Skip to content

Knowledge That
Protects Your Business

What Healthcare Organizations Need to Know About the 2026 HIPAA Security Rule Updates

The HIPAA Security Rule is undergoing its first major overhaul since 2013. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking in January 2025, with a final rule anticipated in mid-2026. For healthcare organizations and their business associates, the window to prepare is open now.

The proposed changes are a direct response to record-breaking data breach volumes across the healthcare sector. They shift the framework from flexible guidance to strict, mandatory requirements. Here is what your organization needs to understand.

The “Addressable” Loophole Is Gone

Under the current Security Rule, implementation specifications are divided into “required” and “addressable” categories. That distinction has caused widespread confusion. Many covered entities interpreted “addressable” as optional.

The proposed rule eliminates this two-tier structure entirely. Every specification in the updated HIPAA Security Rule will be mandatory. Organization size and unique circumstances will no longer provide a workaround. Compliance is compliance.

Encryption Becomes Non-Negotiable

Encryption of all electronic protected health information (ePHI) will be required, both at rest and in transit. This applies to databases, file systems, backups, external network transmissions, and all other data pathways.

For many organizations, the challenge will center on legacy systems. Healthcare environments frequently rely on older platforms and devices that may not support modern encryption standards. Identifying those gaps now and building a remediation plan is a critical first step.

Multi-Factor Authentication Is Required Everywhere

Multi-factor authentication (MFA) will be mandatory for all systems that access ePHI. This requirement applies to internal staff, administrators, and external partners alike. Vendor limitations or third-party software constraints will not be acceptable as reasons for non-compliance. If a vendor cannot support MFA, that vendor relationship will need to be re-evaluated.

New Testing and Monitoring Requirements

The proposed rule establishes specific, enforceable timelines for security testing activities:

  • Vulnerability scans: at least every six months
  • Penetration testing: at least every 12 months
  • Security measure reviews and tests: at least every 12 months
  • Security Rule compliance audits: at least every 12 months

Organizations must also develop and maintain a comprehensive technology asset inventory and a network map illustrating ePHI data flows. Both must be updated at least annually. This is not a documentation exercise. It is the foundation for every other security decision an organization makes.

Faster Patch Management and Incident Response

The updated rule introduces concrete timelines for patching and incident response that organizations must build into their operations:

  • Critical vulnerabilities must be patched within 15 days
  • High-risk vulnerabilities must be addressed within 30 days
  • Business associates must notify covered entities within 24 hours of activating a contingency plan
  • Written data restoration procedures must define recovery priorities, with a 72-hour restoration target

Business Associate Oversight Gets Stronger

Covered entities will be required to verify, at least every 12 months, that their business associates and contractors have adequate security measures in place. A signed agreement will no longer be sufficient. Organizations need documented, verified evidence that their partners are meeting the same security standards.

Additional Technical Controls Now Required

Beyond encryption and MFA, the proposed rule mandates a set of additional technical safeguards that reflect current cybersecurity best practices:

  • Network segmentation to isolate IT and operational technology environments
  • Anti-malware protection on all relevant systems
  • Security controls for mobile devices, tablets, and portable equipment, not just workstations
  • Removal of unnecessary software from electronic information systems
  • Disabling unused network ports based on risk analysis findings

What Organizations Should Do Now

The final rule has not been issued yet, but the direction is clear. Organizations that wait for publication before acting will face a compressed timeline for significant operational change. The time to move is now.

Practical starting points:

  • Conduct a current-state risk analysis against the proposed requirements
  • Inventory all technology assets and map ePHI data flows across your environment
  • Assess legacy systems for encryption and MFA compatibility
  • Review business associate agreements and verify partner security postures
  • Build a patch management process with defined timelines for critical and high-risk vulnerabilities

The 2026 HIPAA Security Rule updates are not a minor tune-up. They represent a fundamental shift in how the federal government expects healthcare organizations to approach cybersecurity. The requirements are rigorous, but they are also achievable for organizations that start preparing now.

Organizations that have already adopted recognized security frameworks and documented security practices will be better positioned, both for compliance and for reduced scrutiny in OCR investigations and audits. Now is the time to close the gaps before the final rule turns the clock on.

We’ve compiled a “cheat sheet” of the aspects that your organization needs to keep abreast of to ensure compliance.

Fill out the form to download the cheat sheet.

Back To Top
Your Cart

Your cart is empty.