January 21, 2026 at 1:00 pm (EDT)
WEBINAR
ON-DEMAND

Security Policies: Requirements and Best Practices for Compliance with HIPAA, 42 CFR Part 2, and Information Blocking

Recorded on October 1, 2026

Program Information

Overview
Learning Objectives
Instructor
Continuing Education
Registration
Security Policies: Requirements and Best Practices for Compliance with HIPAA, 42 CFR Part 2, and Information Blocking

Health centers face a complex compliance landscape when it comes to creating and maintaining security policies - from HIPAA Security Rule requirements for administrative, physical and technical safeguards to 42 CFR Part 2’s consent, disclosure and formal policy requirements, to the Information Blocking Rule’s exceptions under the 21st Century Cares Act. To take advantage of the flexibilities the Information Blocking Rule allows – including the Security and Infeasibility Exceptions - health centers must adopt additional written policies. These policies must not conflict with existing HIPAA and Part 2 policies, while providing a clear process to evaluate and document whether an exception applies to a given disclosure decision.

This webinar will walk attendees through the current regulatory requirements shaping organizational security policies – including recent updates to Part 2 and the Information Blocking exceptions - and provide practical strategies for building (or updating) a policy framework that satisfies all three regimes without creating unnecessary friction for patient care or data sharing.
Who should attend:

  • Compliance Officers
  • Security Officers
  • Privacy Officers
  • HIM
  • Operations
This course has been submitted to the National Association of State Boards of Accountancy (NASBA) for approval of Continuing Professional Education (CPE). Upon approval, participants will be able to earn 1 CPE credit in Specialized Knowledge field of study upon completion of all course requirements.
Credit Information:

CPE Credits:

1.00 CPE 

NASBA Field of Study:

Specialized Knowledge

Program Knowledge Level:

Intermediate

Prerequisites:

Participants should be able to accurately define the HIPAA Security Rule's administrative, physical, and technical safeguard requirements and list at least two examples of each.

Advance Preparation:

None

Delivery Method:

Group
Attendee Requirements for CPE Credit:
You must satisfy the following conditions in order to obtain your CPE credit and receive your certificate:

  • Attend the live version of the webinar. 
  • Answer at least three (3) of the polling questions during the webinar.
  • Complete the evaluation survey after the conclusion of the webinar or in the follow-up email.


Upon completion of these requirements, we will email you your CPE Certificate within one (1) week.
Powers Pyles Sutter & Verville PC is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website www.nasbaregistry.org.
Dianne Pledgie

Principal

Powers Pyles Sutter & Verville PC

Dianne advises health care and non-profit organizations on the development and implementation of robust compliance programs.

Dianne also provides legal guidance on privacy, security and confidentiality matters, with particular focus on Health Insurance Portability and Accountability Act (HIPAA), 42 C.F.R. Part 2 and the Information Blocking Rule, including:
  • Advising clients on their obligations to protect patient records, respond to patient requests, and develop policies and procedures;
  • Reviewing business associate agreements, data use agreements, and patient consents related to the use and disclosure of protected health information and sensitive information; and
  • Supporting clients experiencing security incidents.
Registration Requirements
An account is required to complete registration: log in to your existing account or create a new one during checkout. For the best experience, we recommend using Google Chrome (Mozilla Firefox and Apple Safari are also fully supported).
CPE Eligibility Notice:
This program is delivered in a Group program format via live webinar. Your purchase includes access to both the live session and the on-demand recording afterward, but only the live version is eligible for CPE credit. The on-demand recording does not meet the Group program requirements for real-time attendance verification. To earn CPE credit, you must register in advance and attend the live broadcast.
Refunds and Cancellations:
For details on refunds, transfers, and program cancellations, please visit Refunds and Cancellations.
Complaint Resolution:
Concerns or complaints may be submitted by email to training@powerslaw.com or via the Contact Form. For additional details, please visit Frequently Asked Questions.
By the end of this webinar, participants will be able to:

  1. Identify the administrative, physical, and technical safeguard requirements under the HIPAA Security Rule and how they intersect with 42 CFR Part 2's consent, disclosure, and formal policy requirements — including changes from the 2024 Part 2 Final Rule.
  2. Apply the Information Blocking Rule's exception framework — particularly the Security and Infeasibility Exceptions — to determine when a health center's decision to withhold or restrict access to electronic health information is defensible instead of information blocking.
  3. Draft or revise written policies that satisfy the documentation requirements of the Information Blocking exceptions without creating conflicts with existing HIPAA and Part 2 policies.