Speaking Engagements
Georgetown Law 2025 Advanced eDiscovery Institute
November 21, 2025 | 8:30 AM – 9:30 AM ET
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.
Articles + Publications January 6, 2025
On January 6, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published significant proposed amendments (proposed rule) to the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Key drivers for the proposed rule include the dramatic increase in cyberattacks, including ransomware, the rapid adoption of cloud computing, mobile devices, and other technologies, and inconsistent compliance with the existing Security Rule identified by the OCR’s investigations.
The proposed rule introduces changes that will modernize the Security Rule, including certain technical aspects (e.g., patching, encryption, multifactor authentication, penetration testing), as well as training and awareness regarding social engineering to help address and mitigate against common breach issues. However, the inventory, mapping, assessment, analysis, testing, audit, and verification requirements may be burdensome and challenging to achieve and maintain for entities that do not have the ability to draw on readily available resources. We also note that the OCR’s cost estimates for these initiatives (Tables 6 and 7) could be significantly understated.
For example, the proposed rule would require regulated entities to:
Maintain an accurate and thorough inventory of their technology assets and create a network map of their electronic information systems, which must be updated at least every 12 months.
Conduct and document an annual audit of compliance with each standard and implementation specification of the Security Rule (in addition to the annual risk analysis).
Conduct vulnerability scanning at least every six months and penetration testing at least every 12 months.
Verify business associate/subcontractor technical safeguards at least every 12 months as part of the business associate agreement contracting process, including a written analysis of the business associate’s information systems and certification by an authorized person at the business associate.
Establish and implement a written contingency plan that includes procedures for data backups, disaster recovery, and emergency mode operations. Notably, disaster recovery plans must now set forth a procedure for restoring critical systems within 72 hours of a loss.
For organizations that have self-funded health benefit plans, note that the proposed rule will require Security Rule compliance by any plan sponsor that receives ePHI from a group health plan beyond summary health information for premium bids or to modify, amend, or terminate the group health plan, enrollment/disenrollment information, or ePHI pursuant to an authorization.
The proposed rule includes a transition period to allow regulated entities time to comply with the new requirements. Entities will be expected to comply with the new requirements within 180 days of the effective date of the final rule. Entities will also have additional time to update their business associate agreements, which will be by the earlier of the contract renewal date or within one year of the final rule’s effective date. Public comments on the proposed rule are due within 60 days of its publication in the Federal Register on January 6.
At this point, we suggest that stakeholders analyze how the potential changes may generally impact their organization and existing HIPAA programs, develop a plan for allocating resources to achieve and manage the potential ongoing compliance obligations, and closely monitor the progress of, and any changes to, the proposed rule.
The Troutman Pepper Locke team is ready to assist with your HIPAA, privacy, cybersecurity, and compliance needs. We will keep you up to date on any updates surrounding the proposed rule. Please contact Brent Hoard at brent.hoard@troutman.com or Emma Trivax at emma.trivax@troutman.com for more information or if you are interested in submitting a public comment to the proposed rule.
Speaking Engagements
Georgetown Law 2025 Advanced eDiscovery Institute
November 21, 2025 | 8:30 AM – 9:30 AM ET
Firm Events
2025 Mid-Atlantic Health Care IT Forum
November 19, 2025 | 3:30 PM – 7:00 PM ET
Troutman Pepper Locke Philadelphia Office – Philadelphia Conference Center
31st Floor, 3000 Two Logan Square, Philadelphia, PA 19103, Eighteenth and Arch Streets
Sponsored Events
2025 ACG Deal Crawl
November 19 – 20, 2025
JW Marriott Charlotte
600 S College Street, Charlotte, NC 28202
Speaking Engagements
Restructuring in the Age of Artificial Intelligence
November 17, 2025 | 1:30 PM – 2:30 PM ET
Offices of CohnReznick
New York, NY
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.