Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

HIPAA Security Rule 2026: What's Changing for Practices

The biggest HIPAA Security Rule overhaul in over a decade is coming, and it turns "should" into "must." Federal regulators proposed rewriting the rule so that safeguards practices could previously skip — multi-factor authentication, encryption, penetration testing — become mandatory for every system that touches patient data. It isn't final yet. But the direction is set, and 2026 is the year to get ahead of it — the smart move for a medical or dental practice is to close the gaps now rather than scramble once a final rule lands.

Is the new HIPAA Security Rule in effect yet?

No. The Office for Civil Rights published the proposed rule in the Federal Register on January 6, 2025, and the comment period closed 60 days later, on March 7, 2025. As HHS's own Security Rule page shows, it's still a proposal — OCR is working through thousands of public comments, and a final rule hasn't been issued. The timeline has already slid past OCR's original target, and there's no binding effective date yet.

Here's the catch: proposals like this rarely get softer. When rules move through comment review, the core requirements usually survive. Practices that wait for the final text are choosing to do in a panic what they could do calmly now.

What the proposed rule would require

The draft reads like a modern security checklist, which is the point. Per OCR's official fact sheet on the proposal, the headline changes:

  • Multi-factor authentication on every system that can reach electronic patient data, with limited exceptions — no more treating it as optional.
  • Encryption of patient data both at rest and in transit, with limited exceptions.
  • Asset inventory and network map: a documented list of every system, device, and app that handles patient data, plus a map of how that data moves, reviewed at least every 12 months. You can't protect what you haven't counted.
  • Vulnerability scanning and penetration testing: scans at least every six months and a penetration test at least once a year.
  • Network segmentation so a breach in one corner doesn't hand an attacker the whole practice.
  • 24-hour breach notice from vendors: your business associates would have to tell you within a single day when they're hit.

These aren't exotic. Most are what a well-run practice already does. The proposal just stops letting anyone opt out.

Why "addressable" going away is the real story

Today's Security Rule splits safeguards into "required" and "addressable." Addressable got read — wrongly — as optional, and plenty of practices skipped encryption or MFA and wrote a note explaining why. The proposal scraps that flexibility. Nearly everything becomes required, with narrow documented exceptions.

That single change is what's driving the fight. OCR drew thousands of comments, and most of them center on the shift from addressable to mandatory. For a small practice, it removes the gray area you might have been leaning on. The gap between "we meant to turn on MFA" and "we're compliant" closes fast.

What your practice should do now

Treat the proposal as a preview of your next audit and act on the items that are just good security regardless of what the final rule says.

Turn on MFA everywhere it isn't already — email, the practice management system, remote access. Confirm encryption on laptops, servers, and backups. Build the asset inventory; it's tedious once and easy to maintain after. Schedule a vulnerability scan. None of that is wasted work if the timeline slips, because every one of those controls is what cyber insurers and existing HIPAA risk analyses already expect.

If you want a baseline before the rule lands, that's exactly what a cybersecurity assessment produces: where you stand against these controls, and a punch list to close the gaps. For the fundamentals that don't change, our HIPAA IT compliance checklist and our guide to managed IT for medical and dental practices both walk through the day-to-day.

Written by Joel Baum, who leads cybersecurity and compliance at The NetSys Group. NetSys has delivered managed IT, cybersecurity, and cloud services since 1998, and our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors.

Frequently asked questions

When does the new HIPAA Security Rule take effect?

There's no effective date yet. The proposed rule was published January 6, 2025, the comment period closed that March, and OCR is still reviewing the public comments. A final rule hasn't been issued, its timeline has already slipped, and there's no legally binding effective date to plan around.

Will MFA and encryption really be mandatory?

That's the proposal. Both multi-factor authentication and encryption of patient data — at rest and in transit — would become required rather than "addressable." Because these controls are already security best practice and insurer expectations, waiting for the final rule to adopt them carries little upside and real risk.

Does this apply to small medical and dental practices?

Yes. The Security Rule applies to all covered entities regardless of size, and the proposal doesn't carve out small practices. A two-provider dental office would face the same core requirements — MFA, encryption, asset inventory, testing — as a large group, scaled to its systems.

What should we do before the rule is final?

Close the obvious gaps now: enable MFA everywhere, confirm encryption on all devices and backups, build a current asset inventory, and run a vulnerability scan. These are already expected under today's risk-analysis requirement and by cyber insurers, so the work counts whether the final rule arrives in 2027 or sooner.

Not sure where your practice stands against what's coming? Book a complimentary risk assessment and we'll map your gaps against the proposed requirements.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.