Register for the OCR, NIST, and ITL
Safeguarding Health Information:
Building Assurance through HIPAA Security Conference
  • A Hybrid Event Offered both Online & Onsite
  • In-Person Registration now Closed
  • Virtual Registration is $60.00
  • September 2-3, 2026
  • Click here for more information
FEATURING

Julie Chua
Chief, Applied Cybersecurity Division, Information Technology Laboratory, National Institute of Standards and Technology; Former Director, Governance, Risk Management, and Compliance Division, US HHS, Washington, DC

Nicholas Heesters, MEng, JD, CIPP
Senior Advisor for Cybersecurity, Office for Civil Rights, US Department of Health and Human Services; Former VP, Technology Infrastructure, JP Morgan Chase, Philadelphia, PA

Paula M. Stannard, JD
Director, Office for Civil Rights, US Department of Health & Human Services; Former Senior Counselor to the Secretary and Deputy General Counsel, HHS, Washington, DC

Kevin Stine
Director, Information Technology Laboratory, National Institute of Standards and Technology; Former Chief Information Security Officer, US Food and Drug Administration, Washington DC

Brian M. Mazanec, PhD
Deputy Assistant Secretary and Director, Center for Preparedness, Administration for Strategic Preparedness and Response, US Department of Health and Human Services, Washington, DC

Tim Noonan, JD
Deputy Director, Health Information Privacy, Data, and Cybersecurity Division, Office for Civil Rights, US Department of Health & Human Services, Washington, DC

GAITHERSBURG, MD USA -- HEALTHCARE UPDATE NEWS SERVICE™ -- AUGUST 31, 2026: he Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) are pleased to announce the Safeguarding Health Information: Building Assurance through HIPAA Security 2026 conference. The event will be held on September 2-3, 2026 at the NIST campus in Gaithersburg, MD.

The conference will explore the current healthcare cybersecurity landscape and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. This event will highlight the present state of healthcare cybersecurity, and practical strategies, tips and techniques for implementing the HIPAA Security Rule. The Security Rule sets federal standards to protect the confidentiality, integrity and availability of electronic protected health information by requiring HIPAA covered entities and their business associates to implement and maintain administrative, physical and technical safeguards.

The conference will offer sessions that explore best practices in managing risks to and the technical assurance of electronic health information. Presentations will cover a variety of topics including managing cybersecurity risk and implementing practical cybersecurity solutions, understanding current cybersecurity threats to the healthcare community, cybersecurity considerations for IoT in healthcare environments, updates from federal healthcare agencies, and more.

Cybersecurity practitioners, compliance professionals, and leaders in the health care industry and their partners will benefit most from the available sessions.

AGENDA

All times listed are in U.S. Eastern Daylight Time (EDT). Please note, sessions or speakers/panelists may change or be withdrawn at any time with no notice.

Wednesday September 2nd

9:00 Welcome / NIST Information Technology Laboratory (ITL) Updates
  • Kevin Stine, Director, ITL (NIST)
9:15 Conference Logistics / NIST Applied Cybersecurity Division (ACD) Updates
  • Julie Chua, Chief, ACD (NIST)
9:25 HHS Office for Civil Rights (OCR) Welcome / Updates
  • Paula M. Stannard, Director, OCR (HHS)
9:55 Health Sector Cybersecurity Threat Briefing
  • Joshua Justice, Cyber Threat Intelligence Manager, Health-Information Sharing and Analysis Center (H-ISAC)
10:30 Break (15 minutes)

10:45 Administration for Strategic Preparedness and Response (ASPR) Cyber Updates
  • Dr. Brian Mazanec, Deputy Assistant Secretary (HHS ASPR)
11:20 HHS Cybersecurity Activities and Resources Panel
  • Moderator: Tim Noonan, Deputy Director, Health Information Privacy, Data, and Cybersecurity Division (HHS OCR)
  • Dr. Brian Mazanec, Deputy Assistant Secretary (HHS ASPR)
  • Andrew Carney, Program Manager Resilient Systems (HHS ARPA-H)
  • Avinash Shanbhag, Deputy National Coordinator for Health IT and Executive Director, Office of Standards, Certification, and Analysis (HHS ONC)
  • Nicholas Heesters, Senior Advisor for Cybersecurity, Health Information Privacy, Security, Data, and Cybersecurity Division (HHS OCR)
12:10 Lunch (60 minutes)

1:10 Post-Quantum Cryptography (PQC) Panel/Roundtable
  • Moderator: John Dombrowski, Senior Cybersecurity Engineer, MITRE
  • Dustin Moody, Mathematician, Cryptographic Technology Group (NIST)
  • Stephen Craig, Senior Technical Architect Information Security Department, New York-Presbyterian Hospital
  • Nathan Lesser, VP and Chief Information Security Officer, Children's National Hospital
2:00 Privacy Enhancing Technologies (PETs) and Genomic Data Threats
  • Dr. Gary Howarth, Privacy Engineering Program Manager (NIST) Christine Task, Director, Privacy Solutions and Synthetic Data, Knexus Research
2:35 Break (15 minutes)

2:50 FTC Health Privacy/Security Updates
  • Robin Rosen Spector, Attorney, Division of Privacy and Identity Protection (FTC)
3:25 HHS OCR Health Information Privacy, Data, and Cybersecurity Division (HIPDC) Updates
  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)
3:50 Closeout / Announcements
  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)
Thursday September 3rd

9:00 Day 1 Recap / Conference Logistics
  • Julie Chua, Chief, ACD (NIST)
9:10 Future of Health IT / Office of the National Coordinator for Health IT (ONC) Updates
  • Steven Posnack, Principal Deputy National Coordinator for Health IT (HHS ONC)
9:40 Protecting Health Information: A Committee on Foreign Investment in the United States (CFIUS) Perspective
  • Tara Vayda, Deputy Director, Office of National Security (HHS)
10:10 Artificial Intelligence (AI) Metrology in Healthcare
  • Ram Sriram, Senior Science Advisor, ITL (NIST)
10:40 Break (15 minutes)

10:55 Medical Device Cybersecurity Roundtable
  • Moderator: Jeff Marron, Security Engineer, Cybersecurity and Privacy Applications Group (NIST)
  • Justin Post, Cybersecurity Specialist, Center for Devices and Radiological Health (FDA)
  • Dr. Samantha Jacques, Vice President, Corporate Clinical Engineering, McLaren Healthcare
  • Connor Walsh, Chief Information Security Officer, Americas, Siemens Healthineers
  • Dr. Kevin Fu, Professor, Northeastern University
11:45 Cybersecurity Workforce in Healthcare Panel
  • Moderator: Daniel Eliot, Project Lead, ACD (NIST)
  • Bezawit Sumner, Chief Information Security Officer and Senior Director of Security and Compliance, Chesapeake Regional Information System (CRISP)
  • Greg Seig, Chief Information Security Officer, University of Michigan Regional Health Network
  • Dr. Charles Sweat, Jr., Healthcare and Public Health Sector Liaison (DHS CISA)
  • Gabriel Oberfield, Member at Bond, Schoeneck, and King
12:30 Lunch (60 minutes)

1:30 NIST AI Risk Management Framework
  • Martin Stanley, AI and Cybersecurity Researcher, AI Standards and Guidelines Group (NIST)
2:05 AI in Healthcare Roundtable
  • Ram Sriram, Senior Science Advisor, ITL (NIST)
  • Dr. Samantha Jacques, Vice President, Corporate Clinical Engineering, McLaren Healthcare
  • Rob Suárez, Vice President and Chief Information Security Officer, CareFirst BlueCross BlueShield
  • Dr. Jesse Isaacman-Beck, Director, Division of Artificial Intelligence Policy and Strategy (HHS ONC)
2:55 Break (15 minutes)

3:10 NIST CSF Profiles / Risk Analysis / Risk Management
  • Nick Heesters, Senior Advisor for Cybersecurity, HIPDC (HHS OCR)
  • Jeff Marron, Security Engineer, Cybersecurity and Privacy Applications Group (NIST)
  • Barbara Cuthill, Co-lead, Cyber AI Profile (NIST)
3:50 Closeout
  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)

FOR E-MAIL ADDRESS CHANGE, ADD OR DELETE REQUESTS:

For changes or additions, please email your request to: listmgr@HealthcareUpdateNewsService.com.

For removal of your e-mail address, please click the "SafeUnsubscribe" link located in the footer of this message below to automatically remove your address from the list.