On September 2-3, 2026, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2026 conference.

Epstein Becker Green (“EBG”) was fortunate to attend and, below, shares takeaways in three key areas highlighted at the conference.

(1) Update on Federal Viewpoints on AI Oversight

A clear cross-agency AI theme emerged during the conference: Trustworthiness continues to serve as an organizing principle for federal AI oversight in health care. NIST, the Food and Drug Administration (“FDA”), the HHS Office of the National Coordinator for Health Information Technology ONC (“ONC”), and OCR each signaled attention to trustworthy AI, positioning it as the connective tissue linking security, safety, and privacy obligations across the health data ecosystem.

Two key themes stood out.

First, ONC’s remarks centered on governance, echoing HHS’s newly released AI Strategy. As we previously explored here, HHS’s five-pillar AI Strategy elevates “Governance and Risk Management for Public Trust” as its lead pillar, formalizing a department-wide AI Governance Board and an “outcomes-first,” use-case-driven approach to adoption. ONC’s remarks reinforced that governance — not just technical safeguards — will anchor how health AI is deployed and overseen going forward.

Second, NIST panelists previewed the ongoing refresh of the NIST AI Risk Management Framework (“AI RMF”), still anchored in the concept of “trustworthiness” first codified in the National Artificial Intelligence Initiative Act of 2020 (“NAIIA”). Since its inception, as we discussed here, we have been tracking how the NAIIA impacts AI governance in the public and private sectors. In particular, the NAIIA directed NIST to develop voluntary standards and a risk management framework built around trustworthy AI — privacy, security, bias testing, and robustness among its pillars. NIST’s continuing maturation of the AI RMF, including sector-specific profiles, keeps that statutory trustworthiness mandate at its core.

Together, these themes suggest OCR’s HIPAA Security enforcement priorities will increasingly intersect with NIST, FDA, and ONC's parallel efforts to operationalize trustworthy AI across health care.

(2) Update on Cybersecurity Issues

An HHS roundtable discussion at the conference provided an update on breach trends and cybersecurity activities in the health care industry. The timely discussion comes as health care organizations face increasing and more sophisticated cyberattacks. Key points noted in this discussion include:

Hacking represents the biggest risk of breach. The vast majority of HIPAA breaches are now caused by hacking incidents. Indeed, of the 338 large breaches (affecting more than 500 individuals) reported to OCR so far in 2026, 313 reports (92.6%) identified the type of breach as “Hacking/IT Incident,” and 236 of those identified the location of breached information as “Network Server.”  

Extortion is evolving. Cyberattacks against health care entities continue to be part of extortion schemes. However, there is a shift away from the scheme of data encryption and ransomware to data exfiltration or dual modality schemes. This shift is, in part, a response to health care entities making improvements in data backup and restoration.  

Rapid rise of AI. AI is increasingly being used to exploit cyber vulnerabilities. Not only has AI significantly advanced the sophistication and success rate of malware, but AI-enabled attacks are identifying weaknesses and exposing critical security gaps.  

Additional conference sessions discussed the various NIST resources available to assist health care entities with these cybersecurity issues, including: 

  • NIST AI Risk Management Framework (the previously mentioned AI RMF), which can assist health care entities in identifying, assessing, and mitigating risks from AI systems across their lifecycle;
  • NIST CSF Profiles, which work to customize the NIST Cybersecurity Framework to specific organizational contexts and risk tolerances; and
  • The recently updated Risk Identification and Site Criticality 2.0 (RISC 2.0) Toolkit, which is a cybersecurity module that can be used for identification and assessment of cyber risks against the NIST Cybersecurity Framework and HHS Cybersecurity Performance Goals.

Health care entities can leverage these resources by:

  • Using AI RMF to manage security risks from AI-driven diagnostics and clinical tools;
  • Applying CSF Profiles to align cybersecurity practices with regulatory requirements (HIPAA, HITECH); and
  • Implementing structured risk assessments for protecting patient data and medical systems.

(3) Update on Post-Quantum Computing Encryption Standards

While the world’s collective gaze has been fixed on AI of late, NIST remains committed to encouraging organizations to plan for another crucial vulnerability: the anticipated attacks on current, widely-deployed public-key cryptosystems using quantum computing. For clarity, while quantum computing research applications exist today, the direct cybersecurity risks posed by quantum computing remain some time off. Experts differ on precisely when, but most agree that Post-Quantum Computing (“PQC”) cybersecurity threats will likely become a reality sometime within the next 10 – 15 years, with a significant minority estimating as early as 5 years.

Why is this a problem for today? As discussed by the presenting panelists and as echoed in other panels at the conference, there has been a noticeable shift towards exfiltration as a primary goal of cybersecurity attacks, as opposed to immediate monetization via ransomware. While exfiltrated data in encrypted form may today be unusable, NIST reminds us that, if and when PQC becomes a reality, this stockpile of data could later be accessed by threat actors. This means that data protected by legacy encryptions algorithms may only delay, not prevent, the unauthorized access to this data.

What can be done (and when)? Thanks to the foresight and long-term effort of NIST and leading cryptologists, we have new post-quantum encryption algorithms already developed and ready to deploy that can stave off cyberattacks by both the conventional computers today and the quantum computers of tomorrow. On August 13, 2024, the Secretary of Commerce approved FIPS 203, 204, and 205. In conjunction, NIST has developed a roadmap for implementing the new FIPS standards through its publication of NIST Special Publication (SP) 800-131A Rev. 3 (“Transitioning the Use of Cryptographic Algorithms and Key Lengths”), currently in draft form. The public comment period closed for Rev. 3 at the end of 2024 and has been under review at NIST since that time. Publication of the final document is anticipated soon. However, NIST panelists stressed the need for organizations to start the process now and not wait for the final draft. Migration to the new encryption standards is a major undertaking, which includes a full inventory of systems and end-points, managing public keys, and vendor management. Regarding this last point, organizations are encouraged to begin inquiring about the roadmap of their vendors for implementing the new FIPS standards and building in contractual requirements in their contract terms. If your organization is looking for a yardstick, the federal government’s goal is to mitigate all federal systems by the year 2035. Organizations can learn more about the unique set of problems arising from PQC and the efforts to address them on the NIST dedicated PQC Page.

As the threat landscape evolves, and the likelihood and magnitude of downside impacts grows, we encourage organizations to leverage guidance emerging from these federal efforts as a means to manage these increasing risks. We will continue to monitor developments and provide updates as they emerge.

* * * *

If you have questions, please reach out to the author(s).

The Health Law Advisor blog is currently edited by Emily Chi Fogler.

Back to Health Law Advisor Blog

Search This Blog

Authors

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Health Law Advisor posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.