HHS Announces Restructuring of Office for Civil Rights
The U.S. Department of Health and Human Services (HHS) has announced it is restructuring its Office for Civil Rights (OCR), which will split into three divisions, each with specific responsibilities. HHS has recreated the Conscience and Religious Freedom Division (CRFD), which was established in January 2018 under the first Trump administration and operated until March 2023, when it was disbanded by the Biden administration. The Civil Rights Division has also been reestablished, following the amalgamation of both into the Policy Division under the Biden administration.
CRFD is tasked with raising awareness of religious freedom laws and ensuring religious liberty, combating antisemitism and anti-Christian bias, and enforcing conscience protections. OCR enforces civil rights laws, including those that prohibit discrimination on the basis of race, color, national origin, sex, disability, age, or membership in patriotic youth organizations. These responsibilities will be handled by the Civil Rights Division, which will focus on addressing race-based discrimination in a color-blind manner and restoring biological truth.
The Trump administration has focused on these areas during the second term, after being deprioritized under the Biden administration. “This reorganization… strengthens the Office for Civil Rights’ ability to defend religious liberty, enforce conscience protections, and combat unlawful discrimination,” said HHS Secretary Robert F. Kennedy, Jr. “Under President Trump’s leadership, HHS will defend these rights with clarity, accountability, and resolve.”
The Health Information Privacy, Data, and Cybersecurity Division makes up the trifecta and is tasked with handling HIPAA enforcement, including investigations of breaches of unsecured protected health information and health information privacy complaints, both of which have soared in recent years. This enforcement division will continue to support centralized intake and field office execution.
Early in the latest term, there was a major reduction in HHS staffing as the Department of Government Efficiency (DOGE) targeted the department. HHS lost around 20,000 staff members through a combination of eliminated positions, early retirements, and voluntary redundancies. Several field offices were also closed. OCR has been struggling to operate with a limited budget, an increasing workload, and a smaller workforce than in previous years. OCR currently has 116 full-time staff, and while the fiscal year budget would see the department’s workforce increased to 144 full-time staff members, that is significantly fewer than in the early 2020s. It is slightly reassuring that the HHS has confirmed that the restructuring will not involve any further reductions in OCR’s workforce.
Where OCR’s resources will be focused remains to be seen. Large healthcare data breaches increased in 2025, and the complaint volume continues to grow, which is stretching OCR’s resources for health information privacy investigations further still. Healthcare data breaches continue to occur in high numbers; however, the speed at which data breach reports are verified and added to its data breach portal has slowed considerably. OCR had to contend with a lengthy government shutdown last year, with all but essential work coming to a grinding halt. Even accounting for this disruption, the pace has slowed, suggesting health information privacy investigations are a lower priority than under the current administration.
OCR is still working on an update to the HIPAA Privacy Rule, a Notice of Proposed Rulemaking (NPRM) for which was issued by OCR during President Trump’s first term, and an update to the HIPAA Security Rule, the NPRM for which was published in the Federal Register in January 2025 by OCR under the Biden administration. OCR set a provisional timetable for a May 2026 release of a final rule for the HIPAA Security Rule update. OCR has remained tight-lipped about when these regulatory changes will be finalized. They may be delayed if resources are diverted to the CRFD and Civil Rights Divisions.
“This reorganization reinstitutes a structure that rightly prioritizes civil rights and conscience and religious freedom alongside health information privacy and security,” said HHS Office for Civil Rights Director Paula M. Stannard. “All three areas are deserving of subject-matter expertise and distinct senior executive leadership for OCR to best serve the American people.” In the announcement about the restructuring, OCR said it will publish further information in the Federal Register later this month.
The post HHS Announces Restructuring of Office for Civil Rights appeared first on The HIPAA Journal.
Health Insurance Portability and Accountability Act (HIPAA) – openPR.com
Data Breaches Announced by Lumexa Imaging; FMRS Health Systems – The HIPAA Journal
Data Breaches Announced by Lumexa Imaging; FMRS Health Systems
The diagnostic imaging service provider Lumexa Imaging has been affected by a security incident at one of its vendors. FMRS Health Systems, a West Virginia-based provider of mental health services, is investigating a January 2026 data breach.
Lumexa Imaging
Lumexa Imaging, a diagnostic imaging provider that, together with its affiliates, has the second-largest diagnostic imaging footprint in the United States, has notified regulators about a data security incident involving one of its vendors. The unnamed vendor provided non-clinical support services in connection with the administrative services Lumexa Imaging provided to its affiliated radiology practices. On April 9, 2026, the vendor notified Lumexa Imaging that it was investigating suspicious activity within part of its computer network. Lumexa Imaging immediately terminated the vendor’s access to its systems while the incident was investigated and remediated.
The investigation confirmed a breach of the vendor’s systems between March 31, 2026, and April 9, 2026. On April 15, 2026, Lumexa Imaging learned that an unauthorized actor may have used the connection between itself and the vendor to view or obtain documents associated with its affiliated radiology practices. The documents were reviewed and found to contain patient information such as names, birth dates, addresses, phone numbers, patient account numbers, insurance information, and clinical information such as diagnoses, visit dates, and other information related to the radiology services received. A small subset of patients had their Social Security numbers exposed.
The vendor has provided assurances that steps have been taken to secure its systems to prevent similar incidents in the future, including scrubbing and validating the affected systems and implementing additional cybersecurity monitoring and detection tools. Lumexa Imaging is unaware of any misuse of the exposed data and is offering complementary credit monitoring services to individuals whose Social Security numbers were exposed. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.
FMRS Health Systems
FMRS Health Systems, Inc., a West Virginia-based nonprofit mental health center, has recently reported a data breach to the HHS’ Office for Civil Rights that has affected at least 500 individuals. That figure will likely increase, as at the time of issuing its substitute breach notice, the investigation was still ongoing. According to the substitute breach notice on the FMRS Health Systems website, suspicious activity was identified within its computer systems on February 27, 2026. Steps were immediately taken to secure its systems, and a forensic investigation was launched to determine the nature and scope of the unauthorized activity.
The investigation confirmed unauthorized access between January 20, 2026, and February 27, 2026, during which time files containing patient information were copied by the threat actor. Electronic medical records were not subject to unauthorized access. The file review confirmed that names were stolen in combination with one or more of the following: address, birth date, Social Security number, driver’s license number, financial account information, medical history information, diagnostic and treatment information, prescription information, physician’s name, medical record number, and health insurance information. FMRS Health Systems did not state whether ransomware was used; however, a ransomware group – Qilin – claimed responsibility for the attack.
The post Data Breaches Announced by Lumexa Imaging; FMRS Health Systems appeared first on The HIPAA Journal.