The Department of Health and Human Services reshuffled one of its most consequential enforcement arms this week, a move that industry observers say could slow HIPAA enforcement at precisely the wrong moment for healthcare-adjacent financial services firms.
HHS announced the reorganization of its Office for Civil Rights into three distinct divisions: a revived Conscience and Religious Freedom Division, a Civil Rights Division, and a Health Information Privacy, Data, and Cybersecurity Division. The restructuring mirrors a configuration used during President Trump’s first term, when the conscience and religious freedom unit was first created in 2018 before being dissolved by the Biden administration in 2023.
For professionals in the credit and collection industry, the HIPAA angle is the one to watch. Healthcare debt collection sits at the intersection of two heavily regulated worlds, with collectors regularly handling protected health information on behalf of provider clients. Any shift in OCR’s enforcement posture, staffing priorities, or rulemaking timeline ripples directly into compliance obligations for agencies, debt buyers, and the healthcare providers that place accounts with them.
The resource picture is not encouraging. OCR currently operates with just 116 full-time employees, down sharply from a mid-decade peak of 163 to 195 staff. Former OCR adviser Rachel Seeger put it plainly in a published report: the agency is “resource-starved,” running a $39.7 million operating deficit. A forthcoming budget would bring headcount to 144, still well below historical levels. HHS has pledged no further workforce reductions from the reorganization itself, but experts warn the incoming conscience and religious freedom portfolio will absorb a meaningful share of those limited resources.
That leaves the privacy and cybersecurity division to manage a surging caseload with a depleted bench. Healthcare data breaches increased in 2025, complaint volumes continue to climb, and OCR’s breach verification process has already slowed noticeably. Two long-awaited regulatory updates, to the HIPAA Privacy Rule and the HIPAA Security Rule, remain in limbo. OCR had provisionally targeted May 2026 for a final Security Rule update. That deadline appears to have passed quietly.
For collection industry compliance teams, the practical implication is uncertainty. Slower OCR investigations may reduce near-term enforcement pressure, but delayed Security Rule finalization makes it harder to plan ahead. Firms handling medical accounts should monitor the Federal Register closely, where OCR has committed to publishing additional restructuring details next month, and should not assume that a quieter agency means a more permissive one.




