
Good morning everyone,
This week puts familiar compliance fundamentals back in focus. A new OCR settlement addresses risk analysis and account controls, while reintroduced Senate legislation proposes stronger cybersecurity requirements and hospital funding. Together, these developments give leadership teams good reasons to review how security responsibilities are documented and verified. (OCR settlement reporting; legislative update)
Vendor-related developments also deserve attention: an EHR migration breach has led to a proposed settlement, and new reporting adds detail to the McKesson incident. Below, we cover developments reported September 15–21, alongside an urgent Cisco advisory and an emerging AI-related privacy concern. The practical priority is to connect each relevant finding to an owner, a response deadline, and evidence of completion. (Modernizing Medicine; McKesson)
Regulatory & Legal Updates
Ambry Genetics agrees to $700,000 HIPAA settlement (Announced September 17, 2026)
What happened: OCR reached a $700,000 settlement with Ambry Genetics following a 2020 phishing incident affecting 225,370 individuals. OCR identified deficiencies involving risk analysis, termination of workforce access, and unique user identification. Ambry must implement a corrective action plan subject to two years of monitoring. The new development is the enforcement resolution, not a new breach. (HHS enforcement listing; HIPAA Journal)
Why it matters: A phishing investigation can expose weaknesses beyond the initial compromised account. For compliance leaders, this case is a useful prompt to test whether access-management policies work consistently across systems, including vendor-hosted applications.
Recommended actions:
- Sample recent employee departures and role changes; verify when EHR, email, remote-access, and vendor-platform permissions were removed or adjusted.
- Identify shared workforce credentials and assign individually attributable access; document and remediate exceptions.
- Check that the risk analysis covers email and identity systems, with named owners and completion evidence for outstanding remediation.
Senators reintroduce healthcare cybersecurity legislation (September 17, 2026)
What happened: Senators Mark Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act. The proposal includes mandatory cybersecurity standards, annual risk analyses addressing business-associate exposure, recovery stress tests, and executive compliance statements. It also proposes $1.3 billion for hospital cybersecurity improvements. These provisions are proposed legislation, not newly effective requirements. (HIPAA Journal; proposed bill text)
Why it matters: The proposal connects cybersecurity to leadership accountability and continuity of care. It provides useful planning context, but organizations should distinguish legislative monitoring from obligations already in force.
Recommended actions:
- Add the bill to the regulatory tracker, assigning legal or compliance staff to monitor its progress and amendments.
- Brief leadership on the proposed accountability provisions; identify what evidence would support any future executive certification.
- Exercise a critical vendor outage using measurable recovery objectives, recording clinical dependencies, failed assumptions, and corrective actions.
Vendor & Supply Chain Risk
Modernizing Medicine settlement highlights EHR migration exposure (Reported September 17, 2026)
What happened: Modernizing Medicine agreed to a $2,999,750 settlement that has received preliminary court approval. The litigation concerns July 2025 unauthorized access to two servers used to convert data from retiring EHR platforms. The reported affected population was 198,795 individuals; exposed information included medical and insurance data and some Social Security numbers. The company denies wrongdoing. Final approval remains pending. (HIPAA Journal)
Why it matters: Migration environments deserve the same scrutiny as production systems. Project teams should account for temporary copies of patient information, who can access them, and what happens to those copies after conversion is complete.
Recommended actions:
- Require each EHR migration plan to identify staging servers, data owners, encryption controls, approved access, and logging arrangements.
- Make secure deletion or documented retention of conversion files a formal project-closeout requirement, including vendor confirmation.
- Review contracts for incident escalation, forensic cooperation, notification support, and responsibility for migration subcontractors.
McKesson update identifies 6.4 million unique email addresses (Reported September 18, 2026)
What happened: New reporting on McKesson’s previously disclosed incident cites Have I Been Pwned founder Troy Hunt’s finding of approximately 6.4 million unique email addresses in the allegedly stolen data. The addresses reportedly span patients, staff, marketing contacts, and others. McKesson’s investigation remains ongoing; this is not a confirmed count of affected patients. Earlier company disclosures identified potential exposure of personal, medical, insurance, and financial information. (HIPAA Journal)
Why it matters: Email addresses, database rows, and affected individuals are different measures. Compliance teams should avoid importing an unverified headline number into patient notices or regulatory reports. The new information also supports reviewing targeted phishing exposure.
Recommended actions:
- Ask McKesson to identify affected services, your organization’s records, relevant data elements, and the status of population reconciliation.
- Maintain separate incident-register fields for confirmed individuals, preliminary estimates, and third-party or threat-actor claims.
- Alert help-desk, procurement, and patient-facing teams to possible impersonation attempts; verify unusual requests through established contact channels.
Cybersecurity & Threat Intelligence
Cisco confirms active exploitation of critical identity-system flaw (September 16, 2026)
What happened: Cisco disclosed CVE-2026-76460, a maximum-severity authentication-bypass vulnerability affecting Identity Services Engine and ISE Passive Identity Connector. Cisco confirmed active exploitation and released fixes. There is no workaround that resolves the flaw, although restricting management traffic can mitigate exposure. Cisco also warns that attackers may conceal evidence after obtaining privileged access. (Cisco advisory)
Why it matters: Treat affected identity infrastructure as an urgent security priority. Patching should be paired with investigation for prior compromise; a successful upgrade does not establish that the environment was never accessed.
Recommended actions:
- Inventory internal and managed-service ISE deployments and upgrade every affected node to the appropriate fixed release listed by Cisco.
- Review each node’s access logs and corroborate findings with external firewall and network logs, following Cisco’s indicators and investigation guidance.
- If compromise is suspected, preserve available evidence and coordinate re-imaging and configuration restoration with the incident-response team and Cisco support.
Privacy, AI & Digital Health Updates
Spanish regulator reviews reported AI-agent-assisted breach (Reported September 15, 2026)
What happened: Reuters reported that Spain’s data protection authority received a notification alleging that an AI agent helped access a system, alter personal information, and view billing records. The case remains under review; the organization and affected population were not identified. This is an emerging international incident, not a confirmed healthcare breach or a new U.S. requirement. (Reuters)
Why it matters: For healthcare teams, the practical lesson is to include unauthorized data changes in incident exercises alongside data theft. AI governance reviews should also examine what connected tools can do with their permissions, beyond the accuracy of their generated responses.
Recommended actions:
- Inventory AI-enabled integrations and document their ability to read, export, modify, or delete patient and billing information.
- Require human approval for high-impact automated changes and use narrowly scoped service accounts with attributable activity logs.
- Test how teams would detect altered records, suspend an integration, preserve evidence, and restore trusted information.
Closing Thoughts
Use this week’s developments to test the connection between written policy and operational evidence. Select a recent offboarding event, a vendor migration, and an urgent patch: can your team show who acted, what was verified, and whether residual risk was accepted by the right person?
For the coming week, prioritize unresolved access and vulnerability findings, confirm vendor incident contacts, and rehearse notification decisions with privacy and legal teams. Keep risk analysis, encryption coverage, workforce training, monitoring, and recovery testing connected to a documented remediation plan. Defensible compliance depends on being able to explain—and demonstrate—how safeguards operate in practice.
