August 6, 2026 | Clearwater Healthcare Cyber Briefing
This session will cover key topics in HIPPA enforcement and risk management relevant to healthcare organisations today.
Beyond Compliance: Risk Analysis, Risk Management, and the Future of HIPAA Enforcement
Executive Summary
Healthcare organizations continue to face an increasingly complex cybersecurity and regulatory environment. While proposed HIPAA Security Rule updates and other federal initiatives continue to evolve, one expectation has remained consistent: regulators expect healthcare organizations to conduct meaningful risk analyses and actively manage the risks they identify. Listen to experts discuss HIPAA enforcement and risk management and the future of healthcare cybersecurity.
In Clearwater’s August Healthcare Cyber Briefing, Dave Bailey provides an update on the latest cyber threats affecting the healthcare sector before joining healthcare attorneys Robert Kantrowitz, Partner at Kirkland & Ellis, and Iliana Peters, Shareholder at Polsinelli and former Acting Deputy Director at the HHS Office for Civil Rights (OCR), for a discussion on HIPAA enforcement, cybersecurity risk management, and what healthcare leaders should prioritize now.
The conversation reinforces that compliance alone is not enough. Organizations must be able to demonstrate that risk analysis leads to meaningful action, continuous risk management, and ongoing cybersecurity improvement.
In This Discussion
This briefing explores questions including:
- What is OCR looking for during HIPAA investigations?
- Why are risk analysis and risk management still the foundation of HIPAA compliance?
- What cybersecurity threats should healthcare organizations prioritize today?
- How is AI changing healthcare cybersecurity risk?
- What should covered entities and business associates be doing now?
- What does effective HIPAA compliance look like beyond documentation?
What Are the Biggest Cybersecurity Risks Facing Healthcare Today?
Dave Bailey opens the briefing with a review of the latest cybersecurity developments affecting the healthcare sector.
One of the most notable trends is the increase in ransomware activity. July became the busiest month of 2026 for publicly reported ransomware data leaks, driven largely by attacks against dental practices and specialty healthcare providers.
The discussion also highlights the growing impact of frontier AI models on cybersecurity. Recent disclosures involving AI systems interacting with production environments demonstrate how quickly AI capabilities are advancing and why organizations should begin treating AI governance as a cybersecurity priority rather than a future consideration.
Dave Bailey: “AI capability is outpacing AI governance inside your organization and your vendors.”
Rather than viewing AI solely as an innovation tool, healthcare organizations should evaluate how AI affects enterprise risk, vendor management, and security governance.
Why Should Healthcare Organizations Inventory AI?
The briefing explores several recent AI security disclosures involving frontier models that interacted with production systems during testing.
Although these events occurred in controlled research environments, Dave Bailey explains that they illustrate how quickly AI capabilities are evolving and why organizations should improve visibility into AI across their environments.
Healthcare organizations should know:
- Which AI tools are in use
- What data those tools can access
- Which systems AI can interact with
- Whether vendors have appropriate governance controls
- How AI systems are monitored over time
The discussion also emphasizes that AI governance should include contractual expectations, technical safeguards, and continuous oversight.
What Does OCR Expect During HIPAA Enforcement?
The conversation then shifts from cybersecurity to regulatory enforcement.
Robert Kantrowitz and Iliana Peters explain that OCR has consistently emphasized one principle during investigations:
Organizations must perform meaningful enterprise-wide risk analyses and actively manage identified risks.
Simply documenting risks is not enough.
Healthcare organizations should be prepared to demonstrate that they have evaluated risks, prioritized remediation activities, allocated resources appropriately, and continuously monitored progress over time.
The panel explains that this expectation has remained remarkably consistent across multiple administrations and continues to shape HIPAA enforcement today.
Why Risk Analysis Is Only the Beginning
One of the strongest themes throughout the discussion is the distinction between risk analysis and risk management.
Conducting a risk analysis satisfies only part of an organization’s responsibility.
Healthcare organizations must also demonstrate that findings lead to action.
That includes:
- Prioritizing identified risks
- Implementing security controls
- Monitoring remediation efforts
- Updating risk analyses as environments change
- Maintaining executive visibility into organizational risk
The speakers emphasize that regulators increasingly evaluate whether organizations have established repeatable risk management processes rather than treating risk analysis as a one-time compliance exercise.
How Should Organizations Prepare for Future HIPAA Enforcement?
The panel explains that although proposed HIPAA Security Rule updates continue to evolve, organizations should avoid waiting for final regulations before improving cybersecurity programs.
Many of the practices regulators expect today are already considered industry best practices.
Organizations should continue strengthening:
- Enterprise risk analysis
- Risk management programs
- Asset inventories
- Vendor risk management
- Security governance
- Incident response planning
- Executive oversight
Waiting for additional regulatory certainty may delay improvements organizations already know they need.
Practical Recommendations
Throughout the discussion, the speakers recommend that healthcare organizations:
- Perform enterprise-wide risk analyses on a regular basis.
- Treat risk management as an ongoing operational process.
- Inventory AI tools and understand what systems they can access.
- Strengthen governance for AI-enabled technologies.
- Continue improving cybersecurity regardless of pending regulatory updates.
- Demonstrate measurable progress in addressing identified risks.
- Ensure executive leadership maintains visibility into enterprise cyber risk.
Key Takeaways
- OCR continues to expect meaningful risk analysis and active risk management.
- Compliance documentation alone is not enough.
- AI governance has become a cybersecurity priority.
- Ransomware continues targeting healthcare organizations, particularly smaller providers.
- Organizations should prepare now rather than waiting for future regulatory changes.
- Strong governance and continuous risk management remain the foundation of cybersecurity resilience.
Questions This Discussion Answers
- What does OCR expect during HIPAA investigations?
- What is the difference between risk analysis and risk management?
- Why is AI becoming a cybersecurity governance issue?
- What were the most significant healthcare cyber threats in July 2026?
- How should healthcare organizations prepare for future HIPAA enforcement?
- What practical steps can organizations take to strengthen cybersecurity today?
About This Healthcare Cyber Briefing
Clearwater’s Healthcare Cyber Briefing is a monthly webinar series that examines the latest developments in healthcare cybersecurity, privacy, compliance, and enterprise risk management. In this session, Dave Bailey is joined by Robert Kantrowitz of Kirkland & Ellis and Iliana Peters of Polsinelli, former Acting Deputy Director of the HHS Office for Civil Rights, to discuss today’s healthcare threat landscape, evolving HIPAA enforcement expectations, and practical approaches for strengthening risk analysis and risk management programs. Together, they provide healthcare executives, compliance leaders, privacy officers, and cybersecurity professionals with actionable guidance for building resilience beyond regulatory compliance.
