HIPAA Is Not the Hard Part Anymore
Overview
In this episode, we speak with healthcare attorney and host of the long-running Healthcare de Jure podcast, Matt Fisher, about the state of healthcare privacy and security as HIPAA marks its 30th anniversary. Matt argues that HIPAA itself is relatively straightforward compared to the more convoluted corners of healthcare regulation like fraud, abuse, and Medicare/Medicaid compliance. Its scope is narrow, its three rules are well-defined, and organizations that follow modern industry-standard security practices are often already operating well beyond what the rules require. The harder, and often overlooked, work sits in what HIPAA doesn’t cover: day-to-day data governance, vendor trust, and the expanding gray areas created by patient access rights, information blocking rules, and third-party apps that fall outside its reach.
Matt also unpacks the risks leaders are quietly underestimating around AI, from shadow AI usage to contractual and de-identification questions with AI vendors, and why a signed Business Associate Agreement (BAA) is a starting point, not a safety net. He explains why most breach-related penalties today come from class-action lawsuits rather than OCR fines and what healthcare executives and compliance leaders should be prioritizing internally in 2026.
You’ll learn:
- How HIPAA compliance differs from true data governance, and where each one fits in a modern healthcare organization.
- The tension between information blocking rules, patient access rights, and protecting data once it leaves the covered entity.
- The privacy and security considerations around AI adoption in healthcare, including shadow AI, vendor contracts, and data ownership.
- What strong BAAs and vendor oversight should look like beyond a check-the-box exercise.
Listen to the Podcast
Stream the audio here. Also available on all major podcast networks.
LISTEN ON