Signing you in...

Please wait while we verify your authentication

Article · Sunday, July 26, 2026

Cybersecurity · Industry brief

Top three stories shaping Cybersecurity today, written for someone who already works in the industry: regulation, M&A, new entrants, notable filings, and any precedent worth pulling. Cite the trade publication (e.g. trade press, government source, court docket) directly so I can follow up.

By Marius BongartsTech22 editions
← See today's latest
Editions
9 / 22
Generated by AI overnight from public sources, refreshed daily.
Cybersecurity · Industry brief
Sunday, July 26, 2026
Cybersecurity · Industry brief

HIPAA enforcement escalates, submarine cables under review

1 min read

HIPAA Security Rule enforcement

HHS is moving from documentation audits to action audits.

The Office for Civil Rights has shifted its enforcement focus: organizations must now demonstrate they're actively mitigating identified risks, not merely logging them in annual reviews [Quelle: Clearwater Security]. Nick Heesters, OCR's senior advisor for cybersecurity, has made clear that vulnerabilities found in consecutive risk assessments but left unpatched constitute willful neglect—penalties run $73,011 per day per violation. In 2025, hacking caused 76 percent of large breaches affecting covered entities, with over 286 million individuals compromised.

The bigger shift: OCR now requires continuous risk management using NIST CSF 2.0 and HHS 405(d) frameworks, not just annual snapshots.

HIPAA Security Rule revision stalled

The promised overhaul just got pushed back a year.

HHS delayed final action on the Security Rule to at least July 2027, though the Privacy Rule moves to August separately [Quelle: Clearwater Security]. The January 2025 proposal would eliminate the distinction between "required" and "addressable" specifications and mandate written documentation for all security policies—industry estimates pegged the first-year cost at $9 billion. Paula Stannard, OCR director, signaled the proposal survives despite rescission calls from CHIME and other provider groups.

Covered entities face a dual challenge: stricter enforcement now, but regulatory clarity still years away.

Submarine cable licensing under scrutiny

National security agencies are rewriting the book on critical cables.

The Federal Register published notice of a formal review into submarine cable landing license rules and procedures, examining how national security fits into modern approval workflows [Quelle: Federal Register]. The timing signals growing concern over foreign investment in transatlantic and transpacific infrastructure—particularly as private and state-backed entities compete for underwater fiber routes.

Expect new vetting criteria and longer approval timelines for international cable projects.

Sources
Review of Submarine Cable Landing License Rules and ...
Review of Submarine Cable Landing License Rules and ...
9 hours ago ... ... security of U.S. communications networks and critical infrastructure against foreign adversary threats. III. Second Further Notice of Proposed Rulemaking. In ...
federalregister.gov
AI Summary

""

Visit source
HIPAA Security Rule Enforcement: Where Things Stand in 2026
HIPAA Security Rule Enforcement: Where Things Stand in 2026
5 hours ago ... That's the situation right now with federal healthcare cybersecurity regulation ... Stay informed on the latest healthcare cybersecurity, privacy, and compliance ...
clearwatersecurity.com
AI Summary

The Department of Health and Human Services has delayed final action on the HIPAA Security Rule overhaul to at least July 2027, moving the Privacy Rule changes separately to August. The proposal, published in January 2025 with a 125-page Notice of Proposed Rulemaking, would eliminate distinctions between "required" and "addressable" implementation specifications and mandate written documentation for all security policies. Paula Stannard, HHS Office for Civil Rights director, signaled the proposal is not headed for rescission despite industry concerns over its estimated $9 billion first-year cost, noting that doing nothing carries its own high costs through cyberattacks and breaches. More than 4,700 public comments have been submitted; the Trump administration has not yet decided its position. CHIME submitted public comments and stakeholder letters requesting rescission, arguing cost estimates understate real burden for under-resourced providers. The Office for Civil Rights has expanded its enforcement initiative beyond risk analysis to include active risk management implementation. OCR Senior Advisor for Cybersecurity Nick Heesters released guidance making clear that organizations must take action on identified risks, not merely document them. In 2024, large HIPAA breaches affected over 286 million individuals; 76 percent of large breaches in 2025 were caused by hacking and IT incidents. OCR has found recurring patterns of vulnerabilities identified in security reviews year after year but left unmitigated until exploited. Willful neglect findings carry penalties of $73,011 per day per violation. OCR is actively enforcing existing rules by requiring organizations demonstrate functioning, continuous risk management programs using federally recognized frameworks including NIST CSF 2.0, NIST SP 800-66, and HHS 405(d) Health Industry Cybersecurity Practices.

Visit source
Compiled overnight by MorningMail.aiDelivered at 02:40 AM