Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

What the Proposed 2022 HHS Budget Says About the Future of HIPAA & Cybersecurity

July 15, 2021

HIPAA compliance has seemed to be on the government’s radar more than ever before. In just the past year, we’ve seen record-breaking Office for Civil Rights (OCR) enforcement, proposed Privacy Rule updates and the implementation of the HIPAA Safe Harbor Law and the 21st Century Cures Act – two new sets of legislation centered around healthcare, technology, and patient rights. So with the spotlight set on protecting the privacy and security of health data during a time where reliance on technology is especially prevalent – it should come as no surprise that the government’s newly proposed budget features a heavy focus and increase in funding for this area specifically. 

What’s in the proposed budget? 

The Biden Administration recently released their proposed 2022 budget for the Department of Health and Human Services (HHS) in early June. The proposal calls for additional spending to better protect the healthcare industry from evolving cyber threats and support government efforts in enforcing compliance among covered entities. So exactly how much of a budget increase are they requesting and what does that tell us about the future of HIPAA compliance?

  • Well for starters, the requested budget seeks $111 million for cybersecurity (an increase of $53 million from what is currently enacted in 2021). According to the official HHS Budget in Brief document, this dollar figure was proposed to “support the advancement of existing, and adoption of new, security technologies to protect the department’s information from the evolving number and complexity of cyberthreats.”
  • The budget also includes $73 million to “build greater resilience into information technology systems across HHS by providing resources for security operations center enhancements and increased logging functions.”
  • Remember the 21st Century Cures Act that we mentioned earlier? The proposal is also seeking $5 million to fund investigative and enforcement efforts related to information blocking provisions within the Cures Act.
  • Additionally, the budget also includes $15 million to “hire specialized personnel from a competitive cybersecurity job market, increase OIG’s cybersecurity efforts, support needed expansions in digital technology, modernize OIG’s IT infrastructure, and further promote an AI-ready workforce.”
  • On top of the increase in spending for cybersecurity, the Biden Administration is also proposing more overall funding for the HHS and their HIPAA enforcement efforts. The increase comes with a price tag of $48 million – which is $9 million more than fiscal 2021’s $39 million discretionary budget.
  • The proposed budget also allocates $19 million in civil monetary settlement funds to support HIPAA enforcement activity bringing the proposed budget to a total of $67 million for the OCR. 
  • In addition to the funding for the OCR and cybersecurity – the budget also includes an $87 million increase in funding for the Office of the National Coordinator for Health IT (ONC), which focuses on ensuring that the most advanced health information technology is implemented and used to best protect the electronic exchange of PHI. 
  • And finally, the proposal asks for an increase of $13 million for the ONC to “build the future healthcare data infrastructure needed to better respond to and prepare for public health emergencies, including the COVID-19 pandemic.”

While those dollar figures are already a good indicator of where we can expect the government to continue its focus – ensuring that patients’ health data is properly protected goes beyond those hefty price tags. Fiscal 2022 proposed budget also seeks to add 39 staff members to the OCR, bringing the employment total to 229, and acknowledges that the “OCR will engage in rulemaking to further strengthen individuals’ rights to access their own health information, improve information sharing for care coordination and case management and reduce administrative burdens.”

So just as recent enforcement numbers have proven the governments’ awareness of noncompliance and influx of cyberthreats has shed light on a lack of proper security protections amongst healthcare providers – this proposed budget provides a ‘crystal-ball’ prediction of what we can expect to see moving forward. Adding in millions of dollars to the budget and expanding the task force in these relevant government agencies will produce even more resources available to ensure all covered entities are best protecting health data privacy and security. And although the new budget is not finalized as of yet, the upcoming changes to the Privacy Rule and commitment outlined within the proposal to improve upon government rulemaking is a clear sign that their emphasis on HIPAA and other health IT-related laws is not going away anytime soon. 

What does this mean for you? 

First off, meeting HIPAA and cybersecurity requirements is essential to protecting your practice and your patients from a data breach or HIPAA violation. While these are certainly things that should be prioritized regardless of the government’s spending plans, the proposal creates even more urgency in ensuring that you have these necessary safeguards in place. So as the government continues to hone in their focus on health data privacy and security, your practice should too – and having a complete compliance AND security program is the perfect place to start.

RECENT POSTS

  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • OSHA 2026 GHS Deadlines
    2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
PrevPreviousPrivacy Rule Proposed Modifications | Public Comments Released
NextHow Are You Controlling Access to Your ePHI?Next

Related posts

Spencer Gifts HIPAA Fine
Abyde News, Fines, HIPAA

Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

June 19, 2026 Penelope Schweitzer No comments yet

June 19, 2026   Quick Guide:  The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program.    The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach.  264%: The increase in ransomware-related breaches reported to the OCR since 2018.   When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline.  Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP).  This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure.    What Happened?   In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk.  The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively.    The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data.  For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed.  Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement.   The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program.  Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.

OCR Ransomware Settlements
Abyde News, Fines, HIPAA

OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them

May 4, 2026 Penelope Schweitzer No comments yet

May 4, 2026   Quick Guide:  The Office for Civil Rights (OCR) just issued a massive wake-up call, announcing four simultaneous settlements totaling $1,165,000. The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. 427,000+: Total number of patients impacted across these four recent settlements. 264%: The increase in ransomware-related breaches reported to the OCR since 2018. The Office for Civil Rights (OCR) just announced a flurry of investigation settlements. At the root of the four that were announced: ransomware. Ransomware attacks continue to target healthcare facilities. As of last year, the OCR discovered that 76% of large breaches are due to hacking and IT shortcomings. Unfortunately, healthcare information is a goldmine for hackers, exposing sensitive data that can lead to identity theft, financial fraud, and compromised patient care. Breakdown & Lessons Learned Regional Women’s Health Group (Axia) The first settlement was regarding the Regional Women’s Health Group (Axia), an OBGYN network across five states. In this case, the organization submitted a breach report following a cyberattack that exposed over 37,000 patients. The settlement resulted in a $320,000 fine and a 2-year Corrective Action Plan (CAP). The Lesson: The OCR didn’t just fine them for being hacked; they reached a settlement because the healthcare organization failed to conduct a “thorough and accurate” Security Risk Analysis (SRA). If you don’t know where your vulnerabilities are, you can’t patch them. Unfortunately, hackers counted on this negligence and exploited it.  Assured Imaging This was the largest of the four fines, affecting a staggering 244,813 individuals. When a ransomware infection hit their servers, Assured Imaging, a medical imaging enterprise, reported a breach to the OCR. After a long investigation (the initial cyberattack occurred in 2020), and resulted in a $375,000 settlement and a 2-year CAP.  The Lesson: Beyond the initial ransomware attack, it was discovered that Assured had never completed an SRA. Additionally, the organization did not notify patients within 60 days of discovery of the breach. This is a direct violation of the Breach Notification Rule, which aims to allow patients to take control and mitigate risks as quickly as possible.  Consociate Health Consciate Health is the only Business Associate (BA) fine in the four. BAs continue to be under the OCR’s microscope, such as potentially needing to follow stricter requirements when handling patient data. Their breach started with a phishing attack that eventually led to the encryption of systems holding data for over 136,000 people. The BA discovered the ransomware six months after the initial phishing attack. Upon the OCR’s further investigation, the SRA was found to be insufficient. The organization paid a $225,000 settlement and entered into a 2-year CAP.  The Lesson: Human error (phishing) is the most common entry point for ransomware. Constant employee training is just as important as a strong firewall. Additionally, just because a BA doesn’t directly work with patients doesn’t mean it isn’t their responsibility to keep patient data secure.  SG Health Plan Even employee benefit plans are regulated under the Health Insurance Portability and Accountability Act (HIPAA). SG Health Plan, associated with a Connecticut energy provider, reported that the data of 9,316 members were exposed following a ransomware attack. It was discovered that the organization did not complete an extensive SRA. The benefit plan entered a settlement with the OCR for $245,000 and a 2-year CAP.  The Lesson: This settlement highlights that HIPAA applies to corporate health plans just as much as it does to traditional healthcare providers. Additionally, every organization that handles Protected Health Information (PHI) must complete an SRA.  The Bottom Line The OCR isn’t fining practices for ransomware attacks, but for being ill-prepared.  However, it is easier said than done to ensure your organization is secure in protecting patient data and complying with HIPAA.  Proactively implementing the HIPAA Security Rule is your opportunity to mitigate the impacts of a cyberattack. Waiting until the ransom note appears on your screen is a million-dollar mistake. Want to see what you might be missing?  Run a 5-Minute HIPAA Gap Assessment and protect your practice today! 

MMG Fusion HIPAA Settlement
Abyde News, Fines, HIPAA

15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

March 6, 2026 Penelope Schweitzer No comments yet

March 6, 2026 They say a mistake ignored is a disaster in the making. For one dental software provider, a 2020 breach became a 15-million-patient nightmare in 2026. MMG Fusion LLC, a dental marketing software business in Maryland, is in the crosshairs of the OCR and the subject of the latest HIPAA enforcement action. MMG agreed to a $10,000 settlement and a 3-year Corrective Action Plan (CAP).  The latest HIPAA settlement, and the 12th Enforcement Action in the Office for Civil Rights (OCR) Risk Analysis Initiative, highlighted the importance of completing a thorough Security Risk Analysis (SRA), proper Breach Notification, and choosing the right Business Associate (BA).  What Happened?  In December 2020, a malicious actor infiltrated MMG’s systems. Over 15 million patients’ Protected Health Information (PHI) was exposed in the cybercrime and leaked to the dark web.  Under the HIPAA Breach Notification Rule, a BA must notify affected Covered Entities (the dental practices) within 60 days of discovering a breach. However, the OCR didn’t learn about this 2020 incident until a complaint was filed in March 2023, more than two years later. The investigation uncovered a critical flaw: MMG Fusion lacked a compliant Security Risk Analysis (SRA). The SRA is a comprehensive review of an organization’s physical, technical, and administrative safeguards to protect PHI. A thorough SRA likely would have identified the very system vulnerabilities that the hackers exploited in 2020. Although the OCR factored in MMG’s “small business” status when determining the $10,000 fine, this amount does not account for the years the investigation took, the accumulated costs of legal counsel, stress, and reputational damage that occurred before the fine was made public. Additionally, MMG will also need to report to the OCR for 3 years in accordance with the CAP settlement.  Streamline Your Compliance This case highlights three non-negotiable pillars for every HIPAA-regulated entity: compliant HIPAA risk assessments, timely breach notification to the OCR and impacted parties, and choosing the right business partner to handle your sensitive information.  Managing vendors and staying on top of SRAs is overwhelming for a busy healthcare organization.  Modern software solutions automate the SRA process and generate compliant Business Associate Agreements (BAAs) for Covered Entities and BAs to use, ensuring both parties are held accountable.  Ready to learn more? Meet with an expert today!

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS