Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Safeguarding Health Information: Building Assurance through HIPAA Security 2026

NIST HHS/OCR HIPAA Security Conference
Credit: Kristina Rigopoulos/NIST

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) are pleased to announce the Safeguarding Health Information: Building Assurance through HIPAA Security 2026 conference. The event will be held on September 2-3, 2026 at the NIST campus in Gaithersburg, MD.

The conference will explore the current healthcare cybersecurity landscape and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. This event will highlight the present state of healthcare cybersecurity, and practical strategies, tips and techniques for implementing the HIPAA Security Rule. The Security Rule sets federal standards to protect the confidentiality, integrity and availability of electronic protected health information by requiring HIPAA covered entities and their business associates to implement and maintain administrative, physical and technical safeguards.

The conference will offer sessions that explore best practices in managing risks to and the technical assurance of electronic health information. Presentations will cover a variety of topics including managing cybersecurity risk and implementing practical cybersecurity solutions, understanding current cybersecurity threats to the healthcare community, cybersecurity considerations for IoT in healthcare environments, updates from federal healthcare agencies, and more.

Cybersecurity practitioners, compliance professionals, and leaders in the health care industry and their partners will benefit most from the available sessions.

CEU/CLE Credits

NIST does not provide certificates of attendance or any specific information regarding CEUs/CLEs. Attendees are always welcome to self-report to their authoritative certification bodies to request CEUs/CLEs.
 

September 2, 2026:  9:00am ET - 4:00pm ET

September 3, 2026: 9:00am ET - 4:00pm ET

Conference sessions and topics are tentative and may change prior to conference dates.

Wednesday (9/2)

9:00 Welcome / NIST Information Technology Laboratory (ITL) Updates

  • Kevin Stine, Director, ITL (NIST)

9:15 Conference Logistics / NIST Applied Cybersecurity Division (ACD) Updates

  • Julie Chua, Chief, ACD (NIST)

9:25 HHS Office for Civil Rights (OCR) Welcome / Updates

  • Paula M. Stannard, Director, OCR (HHS)

9:55 Health Sector Cybersecurity Threat Briefing

  • Joshua Justice, Cyber Threat Intelligence Manager, Health-Information Sharing and Analysis Center (H-ISAC)

10:30 Break (15 minutes)

10:45 Administration for Strategic Preparedness and Response (ASPR) Cyber Updates

  • Dr. Brian Mazanec, Deputy Assistant Secretary (HHS ASPR)

11:20 HHS Cybersecurity Activities and Resources Panel

  • Moderator: Tim Noonan, Deputy Director, Health Information Privacy, Data, and Cybersecurity Division (HHS OCR)
  • Dr. Brian Mazanec, Deputy Assistant Secretary (HHS ASPR)
  • Andrew Carney, Program Manager Resilient Systems (HHS ARPA-H)
  • Avinash Shanbhag, Deputy National Coordinator for Health IT and Executive Director, Office of Standards, Certification, and Analysis (HHS ONC)
  • Nicholas Heesters, Senior Advisor for Cybersecurity, Health Information Privacy, Security, Data, and Cybersecurity Division (HHS OCR)

12:10 Lunch (60 minutes)

1:10 Post-Quantum Cryptography (PQC) Panel/Roundtable

  • Moderator: John Dombrowski, Senior Cybersecurity Engineer, MITRE
  • Dustin Moody, Mathematician, Cryptographic Technology Group (NIST)
  • Stephen Craig, Senior Technical Architect Information Security Department, New York-Presbyterian Hospital
  • Nathan Lesser, VP and Chief Information Security Officer, Children’s National Hospital

2:00 Privacy Enhancing Technologies (PETs) and Genomic Data Threats

  • Dr. Gary Howarth, Privacy Engineering Program Manager (NIST)
  • Christine Task, Director, Privacy Solutions and Synthetic Data, Knexus Research

2:35 Break (15 minutes)

2:50 FTC Health Privacy/Security Updates

  • Robin Rosen Spector, Attorney, Division of Privacy and Identity Protection (FTC)

3:25 HHS OCR Health Information Privacy, Data, and Cybersecurity Division (HIPDC) Updates

  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)

3:50 Closeout / Announcements

  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)

Thursday 9/3

9:00 Day 1 Recap / Conference Logistics

  • Julie Chua, Chief, ACD (NIST)

9:10 Future of Health IT / Office of the National Coordinator for Health IT (ONC) Updates

  • Steven Posnack, Principal Deputy National Coordinator for Health IT (HHS ONC)

9:40 Protecting Health Information: A Committee on Foreign Investment in the United States (CFIUS) Perspective

  • Tara Vayda, Deputy Director, Office of National Security (HHS)

10:10 Artificial Intelligence (AI) Metrology in Healthcare

  • Ram Sriram, Senior Science Advisor, ITL (NIST)

10:40 Break (15 minutes)

10:55 Medical Device Cybersecurity Roundtable

  • Moderator: Jeff Marron, Security Engineer, Cybersecurity and Privacy Applications Group (NIST)
  • Justin Post, Cybersecurity Specialist, Center for Devices and Radiological Health (FDA)
  • Dr. Samantha Jacques, Vice President, Corporate Clinical Engineering, McLaren Healthcare
  • Connor Walsh, Chief Information Security Officer, Americas, Siemens Healthineers
  • Dr. Kevin Fu, Professor, Northeastern University

11:45 Cybersecurity Workforce in Healthcare Panel

  • Moderator: Daniel Eliot, Project Lead, ACD (NIST)
  • Bezawit Sumner, Chief Information Security Officer and Senior Director of Security and Compliance, Chesapeake Regional Information System (CRISP)
  • Greg Sieg, Chief Information Security Officer, University of Michigan Regional Health Network
  • Dr. Charles Sweat, Jr., Healthcare and Public Health Sector Liaison (DHS CISA)
  • Gabriel Oberfield, Member at Bond, Schoeneck, and King.

12:30 Lunch (60 minutes)

1:30 NIST AI Risk Management Framework

  • Martin Stanley, AI and Cybersecurity Researcher, AI Standards and Guidelines Group (NIST)

2:05 AI in Healthcare Roundtable

  • Ram Sriram, Senior Science Advisor, ITL (NIST)
  • Dr. Samantha Jacques, Vice President, Corporate Clinical Engineering, McLaren Healthcare
  • Rob Suárez, Vice President and Chief Information Security Officer, CareFirst BlueCross BlueShield
  • Dr. Jesse Isaacman-Beck, Director, Division of Artificial Intelligence Policy and Strategy (HHS ONC)

2:55 Break (15 minutes)

3:10 NIST CSF Profiles / Risk Analysis / Risk Management

  • Nick Heesters, Senior Advisor for Cybersecurity, HIPDC (HHS OCR)
  • Jeff Marron, Security Engineer, Cybersecurity and Privacy Applications Group (NIST)
  • Barbara Cuthill, Co-lead, Cyber AI Profile (NIST)

3:50 Closeout

  • Tim Noonan, Deputy Director, HIPDC (HHS OCR)

 

Lodging Information

Group Name: NIST Safeguarding Health Information: Building Assurance through HIPAA Security 2026

Dates Available: September 01 -03, 2026

Rate: $219.00 USD per night (includes complimentary hot breakfast and transportation to and from NIST Gaithersburg)

Last Day to Book : Tuesday, August 04, 2026

Book your group rate for NIST Safeguarding Health Information: Building Assurance through HIPAA Security 2026

 

Security Instructions

Visitor Access Requirement:

  • For Non-US Citizens: Please have your valid/non-expired passport for photo identification.*
  • For US Permanent Residents: Please have your valid/non-expired green card for photo identification.*
  • For US Citizens: Please have your valid/non-expired state-issued driver's license. NIST will only accept a REAL ID-compliant form of identification. Visitors with state-issued identification must now present a REAL ID or a different form of government-issued photo identification, such as: a valid/non-expired passport, passport card, DOD's Common Access Card (CAC), Veterans ID, Federal Agency HSPD-12 IDs, and Military Dependents ID.*

*Use of apps, physical photocopies, and/or digital screenshots of your ID, Passport or Green card will not be accepted. 

Failure to show proper valid and compliant/non-expired photo identification upon check-in will result in denied entry into the facility.

For more information please visit our Campus Access and Security page.

Created March 10, 2026, Updated August 31, 2026
Was this page helpful?