Cybersecurity · Healthcare
What the Security Rule asks of your IT today, where the proposed update stands as of 2026, and the steps that matter most. General information, not legal advice.
Security Rule safeguards in plain English
Proposed 2025 update status explained
An 11-step practice checklist
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
The HIPAA Security Rule requires a medical practice to protect electronic patient information (ePHI) with three kinds of safeguards: administrative, physical and technical. In IT terms, that means a documented risk analysis, controlled and logged access to systems, protection of devices and data, backups with a tested recovery plan, staff training and signed business associate agreements with vendors that handle ePHI.
As of October 2026, the major Security Rule update HHS proposed in January 2025 is still a proposal, not law. The current rule is the one being enforced. This article is general information, not legal advice; confirm your obligations with your compliance advisor or counsel.
HHS published a proposed rule to strengthen the Security Rule in the Federal Register on January 6, 2025, and the comment period closed in March 2025. As of October 2026 no final rule has been published. The federal regulatory agenda entry for the rule (RIN 0945-AA22) lists it under long-term actions, with final action shown for July 2027. Agenda dates are targets, not commitments, and HHS could act earlier or later.
Among other changes, the proposal would:
None of that is law yet. But most of it is already good practice, and much of it is how OCR and cyber insurers judge a practice today. Working toward it now is sensible.
The risk analysis is the foundation of the Security Rule and the most common finding in enforcement. OCR’s Risk Analysis Initiative, which began in 2024, has produced a steady stream of settlements through 2026, and the recurring issue is a missing, outdated or incomplete risk analysis.
A real risk analysis:
Small practices can use the free Security Risk Assessment Tool from HHS and ONC as a structure. The tool is a guide; the analysis still has to reflect your actual systems.
Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating cybersecurity, IT operations and business continuity as controlled, needs attention, significant exposure or unknown, with next steps in order. It does not replace a HIPAA risk analysis, but it shows where to focus. No obligation. Book your free assessment.
Under the current rule, some specifications are “required” and others “addressable.” Addressable does not mean optional. It means you must implement it if it is reasonable and appropriate for your practice, use an equivalent alternative, or document why neither is reasonable. Encryption is addressable today, but a practice that does not encrypt laptops and cannot show a documented reason is in a weak position after a loss or theft.
HHS guidance on cloud computing makes clear that a cloud provider storing ePHI for you, even in encrypted form, is a business associate. Get a signed agreement from each of these, where they apply:
An agreement covers the vendor’s responsibilities. Your configuration, such as MFA, sharing settings and retention, remains your responsibility.
HHS’s 405(d) program publishes “Health Industry Cybersecurity Practices,” which includes guidance sized for small practices. OCR is required by law to consider recognized security practices like these, in place for the prior 12 months, when it decides fines and audit outcomes.
JLB USA is not a law firm and does not certify HIPAA compliance, and HHS does not endorse or recognize private HIPAA certifications. What we do is the IT work behind the safeguards: MFA, access reviews, same-day removal of leavers, endpoint protection, updates, encryption, email security, monitored backups with tested restores and a written recovery plan, through our cybersecurity and managed IT services for practices with roughly 25 to 100 people. We can work alongside your compliance advisor. Call 954-539-5678 or start with the free assessment.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
No. As of October 2026 the January 2025 proposal has not been finalized. The federal regulatory agenda lists final action for July 2027, but that is a target. The current Security Rule remains in force.
The risk analysis. It is required, it drives every other safeguard, and a missing or incomplete one is the most common finding in OCR enforcement.
Under the current rule, encryption is addressable, which means you must use it where reasonable and appropriate or document an equivalent alternative or reason. The proposed update would make it required with limited exceptions.
If you store or send ePHI using Microsoft 365 or Google Workspace, yes. Both offer agreements for eligible services. You must also configure those services securely.
No. HHS states that it does not endorse or recognize private organizations’ Security Rule certifications, and such certifications do not relieve a practice of its obligations. Ask providers what safeguards they implement and whether they will sign a business associate agreement, and confirm requirements with your counsel.