Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule
Two federal compliance developments worth a calendar note. First, HRSA published its FY2026 340B Manufacturer Audit Results page (updated May 28, 2026) — the companion to the already-tracked FY2025 cycle (49% adverse findings); results are partially finalized, with corrective-action plans and any sanctions to be posted as HRSA approves them, and the agency advises covered entities not to contact audited manufacturers until CAPs post.
FQHCs are the largest class of 340B covered entities, so this is a standing reference to monitor in OPAIS. Second, OCR's Risk Analysis Initiative has now completed 19 ransomware investigations with six 2026 settlements, and a June 1 Sidley analysis frames the recent settlements as a direct preview of the forthcoming HIPAA Security Rule amendments (which would make annual risk analyses, documented asset inventories, and demonstrated remediation mandatory rather than 'addressable').
No FQHC has been named, but FTCA-covered health centers are full HIPAA covered entities — meaning a center that hasn't completed a documented Security Risk Analysis is accumulating enforcement exposure ahead of a rule change, not just theoretical risk. (Affordable FQHC SRA tooling like Medcurity, added to our tech stack this cycle, exists precisely for this gap.)
Key takeaways
- HRSA's FY2026 340B manufacturer-audit results are live (updated May 28) — monitor OPAIS for CAPs/sanctions; FQHCs are the largest 340B class.
- OCR's 19 ransomware investigations + 6 2026 settlements preview a tougher HIPAA Security Rule (mandatory annual risk analysis) — incomplete SRAs = building exposure.
Primary source
Sidley Data Matters / HRSA OPA / Nixon PeabodySource packet
This story's primary source + 4 related tracked stories with theirs — one print-ready digest for your team or board packet.
Free — subscribes you to the weekly Intel Brief. Individual sources are always clickable above, no email needed.
This story will move — get the follow-up
The weekly FQHC Intel Brief traces every claim to a primary source, like the one above. Free.
You are signing up for the newsletter you choose, a short welcome sequence, occasional product updates, and one-click unsubscribe. We do not sell your email. Privacy Policy · Do Not Sell/Share
FQHC Talent. (2026, June 1). Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule. Primary source: Sidley Data Matters / HRSA OPA / Nixon Peabody. Retrieved July 23, 2026, from https://www.fqhctalent.com/intel/hrsa-fy26-340b-audit-ocr-risk-analysis-security-rule-preview-2026
More in Risk & Compliance
Jul 16
CMS and CDC reopen the CLIA regulations with a request for information — comments close September 14
Jul 10
Eli Lilly's 340B Termination Turns Into Litigation and Congressional Pushback — Tampa General Sues in Federal Court, 72 House Members Demand HHS Act
Jul 9
OIG declines to sanction an FQHC's produce-box and voucher program — a favorable outcome, but one that legally protects only the health center that asked
Jul 8
$3.3M California Billing-Fraud Settlement Turns on Rendering-Provider NPIs and Uncredentialed NPs/PAs — an Adjacent-Sector Warning FQHCs Should Read Closely