Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule
Two federal compliance developments worth a calendar note. First, HRSA published its FY2026 340B Manufacturer Audit Results page (updated May 28, 2026) — the companion to the already-tracked FY2025 cycle (49% adverse findings); results are partially finalized, with corrective-action plans and any sanctions to be posted as HRSA approves them, and the agency advises covered entities not to contact audited manufacturers until CAPs post. FQHCs are the largest class of 340B covered entities, so this is a standing reference to monitor in OPAIS. Second, OCR's Risk Analysis Initiative has now completed 19 ransomware investigations with six 2026 settlements, and a June 1 Sidley analysis frames the recent settlements as a direct preview of the forthcoming HIPAA Security Rule amendments (which would make annual risk analyses, documented asset inventories, and demonstrated remediation mandatory rather than 'addressable'). No FQHC has been named, but FTCA-covered health centers are full HIPAA covered entities — meaning a center that hasn't completed a documented Security Risk Analysis is accumulating enforcement exposure ahead of a rule change, not just theoretical risk. (Affordable FQHC SRA tooling like Medcurity, added to our tech stack this cycle, exists precisely for this gap.)
Key takeaways
- HRSA's FY2026 340B manufacturer-audit results are live (updated May 28) — monitor OPAIS for CAPs/sanctions; FQHCs are the largest 340B class.
- OCR's 19 ransomware investigations + 6 2026 settlements preview a tougher HIPAA Security Rule (mandatory annual risk analysis) — incomplete SRAs = building exposure.
Primary source
Sidley Data Matters / HRSA OPA / Nixon PeabodyFQHC Talent. (2026, June 1). Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule. Primary source: Sidley Data Matters / HRSA OPA / Nixon Peabody. Retrieved June 8, 2026, from https://www.fqhctalent.com/intel/hrsa-fy26-340b-audit-ocr-risk-analysis-security-rule-preview-2026
More in Risk & Compliance
Jul 5
Section 1557 Language Access Annual Notice Year 1 Anniversary — July 5, 2026 Compliance Window
Jun 1
Eli Lilly Gives ~50 Covered Entities Five Days to Hand Over 340B Claims Data — or Lose Their Discounts
May 26
California AB 3030 + SB 1120 Are Active FQHC AI Compliance Triggers — Disclosure + Consent + UM Restrictions in Effect
May 21
HHS Launches AERO — AI Re-Scores 5 Years of Audit Data for Every $1M+ Grantee, Including FQHCs