Skip to content
Analytica Solutions

HIPAA Security Rule 2026: what a Michigan practice does now

Mir · · 7 min read

Topics: Hipaa,Security,Compliance,Practice management

The HIPAA Security Rule update is still a proposal, not a rule, and the date for finalising it has slipped from May 2026 to July 2027. That is the news. The rest is that the proposal has not changed, the breach figures that produced it have got worse, and every item in it is something a Michigan practice can do this quarter without waiting for the Federal Register. This post lists what the proposed rule would require, what the numbers behind it say, and the order to do it in for a practice with one office manager and no IT department.

In short

  • Proposed rule published January 6, 2025; comments closed March 7, 2025. The final rule's target on the federal regulatory agenda is now July 2027, per HIPAA Journal.
  • 804 large healthcare breaches were reported to HHS in 2025, up from 738 in 2024, affecting about 138.5 million people. Hacking accounted for more than 80% of them.
  • The proposal makes multifactor authentication, encryption at rest and in transit, six-monthly vulnerability scans, annual penetration tests and 72-hour restoration mandatory for every covered entity, with no small-practice exemption.
  • In 2022, 55% of OCR's financial penalties fell on small medical practices, per HIPAA Journal.
A physician in a white coat with a stethoscope works at a laptop at a small table in a clinic
The proposal is written for a health system's security team. The practice reading it has an office manager. Photo: Pavel Danilyuk, Pexels.

Where the rule stands in September 2026

The Department of Health and Human Services published the proposed Security Rule in the Federal Register on January 6, 2025. It was the first substantive rewrite since 2013, and the comment period closed on March 7, 2025 with more than 4,000 comments filed. Under the old timetable a final rule could have appeared by May 2026. It did not. HIPAA Journal reported in 2026 that the Office of Management and Budget's regulatory agenda now lists July 2027 for the final rule. Nothing in the current Security Rule changed in the meantime, and it is still enforced.

Two ways to read the delay. One is that a practice has two more years. The other is that the practice has two more years of the current rule, under which the same breaches keep happening and the same penalties keep landing, and that the proposal is a published list of what HHS thinks a compliant practice looks like. The second reading is the useful one.

What the proposed Security Rule requires

The proposal's central move is to remove the distinction between "required" and "addressable" implementation specifications. Under the current rule a practice can document why an addressable safeguard, encryption being the famous one, was not reasonable for it. Under the proposal there is no addressable category. Everything is required, with narrow exceptions. The specific additions, from the HHS fact sheet and the Federal Register text:

RequirementProposed standard
Written policies and proceduresAll Security Rule policies documented and reviewed
Technology asset inventory and network mapWritten, showing where ePHI moves, updated at least every 12 months
Risk analysisWritten, with specific required elements, updated at least every 12 months
Multifactor authenticationRequired on systems holding ePHI, with limited legacy and emergency exceptions
EncryptionRequired for ePHI at rest and in transit
Vulnerability scanningAt least every 6 months
Penetration testingAt least every 12 months
Restoration of critical systemsWithin 72 hours of a loss
Workforce access changesRelevant parties notified within 24 hours of a change or termination
Compliance auditAt least every 12 months
Business associate safeguardsWritten verification by a qualified person at least every 12 months

None of that is exotic for a health system. For a three-provider dental office in Livonia, the asset inventory alone is a day's work nobody has scheduled.

Why the numbers make waiting expensive

A dental clinician reviews panoramic and sectional x-rays on a desktop monitor beside a keyboard and a clipboard
Images, charts, claims, recordings: every one is electronic protected health information under the rule. Photo: cottonbro studio, Pexels.

HIPAA Journal's running tally of breaches reported to HHS counts 804 large breaches, those affecting 500 or more people, in 2025, up from 738 in 2024. About 138.5 million people were affected in 2025. Hacking and other IT incidents accounted for more than 80% of the large breaches that year. In its own proposal HHS cited a survey in which 92% of healthcare organisations reported a cyberattack in the previous year, and nearly three quarters of those said it affected patient care.

The enforcement side is the part small practices tend not to hear. HIPAA Journal's analysis of OCR penalties found that in 2022, 55% of the financial penalties were imposed on small medical practices, not on hospitals. The practice that assumes it is too small to be a target is the practice that is easiest to breach and simplest to fine, and the proposed rule's removal of the addressable category takes away the paragraph that used to explain why encryption had not been switched on.

What to do this quarter, in order

A receptionist in grey scrubs uses a tablet at a clinic front desk
The inventory starts at the front desk: every device that can reach a chart is a row. Photo: Cedric Fauntleroy, Pexels.
  1. Write the asset inventory. Every device, application and service that stores, sends or can reach patient information: the practice management system, the imaging software, the laptop the bookkeeper uses at home, the phone system, the text reminder service, the cloud backup. One row each, with who runs it and where the data sits. This is the proposed rule's network map, and it is the document every other step reads from.
  2. Turn on multifactor authentication everywhere the inventory allows. The practice management system, email, the remote access tool, the backup console. Where a system cannot do it, write down that it cannot; that is the exception the proposal allows, and it is only an exception if it is written.
  3. Encrypt the two things that get lost. Laptops and phones. Full-disk encryption is a setting on every current operating system, and a stolen encrypted laptop is a stolen laptop rather than a reportable breach.
  4. Test a restore. The proposal says critical systems back within 72 hours. Ask the backup vendor to restore last Tuesday's schedule to a test machine and time it. A backup that has never been restored is a hope.
  5. Collect the business associate agreements. Every vendor in the inventory that touches patient information needs one, and the proposal wants written verification of their safeguards every year. That includes the answering service, the reminder platform and any AI tool that reads a call or an intake form.
  6. Put the access-change step in the offboarding checklist. When a staff member leaves, the accounts are closed the same day and the closure is written down. The proposal's 24-hour window is the standard; the practice that does it in an hour is the one with a checklist.

The mistake most practices make at step 5

They treat the business associate agreement as the vendor's paperwork and sign whatever arrives, or nothing at all. Under both the current rule and the proposal, the covered entity is responsible for choosing vendors that safeguard the data, and the proposal adds an annual written check that they actually do. A practice adding an AI front desk or automated reminders is adding a business associate, and the question to ask before the pilot is not whether the vendor is HIPAA compliant, a phrase with no legal meaning, but whether they will sign the agreement, where the recordings live, and how long they keep them.

The second mistake is doing the risk analysis last, as a document to have. The proposal wants it first, written, with specific elements, and refreshed yearly. Done from the inventory in step 1, it is an afternoon. Done from memory, it is the finding in the audit.

What the delay is for

A rule targeted for July 2027 will, if it holds, apply in 2028 to practices whose inventories, authentication, encryption and backups were built years earlier. The proposal is the clearest statement HHS has yet published of what it will expect, and the practice that works through the six steps above this quarter meets the current rule better, meets the proposed one in advance, and stops being the easy target the breach numbers describe. Start with the inventory. It is one spreadsheet, and every other step is a column in it.

Sources

  1. HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information, fact sheet (2025)
  2. Federal Register, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule, 90 FR 898) (2025)
  3. HIPAA Journal, Healthcare Data Breach Statistics (2026)
  4. HIPAA Journal, The Impact of Proposed Changes to the HIPAA Security Rule for Business Associates (2026)
  5. BDO, Proposed HIPAA Security Rule Updates (2025)

Questions people ask

Has the new HIPAA Security Rule been finalized?

No. HHS published the proposed rule in the Federal Register on January 6, 2025 and closed comments on March 7, 2025. A final rule had been expected as early as May 2026, but the Office of Management and Budget's regulatory agenda now lists July 2027, according to HIPAA Journal's reporting in 2026. Until a final rule takes effect, the existing Security Rule applies unchanged.

What does the proposed HIPAA Security Rule require?

The proposal removes the distinction between required and addressable specifications, so every safeguard is required. It adds multifactor authentication, encryption of electronic protected health information at rest and in transit, a written technology asset inventory and network map, vulnerability scans at least every six months, penetration tests at least every twelve months, restoration of critical systems within 72 hours of an outage, notice within 24 hours when a workforce member's access changes or ends, an annual compliance audit, and written verification of business associates' safeguards every twelve months.

Does HIPAA apply to small medical and dental practices?

Yes, in full. Any provider that transmits health information electronically for a standard transaction such as a claim is a covered entity, whatever its size. HIPAA Journal's analysis of OCR enforcement found that in 2022, 55% of the financial penalties imposed were on small medical practices. The proposed rule contains no small-practice exemption, and neither does the current one.

Mir, Founder, Analytica Solutions

What we build for healthcare

Talk to us

If this is the problem on your desk, tell us about it. No pitch, no deck.

Talk to us