As of mid-2026, the rule remains proposed. OCR is still reviewing approximately 4,745 public comments. A final rule has not been issued, and the compliance timeline has slipped. But the direction is clear, and the underlying threats haven’t waited for regulatory certainty.
This guide is for practice managers, medical directors, and clinic administrators who want to be ready when the rule finalizes, without wasting time or budget on requirements that could still change. Every recommendation here reflects controls that experienced clinics should have in place regardless of finalization timing, because the current threat environment already demands them.
A note on regulatory status: The current HIPAA Security Rule remains in force and enforceable. OCR continues to investigate breaches, and risk analysis remains the most frequently cited deficiency in OCR enforcement actions. Nothing in this guide replaces existing HIPAA obligations. It supplements them with a forward-looking view of where compliance is heading.
Table of Contents
TogglePart 1: What Is Actually Changing
Nine substantive changes anchor the proposed rule. Each is drawn from the NPRM published in the Federal Register (source: HHS OCR NPRM, December 27, 2024).
Change 1: All Safeguards Become Required
The proposed rule eliminates the “addressable” versus “required” distinction. Every implementation specification becomes required, with limited exceptions.
What this means: Clinics can no longer document why an encryption or MFA control is “not reasonable and appropriate” and skip it. Every safeguard must be implemented, or an approved compensating control must be documented.
Change 2: Written Technology Asset Inventory and Network Map
Every clinic must maintain a current written inventory of all technology assets that create, receive, maintain, or transmit ePHI, plus a network map showing how ePHI moves through those systems. Both must be reviewed at least every 12 months and after any material change.
What this means: The “spreadsheet of laptops” approach doesn’t meet the standard. The inventory must include servers, workstations, laptops, mobile devices, cloud services, EHR platforms, patient portals, telehealth systems, backup systems, and every SaaS tool your team uses.
Change 3: Annual Comprehensive Security Risk Analysis
The proposed rule requires a documented, technical, and thorough risk analysis at least every 12 months, plus after any environmental change.
What this means: A three-year-old risk analysis with checkbox updates won’t meet the standard. Each annual analysis must reflect current systems, current vendors, current workforce, and current threats.
Change 4: Mandatory Encryption at Rest and in Transit
ePHI must be encrypted everywhere it lives and everywhere it travels. Servers, databases, laptops, workstations, portable devices, backup media, email systems, cloud storage, messaging platforms.
What this means: Legacy systems that don’t support encryption must be replaced, isolated, or covered by documented compensating controls. This is one of the biggest lifts for older clinics.
Change 5: Mandatory Multi-Factor Authentication
MFA is required for all systems accessing ePHI, with limited exceptions for certain FDA-approved medical devices.
What this means: Every account that touches ePHI needs MFA. This includes EHR access, email accounts, cloud storage, VPNs, remote desktop, and administrative accounts. Password-only access no longer meets the standard.
Change 6: Vulnerability Scanning and Penetration Testing
The proposed rule requires vulnerability scanning at least every 6 months and penetration testing at least every 12 months.
What this means: Passive security postures are out. Clinics must actively test their defenses, identify gaps, and remediate them. This is a significant new operational commitment for most small practices.
Change 7: Contingency Plan Timelines
The proposed rule sets hard timelines: 24 hours for contingency plan activation notification, 72 hours for data restoration.
What this means: Untested backups don’t count. The clinic must be able to prove, through documented testing, that critical systems can be restored within 72 hours.
Change 8: Enhanced Workforce Controls
Access to ePHI must be terminated within one hour of a workforce member’s separation. Role-based access controls must be documented and reviewed. Security training becomes annual, and content must cover current threats.
What this means: Automated deprovisioning is now essential. The 30-day “we’ll get to it when we can” window is closing.
Change 9: Annual Business Associate Verification
Business associates must provide written annual verification that they have deployed the required technical safeguards. Covered entities must verify this documentation, not just keep the BAA on file.
What this means: Every vendor with ePHI access must be actively verified once a year. The clinic is responsible for chasing that documentation and reviewing it.
Part 2: The Full Technical Safeguard Checklist
This checklist consolidates what a compliant clinic looks like under the proposed rule. Use it as an audit tool.
Access Controls
☐ Unique user identification is assigned to every workforce member
☐ Automatic logoff is configured on all workstations and mobile devices (typical: 10-15 minutes)
☐ Role-based access controls (RBAC) are documented, with each role defined and access mapped to that role
☐ Access reviews occur at least quarterly for administrative accounts, annually for all others
☐ Workforce separation triggers access termination within one hour, verified through automated workflow
☐ Emergency access procedures are documented and tested annually
☐ Session timeout on ePHI systems is 15 minutes or less for inactive sessions
Authentication
☐ Multi-factor authentication is enabled on all accounts accessing ePHI
☐ MFA is enforced on: EHR, email, cloud storage, VPN, remote desktop, administrative accounts, patient portal admin, telehealth platforms, financial systems
☐ Password policy requires minimum 12 characters, complexity, and rotation on compromise (not fixed intervals per current NIST guidance)
☐ Password managers are approved and deployed for workforce use
☐ Service accounts and shared accounts are eliminated or documented with strict access controls
☐ Legacy systems that cannot support MFA are inventoried with documented compensating controls or migration timelines
Encryption
☐ Full disk encryption is enabled on all laptops and workstations (BitLocker, FileVault, or equivalent)
☐ Mobile devices accessing ePHI use encryption and are enrolled in mobile device management (MDM)
☐ Email encryption is enforced for any communication containing ePHI (encrypted portal, secure email, or gateway-level encryption)
☐ Cloud storage services are configured with encryption at rest and in transit
☐ Backup media (physical or cloud) is encrypted
☐ Database-level encryption is enabled on any database storing ePHI
☐ TLS 1.2 or higher is enforced for all data in transit
☐ Encryption keys are managed through a documented key management process
Network Security
☐ Network segmentation isolates ePHI systems from general office networks
☐ Guest Wi-Fi is on a separate VLAN with no access to internal systems
☐ Firewall rules are documented, reviewed at least annually, and follow least-privilege principles
☐ Remote access uses VPN with MFA, no direct RDP or unmanaged remote tools
☐ Unnecessary network ports and services are disabled per documented risk analysis
☐ IoT and medical devices are on a segmented network with monitored access
☐ DNS filtering blocks known malicious domains
Endpoint and Malware Protection
☐ Endpoint detection and response (EDR) is deployed on every workstation, laptop, and server (SentinelOne, CrowdStrike, or equivalent)
☐ Anti-malware protection covers email, web, and endpoint layers
☐ Patch management applies critical updates within 15 days and high-priority updates within 30 days
☐ Software inventory is maintained and unauthorized software is prevented or flagged
☐ USB and removable media policies are documented and technically enforced
Audit and Logging
☐ Audit logs are enabled on all systems accessing ePHI
☐ Logs capture: user access, file access, changes to permissions, authentication attempts, administrative actions
☐ Logs are stored for at least 6 years (HIPAA minimum) in a tamper-resistant location
☐ Logs are reviewed at least monthly, with high-priority alerts reviewed daily
☐ A security information and event management (SIEM) tool or equivalent aggregates logs from all critical systems
Vulnerability Management
☐ Vulnerability scanning runs at least every 6 months (proposed: quarterly is stronger)
☐ Penetration testing occurs at least every 12 months by a qualified third party
☐ Findings are prioritized, remediated on a documented timeline, and retested
☐ Vulnerability management includes third-party components (SaaS, plugins, integrations)
Backup and Recovery
☐ Backups run on a documented schedule (daily minimum for critical systems)
☐ Backups are encrypted, tested at least quarterly, and stored with at least one offsite/immutable copy
☐ Recovery time objective (RTO) for critical systems is documented and tested
☐ 72-hour restoration capability is verified through actual restore tests, not tabletop exercises
☐ Ransomware-resistant backup architecture is in place (air-gapped, immutable, or equivalent)
Incident Response
☐ Written incident response plan exists and covers detection, containment, eradication, recovery, and lessons learned
☐ Incident response plan is tested at least annually with documented results
☐ Incident notification procedures are documented, including 24-hour business associate notification and 60-day patient notification
☐ Contact information for legal counsel, cyber insurance, forensics, and regulators is kept current
☐ A designated incident response lead is named, with backup
Workforce and Training
☐ Security awareness training is delivered at hire and annually thereafter
☐ Training covers: current phishing tactics, password hygiene, safe email practices, physical security, incident reporting
☐ Phishing simulations run at least quarterly
☐ Training completion is documented and stored for at least 6 years
☐ Sanction policy for security violations is documented and consistently applied
Vendor and Business Associate Management
☐ Complete inventory of all business associates and third-party vendors with ePHI access
☐ Signed BAA on file for every business associate
☐ Annual written verification requested from each business associate confirming technical safeguards
☐ Vendor risk assessments completed at onboarding and reviewed annually
☐ Termination process defined for vendors that fail to meet security standards
Documentation
☐ All policies, procedures, and plans are in writing
☐ Documents are reviewed and updated at least annually
☐ Retention period of at least 6 years for all security documentation
☐ Version control and change history are maintained
☐ Documentation is accessible to workforce and OCR upon request
Part 3: Sample Documentation Templates
Below are the core documents every clinic should maintain. Each template outlines the minimum content structure. Fill in specifics based on your clinic’s environment.
Template 1: Technology Asset Inventory
| Asset ID | Asset Name | Asset Type | Owner | Location | ePHI Access | Encryption Status | MFA Status | Last Updated |
| 001 | EHR Server (Primary) | Physical Server | Practice Admin | On-premises server room | Yes – Full | AES-256 at rest, TLS 1.3 in transit | Yes | [Date] |
| 002 | Practice Manager Laptop | Endpoint | Jane Smith | Portable | Yes – Read/Write | BitLocker enabled | Yes (Microsoft Authenticator) | [Date] |
| 003 | Patient Portal | Cloud SaaS | Vendor Contact | Cloud-hosted | Yes – Full | Vendor confirmed AES-256 | Yes | [Date] |
| 004 | Backup System | Cloud Backup | IT Vendor | Cloud (encrypted) | Yes – Full copy | Immutable, AES-256 | Yes | [Date] |
| 005 | Front Desk Workstation | Endpoint | Front Desk Team | Reception area | Yes – Read/Write | BitLocker enabled | Yes | [Date] |
Review cadence: At least every 12 months and after any material change (new system, vendor change, workforce change, EHR upgrade).
Template 2: Network Map (Simplified)
A network map should visually show:
Layer 1: External connections
- Internet gateway → Firewall → Internal network
- Remote access → VPN → Internal network
Layer 2: Segmented networks
- Clinical VLAN (EHR servers, clinical workstations)
- Administrative VLAN (billing, front desk, admin systems)
- Guest VLAN (patient Wi-Fi, isolated)
- IoT VLAN (medical devices, printers, isolated)
Layer 3: ePHI flow arrows
- EHR → Workstation → User
- EHR → Backup System
- EHR → Patient Portal (cloud)
- Email → Encrypted Gateway → Recipient
A diagram tool (Lucidchart, Draw.io, or Visio) works. Update annually and after any material change.
Template 3: Security Risk Analysis (Structure)
Section 1: Scope
- Systems in scope
- Time period covered
- Assessment methodology
- Team conducting the analysis
Section 2: Asset Inventory Reference
- Link to current technology asset inventory
- Confirmation that inventory is current as of assessment date
Section 3: Threat Identification
- External threats (ransomware, phishing, insider threats, supply chain)
- Internal threats (misuse, error, workforce turnover)
- Environmental threats (natural disaster, power failure, hardware failure)
- Emerging threats (AI-generated attacks, deepfakes, LLM prompt injection)
Section 4: Vulnerability Assessment
- Technical vulnerabilities (unpatched systems, weak configurations, missing MFA)
- Administrative vulnerabilities (missing policies, insufficient training)
- Physical vulnerabilities (unlocked areas, unattended workstations)
Section 5: Risk Determination
- For each threat/vulnerability pairing: likelihood × impact = risk level
- Prioritized risk register with high, medium, low ratings
Section 6: Existing Safeguards
- Documented list of current controls
- Effectiveness assessment of each control
Section 7: Recommendations
- Specific remediation actions
- Assigned owner
- Target completion date
- Verification method
Section 8: Sign-off
- Assessment lead signature and date
- Practice manager signature and date
- Next scheduled assessment date
Template 4: Incident Response Plan (Structure)
Section 1: Purpose and Scope
- What this plan covers
- Who this plan applies to
Section 2: Incident Response Team
- Incident Response Lead (name, contact, backup)
- Communications Lead
- Technical Lead
- Legal/Compliance Lead
- Executive Sponsor
Section 3: Incident Classification
- Category 1: Confirmed breach affecting ePHI
- Category 2: Suspected breach, under investigation
- Category 3: Security event without confirmed data exposure
- Category 4: Operational incident, no ePHI risk
Section 4: Response Phases
- Detection: How incidents are identified (alerts, user reports, EDR triggers)
- Containment: Immediate isolation steps
- Eradication: Removing the threat
- Recovery: Restoring operations
- Lessons Learned: Post-incident review
Section 5: Notification Requirements
- Business associates: within 24 hours of contingency plan activation
- Patients: within 60 days of breach discovery
- HHS OCR: within 60 days for breaches affecting 500+ individuals; annual for smaller breaches
- Cyber insurance carrier: within timeframe specified in policy
- Law enforcement: as directed by legal counsel
Section 6: Contact Directory
- Legal counsel (name, phone, email)
- Cyber insurance carrier (policy number, claim phone)
- Forensic response vendor
- Managed IT/security partner
- HHS OCR breach notification portal link
- Local FBI field office
Section 7: Testing
- Annual tabletop exercise (all team roles participate)
- Semi-annual technical restore test
- Documentation of test results
Template 5: Business Associate Annual Verification Request
To: [Business Associate Name]
From: [Clinic Name]
Date: [Date]
Subject: Annual HIPAA Technical Safeguards Verification
Under our Business Associate Agreement dated [Date], and consistent with our HIPAA compliance obligations, we request your written verification that you have implemented the following technical safeguards for ePHI in your possession:
- Encryption at Rest: Please confirm ePHI is encrypted at rest using industry-standard encryption (AES-256 or equivalent).
- Encryption in Transit: Please confirm ePHI is encrypted in transit using TLS 1.2 or higher.
- Multi-Factor Authentication: Please confirm MFA is required for all workforce access to systems containing our organization’s ePHI.
- Access Controls: Please confirm role-based access controls are documented and reviewed.
- Audit Logging: Please confirm audit logs are captured, retained for at least 6 years, and reviewed regularly.
- Vulnerability Management: Please confirm vulnerability scanning is performed at least every 6 months and penetration testing at least annually.
- Incident Response: Please confirm you maintain a written incident response plan and will notify us within 24 hours of activating contingency procedures.
- Subcontractor Management: Please confirm any subcontractors with access to our ePHI have signed BAAs and meet these same standards.
Please return this verification, signed by an authorized representative, within 30 days.
Signed: ____________________
Name: _____________________
Title: ______________________
Company: __________________
Date: ______________________
Part 4: The 90-Day Compliance Readiness Roadmap
This roadmap gives clinics a realistic path from where they are today to substantially prepared for the proposed rule. It assumes a starting point of “current HIPAA compliance in place, but not yet ready for the proposed changes.”
Days 1-30: Assessment and Baseline
Week 1: Scope and Team
- Assign an internal HIPAA compliance owner (usually practice manager or COO)
- Engage a HIPAA-experienced IT partner if not already in place
- Document current state: who owns HIPAA compliance today, what documentation exists, when was the last risk analysis
- Communicate the 90-day plan to leadership and clinical staff
Week 2: Asset Inventory Build
- Inventory every device, application, cloud service, and vendor that touches ePHI
- Categorize each by asset type, owner, ePHI access level, encryption status, MFA status
- Identify obvious gaps (unencrypted laptops, systems without MFA, unmanaged devices)
Week 3: Network Map Development
- Diagram how ePHI moves through your systems
- Identify segmentation gaps (is the guest Wi-Fi truly isolated? Are medical devices segmented from admin systems?)
- Document remote access paths and confirm all use VPN + MFA
Week 4: Baseline Risk Analysis
- Conduct a documented risk analysis using the template above
- Identify the top 10 risks by likelihood × impact
- Draft the initial remediation plan
End of Month 1 deliverables:
- Complete asset inventory
- Draft network map
- Documented risk analysis
- Prioritized 10-item remediation list
Days 31-60: High-Impact Technical Controls
Week 5-6: MFA Deployment
- Enable MFA on EHR access, email, cloud storage, VPN, remote desktop, administrative accounts
- Deploy MFA app (Microsoft Authenticator or equivalent) to all workforce members
- Document any legacy systems that cannot support MFA and implement compensating controls
- Train workforce on MFA setup and troubleshooting
Week 7: Encryption Rollout
- Enable full-disk encryption (BitLocker or FileVault) on all laptops and workstations
- Verify EHR and backup encryption at rest and in transit
- Enable email encryption for outbound messages containing ePHI
- Enroll mobile devices in mobile device management (MDM) with encryption enforced
Week 8: EDR and Network Hardening
- Deploy endpoint detection and response (EDR) to every endpoint if not already in place
- Review firewall rules and disable unnecessary services and ports
- Segment guest Wi-Fi, IoT devices, and medical devices from clinical networks
- Enforce TLS 1.2+ on all systems and disable outdated protocols
End of Month 2 deliverables:
- MFA deployed and verified across all in-scope systems
- Full-disk encryption confirmed on every endpoint
- EDR deployed and monitored
- Network segmentation validated
Days 61-90: Documentation, Testing, and Vendor Verification
Week 9: Incident Response Plan
- Draft or update the written incident response plan using the template above
- Populate the contact directory with current legal, insurance, and vendor contacts
- Schedule an annual tabletop exercise for Month 4
Week 10: Vulnerability Scan and Baseline Penetration Test
- Run an internal vulnerability scan across all in-scope systems
- Engage a qualified third party for a baseline penetration test (this is a real budget item, typically $5,000-$15,000 for a small clinic)
- Prioritize findings and set 90-day remediation targets
Week 11: Business Associate Verification
- Send the annual verification request to every business associate on file
- Track responses and follow up on non-responsive vendors
- For vendors that cannot verify, document the risk and plan mitigation or replacement
Week 12: Workforce Training and Documentation Consolidation
- Deliver refreshed HIPAA security awareness training to all workforce members
- Run a phishing simulation and document results
- Consolidate all documentation (inventory, network map, risk analysis, IR plan, vendor verifications, training records) in a single secure location
- Schedule the next quarterly review
End of Month 3 deliverables:
- Written incident response plan, ready for annual tabletop
- Completed vulnerability scan and penetration test with remediation plan
- Business associate verifications collected or documented gaps
- Refreshed workforce training with completion records
- Consolidated documentation binder (digital or physical)
Part 5: Common Pitfalls and How to Avoid Them
Pitfall 1: Trying to do everything at once.
The proposed rule covers a lot of ground. Clinics that attempt full simultaneous implementation typically burn out staff and produce incomplete work. Follow the 90-day sequencing above. Start with the risk analysis. Then MFA and encryption. Then testing and documentation. Sequenced execution beats aspirational overhaul.
Pitfall 2: Treating the risk analysis as a checkbox.
The most frequently cited OCR deficiency is risk analysis, not the absence of technical controls. A generic template downloaded from the internet, filled with vague statements, will not withstand OCR scrutiny. The risk analysis must reflect your actual environment, your actual vendors, and your actual threats.
Pitfall 3: Assuming your EHR vendor handles HIPAA for you.
EHR vendors are business associates. They handle their own compliance. Your clinic is still responsible for how ePHI is accessed, stored, and transmitted at your location, on your devices, and by your workforce. The EHR being HIPAA-compliant does not make the clinic HIPAA-compliant.
Pitfall 4: Waiting for the final rule.
Some clinics are waiting to see what OCR finalizes. This is risky for two reasons. First, most of the proposed changes are already best practices that OCR enforces under the current rule via risk analysis and reasonable security requirements. Second, when the final rule drops, the implementation window is 180 days. Six months is not enough time to build asset inventories, deploy MFA and encryption, complete a penetration test, and verify every business associate from a cold start.
Pitfall 5: Underestimating the cost of legacy systems.
Older EHRs, imaging systems, and specialty devices often cannot support MFA or modern encryption. These will require either replacement, network isolation, or documented compensating controls. Budget accordingly. HHS estimates first-year industry compliance cost at approximately $9 billion (source: HHS regulatory impact analysis).
Pitfall 6: Skipping the testing.
Backup systems that have never been restored may not actually work. Incident response plans that have never been tested will fail under real pressure. The proposed rule requires actual testing, not just documented procedures. Build testing into your operational calendar.
Part 6: What SecTec Provides
SecTec provides AI-driven managed IT and cybersecurity built for medical clinics, healthcare providers, and organizations under 200 staff. Our HIPAA compliance service maps directly to the proposed rule requirements, covering:
- End-to-end Security Risk Analysis with documentation
- Asset inventory and network map development
- MFA deployment across all in-scope systems
- Encryption at rest and in transit
- EDR deployment (SentinelOne) and 24/7 monitoring
- Vulnerability scanning and penetration testing coordination
- Incident response planning and tabletop exercise facilitation
- Business associate agreement management and annual verification
- Workforce security awareness training (KnowBe4)
- Documentation, audit preparation, and OCR response support
Every engagement starts with a free cybersecurity risk assessment. Three weeks. Prioritized findings. Zero obligation.
Book your free assessment | Learn more about our HIPAA compliance service
Regulatory Status Disclaimer
This guide is based on the HIPAA Security Rule Notice of Proposed Rulemaking (NPRM) published by HHS Office for Civil Rights on December 27, 2024, and formally published in the Federal Register on January 6, 2025. As of mid-2026, this rule remains proposed. OCR has not issued a final rule, and the requirements described here could be modified, delayed, or withdrawn.
The current HIPAA Security Rule remains in force and enforceable. This guide is intended to help clinics prepare for the direction of the industry, not to describe currently binding law. Consult qualified legal counsel for advice specific to your practice.
Sources:
- HHS OCR HIPAA Security Rule NPRM (December 27, 2024)
- Federal Register: HIPAA Security Rule to Strengthen Cybersecurity of ePHI (January 6, 2025)
- HHS OCR Fact Sheet on the NPRM (December 2024)
- HIPAA Journal ongoing coverage (2025-2026)
Prepared by SecTec. AI-Driven IT & Cybersecurity for Modern Businesses. SecTec provides managed IT and cybersecurity services to medical clinics, nonprofits, law firms, and mission-driven organizations across the United States. Recognized as an Industry Expert in IT and Cybersecurity by the Center for Nonprofit Advancement.


