Hale Insights - September 14, 2026

Hale Insights - September 14, 2026

Calendar Icon
September 14, 2026

Good morning everyone,

This week brings practical developments for healthcare compliance teams: an updated federal Security Risk Assessment Tool and an FTC action that requires careful interpretation. The FTC withdrew its 2021 health-app policy statement because subsequent rulemaking superseded it; the Health Breach Notification Rule remains in place. (ONC update; FTC announcement)

New breach disclosures, a medical-device supplier’s recovery update, and vulnerabilities in healthcare integration software also put vendor access and operational resilience in focus. Our practical takeaway: assess who can reach sensitive data, verify what those accounts can do, and connect findings to documented remediation. The developments below cover September 8–14.

Regulatory & Legal Updates

HHS updates the Security Risk Assessment Tool to version 3.7 (Reported September 11, 2026)

What happened: HHS released version 3.7 of the ONC/OCR Security Risk Assessment Tool. Changes address assessment scope, remote access and telework, asset inventories, system-activity logging, and triggers for reassessment. The Windows application and Excel workbook are available, with training webinars scheduled for September 15 and 16. (The HIPAA Journal; ONC tool and webinar details)

Why it matters: This is a useful opportunity to check whether your assessment reflects how your organization actually operates. ONC explicitly cautions that the tool alone may not identify every risk and does not guarantee compliance. Completing the questionnaire should support a broader, evidence-based assessment.

Recommended actions:

  • Compare your current assessment scope with every location and service that creates, receives, maintains, or transmits ePHI, including remote work.
  • Use the revised questions to review asset inventories and logging coverage; record gaps, accountable owners, and target dates in your remediation plan.
  • Assign an assessment lead to attend the September 15 webinar, noon–1 p.m. Eastern, or September 16, 3–4 p.m. Eastern.

FTC withdraws its 2021 health-app policy statement; notification rule remains (September 9, 2026)

What happened: The FTC rescinded its 2021 Statement on Breaches by Health Apps and Other Connected Devices. The Commission explained that its 2024 amendments to the Health Breach Notification Rule already addressed health apps and connected devices, making the earlier statement unnecessary. This action withdrew the policy statement—not the underlying rule. (FTC announcement; Commission statement)

Why it matters: Digital health teams should not interpret this announcement as permission to relax breach-response procedures. The relevant question remains whether a product and its activities fall within the current rule’s scope.

Recommended actions:

  • Update legal-reference inventories and training materials that cite the withdrawn statement as the operative authority.
  • Have privacy and legal teams review health-app applicability against the current rule, documenting the reasoning for each product.
  • Retain incident escalation procedures for suspected unauthorized health-data disclosures, including those involving analytics or advertising integrations.

Breach & Incident Notices

AdaptHealth breach scope reaches more than 4.1 million individuals (Reported September 9–10, 2026)

What happened: New reporting identifies 4,115,802 individuals affected by AdaptHealth’s previously disclosed cyberattack. Its August notice says the attack occurred June 5 and was discovered June 15. Information potentially affected included names, contact and demographic details, health information, and insurance information. AdaptHealth said Social Security numbers and financial information were not involved and arranged identity protection services. This week’s development is the reported affected-person count. (The HIPAA Journal; AdaptHealth notice)

Why it matters: Reporting links the intrusion to social engineering involving a third-party contractor’s privileged account. For compliance teams, the practical issue is how much information an external account can reach and whether its activity is monitored closely enough to detect misuse. (BleepingComputer)

Recommended actions:

  • Identify contractor accounts with access to patient-management, document-storage, billing, and external EHR systems; remove unnecessary privileges.
  • Require independently verified callbacks for sensitive account-recovery requests and review phishing-resistant authentication options for privileged users.
  • Reconcile incident population estimates across notification vendors, patient communications, and regulatory submissions; document changes and their supporting evidence.

Vendor & Supply Chain Risk

Veradigm discloses patient-data theft through a vendor’s API credentials (Filed September 8; reported September 10, 2026)

What happened: Veradigm disclosed that an unauthorized party obtained a vendor’s credentials for a Veradigm application programming interface and downloaded patient personal information, including some Social Security numbers. The company said no clinical or medical data was involved, access was limited to the interface, and operations were unaffected. The confirmed affected-person count had not been publicly disclosed in the September 10 reporting. (Veradigm SEC filing; The HIPAA Journal)

Why it matters: A narrowly scoped technical connection can still expose sensitive information. Vendor oversight should examine the fields and record volumes accessible through an integration, alongside the vendor’s broader security assurances.

Recommended actions:

  • Inventory vendor API credentials, their owners, permitted data fields, customer scope, and expiration or rotation arrangements.
  • Configure alerts for abnormal query volume, bulk downloads, and unexpected access locations; test who receives and investigates them.
  • If your organization is potentially affected, request written confirmation of impacted records, containment measures, and notification responsibilities.

Boston Scientific restores core operations and remote-monitoring activations (September 9, 2026)

What happened: In a new recovery update following its August 25 cyberattack, Boston Scientific said manufacturing, order fulfillment, and shipping were fully restored. Cardiac-device remote-monitoring activation capability had also resumed. The company cautioned that some customers could still experience delays while backlogs were cleared and that business-application restoration remained underway. (Boston Scientific recovery update)

Why it matters: Supplier recovery should be verified at the workflow level. A general restoration announcement does not establish that every delayed order, application connection, or patient-monitoring activation has been completed. Clinical and procurement teams need a shared picture of outstanding dependencies.

Recommended actions:

  • Reconcile delayed orders with clinical demand and confirm delivery dates for time-sensitive supplies.
  • Identify patients whose monitoring activation was deferred and verify completion with the responsible clinical team.
  • Document criteria for ending downtime procedures, including application availability, backlog reconciliation, and vendor escalation contacts.

Cybersecurity & Threat Intelligence

CISA flags three vulnerabilities in NextGen Mirth Connect (September 10, 2026)

What happened: CISA published an advisory covering three vulnerabilities in Mirth Connect: CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578. The issues involve SQL injection and XML processing and can expose data or disrupt service. The advisory identifies versions 4.7.1 and earlier as affected and recommends upgrading to 4.7.2 or later. CISA reported no known public exploitation at publication. (CISA advisory)

Why it matters: Integration software warrants explicit attention in vulnerability management. The potential exposure of connected-system credentials makes this more than a single-application patching issue; your review should consider downstream access and clinical data flows.

Recommended actions:

  • Locate internal and vendor-managed Mirth Connect instances, verify versions, and obtain a documented upgrade schedule.
  • Restrict administrative access and unnecessary network exposure while testing the update against critical interfaces.
  • Review suspicious access and outbound connections; if compromise is suspected, preserve evidence and assess whether connected-system credentials require rotation.

Closing Thoughts

This week’s practical priority is to connect assessment, access management, and incident readiness. Use the updated SRA questions to challenge assumptions about remote work, vendors, and monitoring. For each gap, record the risk, the chosen treatment, an accountable owner, and evidence that the treatment works.

As you plan the coming week, select a high-risk vendor connection or clinical interface and test its access controls, logging, and recovery process. Keep workforce training, encryption coverage, notification decision-making, and documentation in that review. A defensible compliance program should be able to explain both what it requires and how those requirements operate in practice.