Cybersecurity: 24/7/365

Your office manager forwards you a newsletter headline: "New HIPAA rules for 2026." She wants to know what to buy and who to call. She also wants to know whether you are already behind. The honest answer is that nothing is final yet — and that the practices starting now will spend less and scramble less than the ones who wait.
This guide is the how. For the full list of what the proposal would change, start with our breakdown of the HIPAA Security Rule changes. What follows is the order to do the work in, who should do each part, and what to keep on file.
No. There are no new HIPAA Security Rule requirements in force for 2026. The Office for Civil Rights (OCR) is part of the United States Department of Health and Human Services (HHS).
OCR published a notice of proposed rulemaking, which appeared in the Federal Register on January 6, 2025. The comment period closed that March.
The regulatory agenda now projects final action in July 2027. That is a planning estimate, and it has already slipped once.
If the final rule publishes as proposed, it takes effect 60 days later. Covered entities then get another 180 days to reach compliance — roughly eight months in total.
Eight months is not much time to buy hardware, retrain staff and rewrite your security policies for full HIPAA compliance. That is the case for starting before the final rule, not after it.
Because almost none of this work is wasted if the proposed changes shift. The existing Security Rule under the Health Insurance Portability and Accountability Act (HIPAA) already requires a risk analysis. It also requires reasonable security measures for electronic protected health information (ePHI).
The proposal mostly turns today's good cybersecurity practice into written, dated, mandatory security controls. Few of the new requirements would surprise any healthcare organization that already takes security seriously.
Multi-factor authentication, encryption, tested backups and an incident response plan protect you from ransomware whatever the final text says. They are no-regret cybersecurity spending. The parts most likely to change are the details — review frequencies, exceptions, deadlines — not the controls themselves.
Build your asset inventory. Every other step depends on it, and it costs almost nothing but time. You cannot encrypt a laptop, patch a server or turn on MFA for a system you never listed.
Walk the office with a spreadsheet. Record every workstation, laptop, server, phone, tablet, printer, imaging device and cloud service that stores or touches ePHI.
Include your electronic health record (EHR) system and any information technology a vendor runs for you. Note the operating system, who uses it, and who supports it.
Then draw how patient data moves: check-in to the EHR, the EHR to the billing clearinghouse, the server to the cloud backup. The proposed rule requires both documents, reviewed at least every 12 months. More usefully, the map shows you where your data actually leaves the building.
Sequence matters more than speed. Each phase below produces something the next phase needs, so doing them out of order means paying twice.
Finish the inventory and data map, then refresh your security risk assessment against them. An incomplete risk analysis is one of the failures OCR cites most often. Building yours on a real inventory, not a guessed one, is how you avoid it. Our HIPAA risk assessment checklist walks through the method.
The HIPAA Security Rule requires you to assess the risks and vulnerabilities to ePHI on each system. Score what could go wrong and how badly, then list the security gaps. The output is your ranked to-do list for everything that follows.
Turn on MFA for email, the EHR, remote access and every admin account. Stolen passwords remain the easiest way in, and setting up MFA takes days, not months.
Enable full-disk encryption on every laptop and workstation, and confirm your backups are encrypted too. Put patching on a schedule someone actually owns. The proposal sets 15 days for critical patches and 30 days for high-risk ones, so measure how long yours take today.
Prove you can restore. The proposal asks for critical electronic information systems back within 72 hours. Many practices have never timed a restore.
Run one, write down how long it took, and fix what broke. Our guide to backup and disaster recovery planning covers the setup.
Write your incident response plan, then test it with a one-hour tabletop exercise. Walk through a ransomware morning: who calls whom, and how you keep seeing patients.
The Security Rule requires you to respond to suspected or known security incidents. The Breach Notification Rule then decides whether one becomes a reportable breach.
Add network segmentation while you are here. Guest Wi-Fi, medical devices and front-office computers should not share one flat network.
List every HIPAA business associate that handles ePHI: EHR vendor, clearinghouse, IT provider, backup service, answering service. The proposed rule would require each business associate to verify its technical safeguards in writing every year. That turns vendor compliance from a signed form into evidence you can check.
Start that conversation now. Ask each vendor what it has in place, and update your agreements when they renew. Our business associate agreement guide covers the clauses worth adding.
Schedule vulnerability scanning and your first penetration test last, not first. Testing before the basics are fixed means paying a firm to report problems you already knew about. Tested after phases 1 to 4, the report finds what you missed.
The proposal would require scanning at least every six months and a penetration test at least every 12 months. After this first year, the work becomes an annual cycle rather than a project.
You do not need a security team. You need clear owners. Here is how the work usually splits for a practice of five to twenty-five people:
| Task | Practice staff | IT provider | Outside firm |
|---|---|---|---|
| Asset inventory and data map | Supplies facts | Builds and maintains | — |
| Security risk assessment | Owns decisions | Technical input | Optional reviewer |
| MFA, encryption, patching | — | Deploys and monitors | — |
| Backups and restore tests | Signs off | Runs and records | — |
| Incident response plan | Owns and rehearses | Technical steps | — |
| Business associate reviews | Owns contracts | Assesses answers | — |
| Penetration test | Approves scope | Fixes findings | Performs test |
| HIPAA training | Runs and tracks | Phishing drills | — |
The pattern matters more than the names. The practice owns decisions, the IT provider owns execution, and an independent firm tests the result. If one vendor both builds and tests your security, nobody is checking the work.
Under the proposal, a control you cannot prove does not exist. Compliance becomes a matter of records, so keep a dated folder for each of these:
This folder is also what you hand an auditor, an insurer or OCR during an investigation. Building it now costs hours; rebuilding it under a deadline costs weeks.
Security awareness and training already sits in the current HIPAA Security Rule, alongside workforce security. The HIPAA Privacy Rule has its own training duty, so one program can cover both. The proposal adds timing: training within 30 days of a new hire getting system access, and a refresher at least every 12 months.
Make it specific to your office. Show staff real phishing examples and how to report a suspicious email.
Cover what to do when a screen looks wrong, because cybersecurity starts at the front desk. A five-minute monthly drill teaches more than one annual video.
Build to the controls, not to the citations. HIPAA Security Rule updates change wording far more often than they change what a strong security posture looks like.
If the final rule changes a review interval from 12 months to 18, a practice with working MFA and tested backups loses nothing. A practice that waited loses the whole runway.
Check the federal regulatory agenda each spring and fall, when the July 2027 estimate may move. Watch for any new guidance on healthcare cybersecurity from HHS in between.
When the final rule publishes, check your compliance with the Security Rule against your evidence folder. The gap becomes a short list rather than a project.
Most of this work pays off long before any deadline. It is the same work that keeps your ePHI safe and a ransomware attack from closing your doors for a week. If you want help sequencing it, our HIPAA compliance services start with exactly this inventory and gap assessment.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.