agreed to pay $2,999,750 to resolve class action litigation over a July 2025 cyberattack and data breach that affected almost 200,000 patients.
https://t.co/BdSERFSOpg
Their cyber application said they had encryption, a current risk assessment, and real training. The claim denial said otherwise.
Paperwork is not posture. That gap stays invisible until ransomware, a claim denial, or OCR makes it expensive.
Same logo. Two products. Which one did your staff just paste a patient name into?
Before you trust a HIPAA badge: name the SKU, hold a signed BAA that covers that surface, and know what is carved out. The homepage claim is not the contract.
HIPAA never certified a product. Marketing had to invent the badge.
A landing-page HIPAA claim is not a stamp from HHS. There is no product certification. SOC 2 is not HIPAA. A BAA covers a named surface, not every chat that shares the logo.
If your last "risk assessment" is a filled-out form with no proof the fixes happened, OCR already has a name for that.
A questionnaire is not a risk analysis. Assess, map the fixes, implement, document. OSF paid $552,250. OCR wrote down the analysis, not the malware brand.
A patient asked for her records in January 2023. She got them in January 2025, after OCR opened a case.
Azul Vision. $50,000 + 2-year CAP. OCR's 55th Right of Access action.
Monday check for covered entities: how old is your oldest open access request sitting?
A 5.8M imaging breach is not just their problem.
If Lumexa held your patients' data, you still own the outcome. The signed BAA is one question. Whether that vendor can still back it up is a different one.
https://t.co/awiSpsT0nZ
Would you bet your audit on training nobody remembers by Friday?
Most HIPAA training is theater. Click through, quiz, forget. Completion rates look great. They measure clicking, not behavior.
Audits ask whether anyone still knows who to call. Not that 100% finished the module.
Check what your vendor named the bot.
Oregon: an AI agent may not use RN, NP, LPN, CNA, or any other nursing title. In force since January.
The violation is the badge on the chatbot, not the model behind it. If it is labeled nurse, that is the violation.
"That's way better than the $29 training nobody even watched."
Said on a call, looking at role-based training with their own security officer's face on it, next to the generic module they'd been running.
The audit doesn't ask who clicked through. It asks whether the behavior changed.
California has required an AI disclaimer on clinical patient messages since January 2025.
Unless a licensed human reviewed the message first. Scheduling texts do not count. Anything about their clinical information does.
Eighteen months in. Still news to a lot of clinics.
A billing vendor's breach just became a problem for 4,500 oncology practices that had nothing to do with it. Second cascade in three weeks.
The practices did not get breached. Their vendor did. They still own the outcome.
"We support your program" means you still own it alone.
In Texas, a clinician has to review every AI-generated clinical record.
Not a suggestion. Medical Board standard, in force since September 2025. Offshoring those records is also off the table.
If the scribe writes it, a human still signs it.
Another hospital got hit by ransomware this month. 25 beds. Rural Missouri.
I don't know their IT setup. That's not the point. At that size, HIPAA often got handed to the IT company by default.
Ask if compliance is in scope. The pause is the answer.