Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule
Two federal compliance developments worth a calendar note. First, HRSA published its FY2026 340B Manufacturer Audit Results page (updated May 28, 2026) — the companion to the already-tracked FY2025 cycle (49% adverse findings); results are partially finalized, with corrective-action plans and any sanctions to be posted as HRSA approves them, and the agency advises covered entities not to contact audited manufacturers until CAPs post.
FQHCs are the largest class of 340B covered entities, so this is a standing reference to monitor in OPAIS. Second, OCR's Risk Analysis Initiative has now completed 19 ransomware investigations with six 2026 settlements, and a June 1 Sidley analysis frames the recent settlements as a direct preview of the forthcoming HIPAA Security Rule amendments (which would make annual risk analyses, documented asset inventories, and demonstrated remediation mandatory rather than 'addressable').
No FQHC has been named, but FTCA-covered health centers are full HIPAA covered entities — meaning a center that hasn't completed a documented Security Risk Analysis is accumulating enforcement exposure ahead of a rule change, not just theoretical risk. (Affordable FQHC SRA tooling like Medcurity, added to our tech stack this cycle, exists precisely for this gap.)
Key takeaways
- HRSA's FY2026 340B manufacturer-audit results are live (updated May 28) — monitor OPAIS for CAPs/sanctions; FQHCs are the largest 340B class.
- OCR's 19 ransomware investigations + 6 2026 settlements preview a tougher HIPAA Security Rule (mandatory annual risk analysis) — incomplete SRAs = building exposure.
Linked evidence
Sidley Data Matters / HRSA OPA / Nixon PeabodySource packet
This story's linked evidence + 4 related tracked stories with theirs — one print-ready digest for your team or board packet.
Free — unlocks the packet and submits a single opt-in for Intel Brief. Eligible addresses are subscribed immediately and no confirmation email is sent; a prior unsubscribe, verified deletion, or bounce is not overridden. Individual sources are always clickable above, no email needed.
FQHC Talent. (2026, June 1). Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule. Linked evidence: Sidley Data Matters / HRSA OPA / Nixon Peabody. Retrieved September 11, 2026, from https://www.fqhctalent.com/intel/hrsa-fy26-340b-audit-ocr-risk-analysis-security-rule-preview-2026
More in Risk & Compliance
Aug 27
OCR's 55th HIPAA access action adds a current records-request workflow warning
Aug 21
A vendor that archives the EHR you decommissioned was breached — at least seven health centers are affected, and its own client list is provably incomplete
Aug 21
HHS asks clinicians whether federal vaccine-recommendation categories should change — comments due September 20; nothing changes yet
Aug 13
A final rule takes effect October 13 barring federal Medicaid and CHIP payment for a service line more than a dozen tracked health centers advertise — and the age cutoff is different in Medicaid than in CHIP