top of page
Search

The HIPAA Security Rule Is Getting Stricter: What Small Healthcare Businesses Should Do Now

Writer: Christine
Christine
Aug 22
3 min read

If you run a medical practice, dental office, behavioral health clinic, or any business that touches patient data, you've probably heard rumblings about changes coming to the HIPAA Security Rule. Here's the short version: after years of relatively loose "addressable" requirements, HHS is moving toward a much stricter, more prescriptive standard — and even though the final rule has slipped on the calendar, the direction of travel is clear enough that waiting to prepare is a risky bet.


What's Actually Changing

The Department of Health and Human Services' Office for Civil Rights proposed a significant overhaul of the Security Rule, and while the final rule has been pushed back (current estimates point to 2027), the proposal itself tells you exactly where enforcement is headed:


Encryption becomes mandatory, not optional. Today, encrypting electronic protected health information (ePHI) at rest and in transit is technically "addressable," which has always given smaller practices some wiggle room to document why they weren't doing it. Under the proposed rule, that wiggle room disappears. Encryption would be required, full stop, with only narrow exceptions.


Multi-factor authentication (MFA) is required for all system access. Not just remote access or admin accounts — all access to systems that touch ePHI. If your staff is still logging into your EHR or billing system with just a username and password, that's a gap worth closing now rather than under deadline pressure later.


The "required vs. addressable" distinction goes away. This is the big structural shift. For two decades, HIPAA has let covered entities treat many safeguards as flexible based on their size and risk. The proposed rule collapses that flexibility, making most implementation specifications mandatory regardless of organization size.


Asset inventories, network segmentation, and incident response planning move from best practice to baseline expectation. OCR's enhanced cybersecurity performance goals — things like maintaining a current inventory of systems that touch ePHI, segmenting networks, and having a documented incident response plan — are increasingly treated as the floor, not the ceiling, during investigations.


Why This Matters Even Though the Deadline Moved

It's tempting to file this under "future problem" since the final rule isn't expected until 2027. But two things make that a mistake. First, OCR doesn't need a finalized rule to increase enforcement pressure around risk analysis and access controls — both are already priority areas under current law, and investigators are signaling more assertive enforcement now. Second, once the rule is finalized, covered entities will likely get only about 180 days to comply. Retrofitting encryption, MFA, and network segmentation into a live healthcare practice in six months is a scramble. Building it in gradually, starting now, is a plan.


Practical Takeaways for Small and Mid-Size Practices

  • Run (or update) your HIPAA risk analysis this year. This is already required under current law and is the single most cited deficiency in OCR enforcement actions — don't wait for the new rule to make it urgent.

  • Turn on MFA everywhere ePHI lives — EHR, email, billing systems, cloud storage — not just for remote logins.

  • Confirm encryption is actually enabled for data at rest and in transit, not just theoretically supported by your software.

  • Build a real asset inventory of every system, device, and application that stores or transmits patient data. You can't protect what you haven't catalogued.

  • Document an incident response plan and walk through it at least once with your team, even informally.

  • Revisit business associate agreements with vendors who touch patient data, since the proposed rule also raises expectations for business associates specifically.


The Bottom Line

The direction here isn't ambiguous, even if the timeline is. Practices that treat the next year as a runway to strengthen risk analysis, access controls, and encryption will be in a far better position than those that wait for a final rule and a countdown clock.


Compliance work spread over months is manageable; compliance work compressed into 180 days is expensive and stressful.


If you're not sure where your practice stands against these expectations — or you know you're behind and want a clear-eyed plan to catch up — that's exactly the kind of gap analysis we help clients work through. Reach out to The Compliance Labs for a consultation, and we'll help you figure out what's actually urgent versus what can wait.

 
 
 

Recent Posts

See All

Comments


bottom of page