954-539-5678Free audit
Menu

Cybersecurity · Healthcare

HIPAA IT requirements, translated for a small practice

What the Security Rule asks of your IT today, where the proposed update stands as of 2026, and the steps that matter most. General information, not legal advice.

Security Rule safeguards in plain English

Proposed 2025 update status explained

An 11-step practice checklist

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

The HIPAA Security Rule requires a medical practice to protect electronic patient information (ePHI) with three kinds of safeguards: administrative, physical and technical. In IT terms, that means a documented risk analysis, controlled and logged access to systems, protection of devices and data, backups with a tested recovery plan, staff training and signed business associate agreements with vendors that handle ePHI.

As of October 2026, the major Security Rule update HHS proposed in January 2025 is still a proposal, not law. The current rule is the one being enforced. This article is general information, not legal advice; confirm your obligations with your compliance advisor or counsel.

Where the 2025 Security Rule update stands

HHS published a proposed rule to strengthen the Security Rule in the Federal Register on January 6, 2025, and the comment period closed in March 2025. As of October 2026 no final rule has been published. The federal regulatory agenda entry for the rule (RIN 0945-AA22) lists it under long-term actions, with final action shown for July 2027. Agenda dates are targets, not commitments, and HHS could act earlier or later.

Among other changes, the proposal would:

  • Remove the distinction between “required” and “addressable” specifications, making most of them mandatory with limited exceptions.
  • Require a written inventory of technology assets and a network map, kept current.
  • Require encryption of ePHI at rest and in transit and multifactor authentication, with limited exceptions.
  • Require vulnerability scanning at least every six months and penetration testing at least once a year.
  • Require written procedures to restore critical systems and data within 72 hours.
  • Require a compliance audit at least once a year and yearly written verification from business associates.

None of that is law yet. But most of it is already good practice, and much of it is how OCR and cyber insurers judge a practice today. Working toward it now is sensible.

Start with the risk analysis

The risk analysis is the foundation of the Security Rule and the most common finding in enforcement. OCR’s Risk Analysis Initiative, which began in 2024, has produced a steady stream of settlements through 2026, and the recurring issue is a missing, outdated or incomplete risk analysis.

A real risk analysis:

  • Covers every place ePHI is created, received, stored or sent: the EHR, email, laptops, phones, scanners, backups, patient portals, billing services and cloud storage.
  • Identifies threats and weaknesses for each, rates likelihood and impact, and records what you already do about them.
  • Leads to a written risk management plan with owners and dates.
  • Is repeated when things change, such as a new EHR, a new office or a security incident, and reviewed at least yearly.

Small practices can use the free Security Risk Assessment Tool from HHS and ONC as a structure. The tool is a guide; the analysis still has to reflect your actual systems.

Administrative safeguards in IT terms

  • Security management process: risk analysis, risk management, a sanctions policy and regular review of system activity such as sign-in and audit logs.
  • Assigned security responsibility: one named person is the security official. It can be the practice manager, supported by an IT provider.
  • Workforce security and access management: people get only the access their job needs, and leavers lose access promptly.
  • Security awareness and training: phishing training, password and MFA guidance, and protection from malicious software.
  • Security incident procedures: how staff report a problem and how you respond and document it.
  • Contingency plan: data backup, disaster recovery, emergency mode operations, and testing of those plans.
  • Evaluation: periodic checks that your safeguards still work.
  • Business associate agreements: signed with every vendor that handles ePHI for you.

Physical safeguards

  • Facility access: lock the server or network closet, control who has keys and codes, and keep a visitor log where appropriate.
  • Workstation use and security: screens that face away from patients, automatic screen lock, and no shared logins at the front desk.
  • Device and media controls: an inventory of laptops, drives and devices that hold ePHI, and secure wiping or destruction when they are retired or reused.

Technical safeguards

  • Access control: unique user IDs for everyone, emergency access procedures, automatic logoff and encryption where reasonable. Encrypted laptops are also a practical safe harbor under the breach notification rule if one is lost.
  • Audit controls: the EHR, Microsoft 365 or Google Workspace, and servers record who accessed what, and someone reviews those logs.
  • Integrity: protection against improper changes or deletion of records, including backups that ransomware cannot reach.
  • Person or entity authentication: confirm users are who they say they are. In 2026 that means MFA on email, the EHR and remote access.
  • Transmission security: encrypted email for ePHI, secure portals and no patient data over plain text or personal email.

Want to know where your practice stands?

Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating cybersecurity, IT operations and business continuity as controlled, needs attention, significant exposure or unknown, with next steps in order. It does not replace a HIPAA risk analysis, but it shows where to focus. No obligation. Book your free assessment.

Required vs addressable today

Under the current rule, some specifications are “required” and others “addressable.” Addressable does not mean optional. It means you must implement it if it is reasonable and appropriate for your practice, use an equivalent alternative, or document why neither is reasonable. Encryption is addressable today, but a practice that does not encrypt laptops and cannot show a documented reason is in a weak position after a loss or theft.

Vendors and business associate agreements

HHS guidance on cloud computing makes clear that a cloud provider storing ePHI for you, even in encrypted form, is a business associate. Get a signed agreement from each of these, where they apply:

  • Your EHR and practice management vendor.
  • Microsoft 365 or Google Workspace. Both offer agreements for eligible services, but you must accept them and use only covered services.
  • Backup, email security, encrypted email and phone or fax providers.
  • Your IT provider, if they can access systems holding ePHI.
  • Billing, transcription and answering services.

An agreement covers the vendor’s responsibilities. Your configuration, such as MFA, sharing settings and retention, remains your responsibility.

A practical checklist for a small practice

  1. Complete or update your written risk analysis and risk management plan.
  2. Name your security official and write down your core policies.
  3. Turn on MFA for email, the EHR and remote access.
  4. Encrypt every laptop and mobile device that can reach ePHI, and enroll them in device management.
  5. Keep systems patched and protected with endpoint security.
  6. Back up ePHI to a copy ransomware cannot reach, and test a full restore.
  7. Write a recovery plan with who does what, and test it once a year.
  8. Review user access quarterly and remove leavers the same day.
  9. Train staff on phishing at least yearly and document it.
  10. Collect business associate agreements and keep a vendor list.
  11. Keep a technology asset inventory and network map, as the proposed rule would require.

HHS’s 405(d) program publishes “Health Industry Cybersecurity Practices,” which includes guidance sized for small practices. OCR is required by law to consider recognized security practices like these, in place for the prior 12 months, when it decides fines and audit outcomes.

How JLB USA fits in

JLB USA is not a law firm and does not certify HIPAA compliance, and HHS does not endorse or recognize private HIPAA certifications. What we do is the IT work behind the safeguards: MFA, access reviews, same-day removal of leavers, endpoint protection, updates, encryption, email security, monitored backups with tested restores and a written recovery plan, through our cybersecurity and managed IT services for practices with roughly 25 to 100 people. We can work alongside your compliance advisor. Call 954-539-5678 or start with the free assessment.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

Is the new HIPAA Security Rule in effect?

No. As of October 2026 the January 2025 proposal has not been finalized. The federal regulatory agenda lists final action for July 2027, but that is a target. The current Security Rule remains in force.

What is the most important HIPAA IT requirement?

The risk analysis. It is required, it drives every other safeguard, and a missing or incomplete one is the most common finding in OCR enforcement.

Is encryption required under HIPAA?

Under the current rule, encryption is addressable, which means you must use it where reasonable and appropriate or document an equivalent alternative or reason. The proposed update would make it required with limited exceptions.

Do we need a business associate agreement with Microsoft or Google?

If you store or send ePHI using Microsoft 365 or Google Workspace, yes. Both offer agreements for eligible services. You must also configure those services securely.

Is there an official HIPAA certification for IT providers?

No. HHS states that it does not endorse or recognize private organizations’ Security Rule certifications, and such certifications do not relieve a practice of its obligations. Ask providers what safeguards they implement and whether they will sign a business associate agreement, and confirm requirements with your counsel.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678