Cybersecurity: 24/7/365

Blog

How to Prepare for the New HIPAA Security Rule
by 4MEDNET Team
September 3, 2026
HIPAA Compliance

Your office manager forwards you a newsletter headline: "New HIPAA rules for 2026." She wants to know what to buy and who to call. She also wants to know whether you are already behind. The honest answer is that nothing is final yet — and that the practices starting now will spend less and scramble less than the ones who wait.

This guide is the how. For the full list of what the proposal would change, start with our breakdown of the HIPAA Security Rule changes. What follows is the order to do the work in, who should do each part, and what to keep on file.

Is the new HIPAA Security Rule final yet?

No. There are no new HIPAA Security Rule requirements in force for 2026. The Office for Civil Rights (OCR) is part of the United States Department of Health and Human Services (HHS).

OCR published a notice of proposed rulemaking, which appeared in the Federal Register on January 6, 2025. The comment period closed that March.

The regulatory agenda now projects final action in July 2027. That is a planning estimate, and it has already slipped once.

If the final rule publishes as proposed, it takes effect 60 days later. Covered entities then get another 180 days to reach compliance — roughly eight months in total.

Eight months is not much time to buy hardware, retrain staff and rewrite your security policies for full HIPAA compliance. That is the case for starting before the final rule, not after it.

Why start before the rule is final?

Because almost none of this work is wasted if the proposed changes shift. The existing Security Rule under the Health Insurance Portability and Accountability Act (HIPAA) already requires a risk analysis. It also requires reasonable security measures for electronic protected health information (ePHI).

The proposal mostly turns today's good cybersecurity practice into written, dated, mandatory security controls. Few of the new requirements would surprise any healthcare organization that already takes security seriously.

Multi-factor authentication, encryption, tested backups and an incident response plan protect you from ransomware whatever the final text says. They are no-regret cybersecurity spending. The parts most likely to change are the details — review frequencies, exceptions, deadlines — not the controls themselves.

What should you do first?

Build your asset inventory. Every other step depends on it, and it costs almost nothing but time. You cannot encrypt a laptop, patch a server or turn on MFA for a system you never listed.

Walk the office with a spreadsheet. Record every workstation, laptop, server, phone, tablet, printer, imaging device and cloud service that stores or touches ePHI.

Include your electronic health record (EHR) system and any information technology a vendor runs for you. Note the operating system, who uses it, and who supports it.

Then draw how patient data moves: check-in to the EHR, the EHR to the billing clearinghouse, the server to the cloud backup. The proposed rule requires both documents, reviewed at least every 12 months. More usefully, the map shows you where your data actually leaves the building.

The order that makes each step cheaper

Sequence matters more than speed. Each phase below produces something the next phase needs, so doing them out of order means paying twice.

Phase 1 — Weeks 1 to 4: inventory and risk analysis

Finish the inventory and data map, then refresh your security risk assessment against them. An incomplete risk analysis is one of the failures OCR cites most often. Building yours on a real inventory, not a guessed one, is how you avoid it. Our HIPAA risk assessment checklist walks through the method.

The HIPAA Security Rule requires you to assess the risks and vulnerabilities to ePHI on each system. Score what could go wrong and how badly, then list the security gaps. The output is your ranked to-do list for everything that follows.

Phase 2 — Months 2 to 3: the controls attackers use most

Turn on MFA for email, the EHR, remote access and every admin account. Stolen passwords remain the easiest way in, and setting up MFA takes days, not months.

Enable full-disk encryption on every laptop and workstation, and confirm your backups are encrypted too. Put patching on a schedule someone actually owns. The proposal sets 15 days for critical patches and 30 days for high-risk ones, so measure how long yours take today.

Phase 3 — Months 4 to 6: recovery and response

Prove you can restore. The proposal asks for critical electronic information systems back within 72 hours. Many practices have never timed a restore.

Run one, write down how long it took, and fix what broke. Our guide to backup and disaster recovery planning covers the setup.

Write your incident response plan, then test it with a one-hour tabletop exercise. Walk through a ransomware morning: who calls whom, and how you keep seeing patients.

The Security Rule requires you to respond to suspected or known security incidents. The Breach Notification Rule then decides whether one becomes a reportable breach.

Add network segmentation while you are here. Guest Wi-Fi, medical devices and front-office computers should not share one flat network.

Phase 4 — Months 6 to 8: your business associates

List every HIPAA business associate that handles ePHI: EHR vendor, clearinghouse, IT provider, backup service, answering service. The proposed rule would require each business associate to verify its technical safeguards in writing every year. That turns vendor compliance from a signed form into evidence you can check.

Start that conversation now. Ask each vendor what it has in place, and update your agreements when they renew. Our business associate agreement guide covers the clauses worth adding.

Phase 5 — Months 9 to 12: scanning and testing

Schedule vulnerability scanning and your first penetration test last, not first. Testing before the basics are fixed means paying a firm to report problems you already knew about. Tested after phases 1 to 4, the report finds what you missed.

The proposal would require scanning at least every six months and a penetration test at least every 12 months. After this first year, the work becomes an annual cycle rather than a project.

Who does what in a small practice?

You do not need a security team. You need clear owners. Here is how the work usually splits for a practice of five to twenty-five people:

TaskPractice staffIT providerOutside firm
Asset inventory and data mapSupplies factsBuilds and maintains
Security risk assessmentOwns decisionsTechnical inputOptional reviewer
MFA, encryption, patchingDeploys and monitors
Backups and restore testsSigns offRuns and records
Incident response planOwns and rehearsesTechnical steps
Business associate reviewsOwns contractsAssesses answers
Penetration testApproves scopeFixes findingsPerforms test
HIPAA trainingRuns and tracksPhishing drills

The pattern matters more than the names. The practice owns decisions, the IT provider owns execution, and an independent firm tests the result. If one vendor both builds and tests your security, nobody is checking the work.

What evidence should you keep?

Under the proposal, a control you cannot prove does not exist. Compliance becomes a matter of records, so keep a dated folder for each of these:

  • Asset inventory and network map, with the date of each review
  • Risk analysis and the risk management plan it produced
  • Written security policies, signed and dated
  • Patch reports showing time from release to install
  • Backup logs and at least one timed restore test
  • Incident response plan and tabletop notes
  • Business associate agreements and each vendor's safeguard answers
  • Training records, including phishing test results

This folder is also what you hand an auditor, an insurer or OCR during an investigation. Building it now costs hours; rebuilding it under a deadline costs weeks.

What does HIPAA training need to cover?

Security awareness and training already sits in the current HIPAA Security Rule, alongside workforce security. The HIPAA Privacy Rule has its own training duty, so one program can cover both. The proposal adds timing: training within 30 days of a new hire getting system access, and a refresher at least every 12 months.

Make it specific to your office. Show staff real phishing examples and how to report a suspicious email.

Cover what to do when a screen looks wrong, because cybersecurity starts at the front desk. A five-minute monthly drill teaches more than one annual video.

How do you plan for a rule that might change?

Build to the controls, not to the citations. HIPAA Security Rule updates change wording far more often than they change what a strong security posture looks like.

If the final rule changes a review interval from 12 months to 18, a practice with working MFA and tested backups loses nothing. A practice that waited loses the whole runway.

Check the federal regulatory agenda each spring and fall, when the July 2027 estimate may move. Watch for any new guidance on healthcare cybersecurity from HHS in between.

When the final rule publishes, check your compliance with the Security Rule against your evidence folder. The gap becomes a short list rather than a project.

Most of this work pays off long before any deadline. It is the same work that keeps your ePHI safe and a ransomware attack from closing your doors for a week. If you want help sequencing it, our HIPAA compliance services start with exactly this inventory and gap assessment.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

Tags:
Share:
HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment