When we got it wrong

9 substantive corrections made to published articles, each with the primary-source citation that drove the change.

Every entry below is a real change to a real article on this site. The corrections come from our ongoing content integrity audits.

We publish them openly. If you read an older version of an article in a cache or saved one to PDF, this page tells you what changed and why.

Fabricated HIPAA Security Rule subsection 45 CFR 164.308(b)(4)

Article: HIPAA Risk Assessment, HIPAA Risk Analysis Documentation, HIPAA Asset Inventory Requirement, and the HIPAA evaluation series

What changed. Four HIPAA articles cited 45 CFR 164.308(b)(4) as the source for written contract requirements with business associates. That subsection does not exist. 164.308(b) terminates at paragraph (3). The written contract requirement lives at 164.308(b)(2) and the implementation specifications at 164.314(a).

Before

“45 CFR 164.308(b)(4) requires a written contract with each business associate that obtains, creates, receives, maintains, or transmits ePHI.”

After

45 CFR 164.308(b)(2) requires a written contract with each business associate. The contract content requirements are spelled out at 45 CFR 164.314(a) (Business Associate Contracts).

Primary source

eCFR Title 45 Part 164 Subpart C, 45 CFR 164.308(b) and 45 CFR 164.314(a) (current text)

Why it matters. A compliance officer verifying our citation against eCFR would have hit a 404 on a fabricated subsection. The error appeared in four articles and two paired meta files. Every instance is now corrected.

HIPAA civil money penalty schedule stale at 2009 HITECH-era figures

Article: HIPAA Breach Notification Requirements, HIPAA Encryption Requirements 2026, Is ChatGPT HIPAA Compliant, Is Slack HIPAA Compliant

What changed. Four HIPAA articles published the 2009 HITECH-era penalty schedule ($100 to $50,000 per violation, $1.5M annual cap) as current. The Department of Justice and HHS apply annual inflation adjustments under the Federal Civil Penalties Inflation Adjustment Act. The 2026 figures are $145 to $2,190,294 per violation, with tier-specific annual enforcement-discretion caps per HHS 2019 Notification (84 FR 18151) and 2026 inflation adjustments (90 FR 6537, multiplier 1.02598).

Before

“HIPAA civil money penalties range from $100 per violation to $50,000 per violation, with a $1.5 million annual cap per identical provision.”

After

HIPAA civil money penalties for 2026 range from $145 to $2,190,294 per violation, with tier-specific annual enforcement-discretion caps ($36,505 for Tier 1, $146,053 for Tier 2, $365,052 for Tier 3, $2,190,294 for Tier 4) per HHS' 2019 Notification of Enforcement Discretion (84 FR 18151) as adjusted by 2026 inflation factors (Federal Register 2026-01688, Jan 28, 2026).

Primary source

45 CFR 160.404; HHS 2019 Notification of Enforcement Discretion (84 FR 18151); Federal Register 2026-01688 (Jan 28, 2026)

Why it matters. A covered entity sizing breach exposure against the stale schedule would understate maximum liability by roughly 43x at the top tier. The penalty range is also the basis for board reporting and cyber insurance underwriting questions. Wrong numbers, wrong board memo.

SOC 2 attestation standard cited as AT-C Section 320 (which governs SOC 1)

Article: Healthcare SaaS SOC 2 Audit Failures, SOC 2 Audit Cost 2026, SOC 2 vs ISO 27001 for Startups, Do I Need SOC 2 Certification

What changed. Four SOC 2 articles cited AT-C Section 320 as the operative attestation standard. AT-C 320 governs SOC 1 reporting (Reporting on Controls at a Service Organization Relevant to User Entities' Internal Control over Financial Reporting). SOC 2 examinations are conducted under AT-C Sections 105 and 205, with reporting performed per the AICPA SOC 2 Reporting Guide. A former Big 4 partner would catch this in 30 seconds.

Before

“SOC 2 examinations are conducted under SSAE 18 AT-C Section 320.”

After

SOC 2 examinations are conducted under SSAE 18 AT-C Sections 105 (Concepts Common to All Attestation Engagements) and 205 (Examination Engagements), with reporting performed in accordance with the AICPA Guide: SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy.

Primary source

AICPA AT-C Section 105; AT-C Section 205; AICPA SOC 2 Reporting Guide

Why it matters. Reading the wrong attestation standard misframes the entire engagement. AT-C 320 imposes requirements that do not apply to SOC 2 (financial-statement audit linkage, ICFR carve-out treatment). Practitioners using the wrong standard would build evidence procedures that do not match what the SOC 2 auditor actually applies.

CISA BOD 22-01 remediation windows framed as 14 days for "high-priority" and 60 days for "all others"

Article: CISA Binding Operational Directives Compliance and CISA KEV Catalog Compliance Guide

What changed. Two cybersecurity articles described BOD 22-01's remediation timeline as 14 days for high-priority KEV entries and 60 days for all others. The actual directive sets the cutoff by CVE-ID issuance year, not priority. CVE-IDs assigned in 2021 or later carry a 14-day remediation window. CVE-IDs assigned prior to 2021 carry a 6-month window. There is no "high-priority" subset and no 60-day window.

Before

“BOD 22-01 requires federal civilian agencies to remediate high-priority KEV entries within 14 days and all other entries within 60 days.”

After

BOD 22-01 requires federal civilian agencies to remediate KEV catalog entries on the following schedule. For vulnerabilities with CVE-IDs assigned in 2021 or later, remediation is due within two weeks (14 days) of catalog inclusion. For vulnerabilities with CVE-IDs assigned prior to 2021, remediation is due within six months of catalog inclusion.

Primary source

CISA Binding Operational Directive 22-01 (Reducing the Significant Risk of Known Exploited Vulnerabilities), cisa.gov/news-events/directives/bod-22-01

Why it matters. A federal agency planning patch SLAs around the wrong framing would either under-resource for the 2021-and-later catalog or over-resource for a fictional 60-day track. The same window applies to FedRAMP-authorized cloud providers via continuous monitoring.

SPRS canonical URL and the partial-credit scoring methodology for §3.5.3 and §3.13.11

Article: SPRS Score Calculation Guide

What changed. The article published the SPRS URL as sprs.pm.mil (incorrect domain) and stated that §3.5.3 (MFA) and §3.13.11 (FIPS) have no partial-credit scoring. Both statements were wrong. The canonical SPRS domain is sprs.csd.disa.mil. Both §3.5.3 and §3.13.11 have partial-credit scoring per DoD Assessment Methodology v1.2.1: §3.5.3 deducts 5 points when MFA is fully missing, 3 points when MFA is implemented for privileged or remote access only. §3.13.11 applies analogous partial-credit logic for FIPS-validated cryptography.

Before

“Submit your self-assessment score at sprs.pm.mil. Two requirements have no partial-credit option: §3.5.3 (multifactor authentication) and §3.13.11 (FIPS-validated cryptography). Either you implement them fully or you take the full deduction.”

After

Submit your self-assessment score at sprs.csd.disa.mil. §3.5.3 (multifactor authentication) and §3.13.11 (FIPS-validated cryptography) DO carry partial-credit scoring per DoD Assessment Methodology v1.2.1. §3.5.3 deducts 5 points when MFA is fully absent, 3 points when MFA is implemented for privileged or remote access only. §3.13.11 follows the same logic.

Primary source

DoD Assessment Methodology v1.2.1 (June 24, 2020), §3.5.3 and §3.13.11; sprs.csd.disa.mil

Why it matters. A contractor reading the wrong URL would land on a domain that does not exist. More substantively, a contractor with MFA implemented for privileged access only would over-deduct (5 points instead of 3), pushing the SPRS score lower than the methodology actually requires. That difference moves the contractor across the joint-surveillance threshold.

Deloitte report name and the framing of the 21% mature-governance statistic

Article: NIST AI RMF Explained

What changed. The article cited "Deloitte State of AI 2026" with the 21% figure presented as the share of all surveyed companies with mature AI governance. The actual report is "Deloitte State of AI in the Enterprise, 8th Edition, 2026" (n=3,235). The 21% figure applies to the subset of 85% planning moderate-to-significant generative AI deployment, not to all surveyed companies. Both the title and the denominator were wrong.

Before

“Only 21% of companies have mature AI governance programs in place [Deloitte State of AI 2026].”

After

Of the 85% of organizations planning moderate-to-significant generative AI deployment, only 21% report mature AI governance programs in place. Survey data from Deloitte State of AI in the Enterprise, 8th Edition, 2026 (n=3,235).

Primary source

Deloitte State of AI in the Enterprise, 8th Edition, 2026, deloitte.com

Why it matters. A board memo citing the original framing would overstate the maturity gap across the whole market. The denominator matters. 21% of an active-deployer subset is a different signal than 21% of everyone.

Colorado AI Act presented as live SB 24-205 (June 30, 2026 effective date, six deployer obligations, rebuttable presumption, NIST AI RMF affirmative defense) after the original law was stayed and then repealed and reenacted by SB 26-189

Article: Colorado AI Act Compliance Playbook

What changed. The article framed Colorado SB 24-205 as operative law with a June 30, 2026 compliance date and a six-obligation risk-based structure. That framework no longer controls. A federal magistrate judge (Cyrus Chung, D. Colo.) stayed enforcement of SB 24-205 on April 27, 2026 in litigation brought by xAI and joined by the U.S. Department of Justice. On May 14, 2026, Governor Polis signed SB 26-189, which repeals and reenacts the Colorado AI Act as a narrower automated decision-making technology (ADMT) statute. The duty of care, risk management program, annual impact assessment, rebuttable presumption, and Section 6-1-1703 affirmative defense are all repealed. The reenacted law imposes four consumer-facing deployer duties (notice at interaction, plain-language adverse-outcome disclosure within 30 calendar days, data correction, and meaningful human review), a developer documentation duty beginning January 1, 2027, AG-exclusive enforcement, and fault-based apportionment for discrimination liability. The new obligations take effect January 1, 2027. The article was rewritten to SB 26-189 with a dated Editor's Note retained at the top.

Before

“Colorado's AI Act (SB 205) takes effect June 30, 2026, making it the first US state law requiring deployers of high-risk AI systems to implement risk management policies, impact assessments, consumer notifications, and appeal processes. Deployers who satisfy all six obligations earn a rebuttable presumption of reasonable care.”

After

Colorado AI Act compliance now runs through SB 26-189 (signed May 14, 2026), which repealed and reenacted SB 24-205 after a federal court stayed the original law on April 27, 2026. The new obligations take effect January 1, 2027 and replace the risk-based duty of care with four consumer-facing duties on deployers of automated decision-making technology (ADMT): clear notice at the point of interaction, plain-language adverse-outcome disclosure within 30 calendar days, correction of inaccurate personal data, and meaningful human review and reconsideration.

Primary source

Colorado SB 26-189 (signed May 14, 2026), leg.colorado.gov/bills/sb26-189; Colorado SB 24-205, leg.colorado.gov/bills/sb24-205; enforcement stay order April 27, 2026 (Magistrate Judge Cyrus Chung, U.S. District Court for the District of Colorado); Crowell & Moring and Holland & Knight client alerts (May 2026); Norton Rose Fulbright litigation summary

Why it matters. An organization building a Colorado compliance program off the original article would have stood up a risk management program, an annual impact assessment, and a NIST AI RMF affirmative defense, none of which survive SB 26-189. The operative law is now a notice-and-transparency regime effective January 1, 2027. Wrong framework, wasted build, and a false read on the live legal status of the statute.

CMMC Phase 2 third-party assessment presented as a live November 10, 2026 deadline after the Department of Defense suspended it on July 13, 2026

Article: CMMC 2.0 Compliance Guide, CMMC Enclave vs Full GCC High Migration Decision, CMMC Level 2 Assessment Preparation, CMMC Enclave Architecture Scoping, and DFARS 252.204-7012 Compliance Requirements

What changed. Five CMMC articles treated CMMC Phase 2, the third-party C3PAO assessment requirement scheduled to begin November 10, 2026, as a live and upcoming deadline. Two ran an explicit countdown, telling readers to reserve a C3PAO slot and describing what happens if they miss the date. On July 13, 2026 the Department of Defense suspended CMMC Phase 2 effective immediately, pending a 60 day review, through two memoranda issued under publication case 26-P-1023: a policy memorandum from the DoD Chief Information Officer and an implementation memorandum from the Under Secretary of Defense for Acquisition and Sustainment. While the suspension runs, contracting officers may designate only CMMC Level 1 Self or CMMC Level 2 Self, and no waivers are issued. CMMC Phase 1 self-assessment, in force since November 10, 2025, is unchanged, as are DFARS 252.204-7012, NIST SP 800-171, and the SPRS score affirmation. Four of the five articles were corrected directly on the live site on July 31, 2026; the fifth was corrected on August 30, 2026. Each now carries a dated note, marks the November 10, 2026 date as suspended rather than operative, and keeps the readiness guidance for when assessments resume.

Before

“CMMC Phase 2 begins November 10, 2026. On that date, contract clauses requiring C3PAO-validated Level 2 certification become active across DoD contracts handling CUI.”

After

CMMC Phase 2, the third-party C3PAO assessment requirement, was scheduled to begin November 10, 2026 but was suspended on July 13, 2026 under case 26-P-1023, effective immediately and pending a 60 day review. CMMC Phase 1 self-assessment, in force since November 10, 2025, remains in effect, and so do DFARS 252.204-7012, NIST SP 800-171, and the SPRS score affirmation.

Primary source

Department of Defense memoranda issued under publication case 26-P-1023 (July 13, 2026): a DoD CIO policy memorandum and a USD(A&S) implementation memorandum. Contemporaneous reporting: Crowell & Moring client alert, Federal News Network, Breaking Defense, DefenseScoop, Washington Technology (July 2026). Suspension re-verified as still in effect on August 30, 2026.

Why it matters. A defense contractor reading the original framing would spend to reserve a finite C3PAO assessment slot and rush readiness against a date that is no longer operative. The suspension resets the near-term calendar but not the underlying obligation. The durable work is Phase 1 self-assessment and NIST SP 800-171 implementation, which the suspension does not touch.

The FedRAMP machine-readable requirement and its September 30, 2026 date presented as operative and attached to FedRAMP 20x, when RFC-0024 is a Rev5-only proposal superseded by CR26

Article: FedRAMP 20x Compliance Guide, RFC-0024 Machine-Readable Compliance, and eight related FedRAMP, OSCAL, and GRC engineering articles

What changed. Ten articles presented FedRAMP's machine-readable authorization requirement, including its September 30, 2026 date and its two-lane priority review pipeline, as an operative deadline, and several attached it to FedRAMP 20x. Primary-source verification established that RFC-0024 is a Request for Comment, that the two-lane priority mechanism it describes, clause LMR-FRX-PRM, applies to the FedRAMP Rev5 process and not to FedRAMP 20x, and that September 30, 2026 does not appear among the Important Dates published for the Consolidated Rules for 2026. CR26 is the single standard every submission is measured against and takes mandatory effect on January 1, 2027. Each article now presents September 30, 2026 as a proposal, scopes the machine-readable priority mechanism to Rev5, anchors on CR26, and points readers to the CR26 timeline for the operative dates. Where the earlier Notice 0009 milestone of November 1, 2027 for Rev5 Class D still appears, it is now attributed to Notice 0009 by name, with an instruction to confirm against the CR26 timeline. It was neither deleted nor asserted as a CR26 deadline, because Notice 0009 has not been withdrawn and still publishes that date, while CR26 does not restate it and Notice 0009 defers its own timelines to CR26.

Before

“FedRAMP 20x mandates machine-readable OSCAL packages for new providers and annual assessments by September 30, 2026 per RFC-0024, enforced through a two-speed submission pipeline.”

After

RFC-0024 is a Request for Comment. Its two-lane priority mechanism, clause LMR-FRX-PRM, applies to the FedRAMP Rev5 process and does not apply to FedRAMP 20x. Its September 30, 2026 date was a proposal and does not appear among the Important Dates for the Consolidated Rules for 2026. The binding standard is CR26, mandatory on January 1, 2027, with the machine-readable requirements phasing in across 2027 on the schedule CR26 publishes.

Primary source

FedRAMP RFC-0024 (fedramp.gov/rfcs/0024); FedRAMP Consolidated Rules for 2026 Important Dates (fedramp.gov/2026/timeline); FedRAMP Notice 0009 (fedramp.gov/notices/0009). All three re-verified on August 30, 2026.

Why it matters. A cloud service provider reading the original framing would treat a proposed Rev5 date as a hard 20x deadline, and could build a machine-readable package for a requirement that does not apply to its 20x path, against a date that was never operative. The binding schedule is CR26. The two-lane mechanism belongs to the Rev5 process only.

Spotted something we got wrong?

Tell us. We post corrections within 14 days of verification and credit the reader who flagged the issue when they give us permission.

Submit a correction
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.