HHS Releases Updated Security Risk Assessment Tool
HHS OCR and ONC released version 3.7 of the Security Risk Assessment Tool for healthcare organizations.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) released version 3.7 of the Security Risk Assessment (SRA) Tool. The tool helps covered entities conduct HIPAA security risk assessments. ONC and OCR provided guidance on the updates.
NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities
New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.
On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.