HIPAA Digest | Catapult Business Innovations – October 11, 2025

OCR and ASTP Release Updated Security Risk Assessment Tool and User Guide – The National Law Review

The National Law Review reports that HHS OCR has released an updated Security Risk Assessment Tool and an accompanying User Guide, providing a clearer framework for evaluating PHI risks and documenting security controls. This update helps healthcare and related businesses strengthen HIPAA compliance, especially when deploying AI and digital marketing tools that handle PHI.

Read full article

Nurse Fired for Disclosing Teenager’s Pregnancy Status to Family Member – The HIPAA Journal

This HIPAA Journal piece underlines the consequences of inappropriately sharing PHI, including staff disclosures to family members. It underscores the need for robust privacy training, access controls, and clear policies—critical for any business handling PHI or using AI-enabled tools in marketing or customer support.

Read full article