The Medical Clinic Guide to the 2026 HIPAA Security Rule Update

HIPAA Security Rule Update
The HIPAA Security Rule is heading for its first major update since 2003. In December 2024, HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) that would fundamentally modernize how medical clinics, healthcare providers, and their business associates protect electronic protected health information (ePHI). 

As of mid-2026, the rule remains proposed. OCR is still reviewing approximately 4,745 public comments. A final rule has not been issued, and the compliance timeline has slipped. But the direction is clear, and the underlying threats haven’t waited for regulatory certainty. 

This guide is for practice managers, medical directors, and clinic administrators who want to be ready when the rule finalizes, without wasting time or budget on requirements that could still change. Every recommendation here reflects controls that experienced clinics should have in place regardless of finalization timing, because the current threat environment already demands them. 

A note on regulatory status: The current HIPAA Security Rule remains in force and enforceable. OCR continues to investigate breaches, and risk analysis remains the most frequently cited deficiency in OCR enforcement actions. Nothing in this guide replaces existing HIPAA obligations. It supplements them with a forward-looking view of where compliance is heading. 

Table of Contents

Part 1: What Is Actually Changing 

Nine substantive changes anchor the proposed rule. Each is drawn from the NPRM published in the Federal Register (source: HHS OCR NPRM, December 27, 2024). 

Change 1: All Safeguards Become Required 

The proposed rule eliminates the “addressable” versus “required” distinction. Every implementation specification becomes required, with limited exceptions. 

What this means: Clinics can no longer document why an encryption or MFA control is “not reasonable and appropriate” and skip it. Every safeguard must be implemented, or an approved compensating control must be documented. 

Change 2: Written Technology Asset Inventory and Network Map 

Every clinic must maintain a current written inventory of all technology assets that create, receive, maintain, or transmit ePHI, plus a network map showing how ePHI moves through those systems. Both must be reviewed at least every 12 months and after any material change. 

What this means: The “spreadsheet of laptops” approach doesn’t meet the standard. The inventory must include servers, workstations, laptops, mobile devices, cloud services, EHR platforms, patient portals, telehealth systems, backup systems, and every SaaS tool your team uses. 

Change 3: Annual Comprehensive Security Risk Analysis 

The proposed rule requires a documented, technical, and thorough risk analysis at least every 12 months, plus after any environmental change. 

What this means: A three-year-old risk analysis with checkbox updates won’t meet the standard. Each annual analysis must reflect current systems, current vendors, current workforce, and current threats. 

Change 4: Mandatory Encryption at Rest and in Transit 

ePHI must be encrypted everywhere it lives and everywhere it travels. Servers, databases, laptops, workstations, portable devices, backup media, email systems, cloud storage, messaging platforms. 

What this means: Legacy systems that don’t support encryption must be replaced, isolated, or covered by documented compensating controls. This is one of the biggest lifts for older clinics. 

Change 5: Mandatory Multi-Factor Authentication 

MFA is required for all systems accessing ePHI, with limited exceptions for certain FDA-approved medical devices. 

What this means: Every account that touches ePHI needs MFA. This includes EHR access, email accounts, cloud storage, VPNs, remote desktop, and administrative accounts. Password-only access no longer meets the standard. 

Change 6: Vulnerability Scanning and Penetration Testing 

The proposed rule requires vulnerability scanning at least every 6 months and penetration testing at least every 12 months. 

What this means: Passive security postures are out. Clinics must actively test their defenses, identify gaps, and remediate them. This is a significant new operational commitment for most small practices. 

Change 7: Contingency Plan Timelines 

The proposed rule sets hard timelines: 24 hours for contingency plan activation notification, 72 hours for data restoration. 

What this means: Untested backups don’t count. The clinic must be able to prove, through documented testing, that critical systems can be restored within 72 hours. 

Change 8: Enhanced Workforce Controls 

Access to ePHI must be terminated within one hour of a workforce member’s separation. Role-based access controls must be documented and reviewed. Security training becomes annual, and content must cover current threats. 

What this means: Automated deprovisioning is now essential. The 30-day “we’ll get to it when we can” window is closing. 

Change 9: Annual Business Associate Verification 

Business associates must provide written annual verification that they have deployed the required technical safeguards. Covered entities must verify this documentation, not just keep the BAA on file. 

What this means: Every vendor with ePHI access must be actively verified once a year. The clinic is responsible for chasing that documentation and reviewing it. 

Part 2: The Full Technical Safeguard Checklist 

This checklist consolidates what a compliant clinic looks like under the proposed rule. Use it as an audit tool. 

Access Controls 

☐ Unique user identification is assigned to every workforce member
☐ Automatic logoff is configured on all workstations and mobile devices (typical: 10-15 minutes)
☐ Role-based access controls (RBAC) are documented, with each role defined and access mapped to that role
☐ Access reviews occur at least quarterly for administrative accounts, annually for all others
☐ Workforce separation triggers access termination within one hour, verified through automated workflow
☐ Emergency access procedures are documented and tested annually
☐ Session timeout on ePHI systems is 15 minutes or less for inactive sessions 

Authentication 

☐ Multi-factor authentication is enabled on all accounts accessing ePHI
☐ MFA is enforced on: EHR, email, cloud storage, VPN, remote desktop, administrative accounts, patient portal admin, telehealth platforms, financial systems
☐ Password policy requires minimum 12 characters, complexity, and rotation on compromise (not fixed intervals per current NIST guidance)
☐ Password managers are approved and deployed for workforce use
☐ Service accounts and shared accounts are eliminated or documented with strict access controls
☐ Legacy systems that cannot support MFA are inventoried with documented compensating controls or migration timelines 

Encryption 

☐ Full disk encryption is enabled on all laptops and workstations (BitLocker, FileVault, or equivalent)
☐ Mobile devices accessing ePHI use encryption and are enrolled in mobile device management (MDM)
☐ Email encryption is enforced for any communication containing ePHI (encrypted portal, secure email, or gateway-level encryption)
☐ Cloud storage services are configured with encryption at rest and in transit
☐ Backup media (physical or cloud) is encrypted
☐ Database-level encryption is enabled on any database storing ePHI
☐ TLS 1.2 or higher is enforced for all data in transit
☐ Encryption keys are managed through a documented key management process 

Network Security 

☐ Network segmentation isolates ePHI systems from general office networks
☐ Guest Wi-Fi is on a separate VLAN with no access to internal systems
☐ Firewall rules are documented, reviewed at least annually, and follow least-privilege principles
☐ Remote access uses VPN with MFA, no direct RDP or unmanaged remote tools
☐ Unnecessary network ports and services are disabled per documented risk analysis
☐ IoT and medical devices are on a segmented network with monitored access
☐ DNS filtering blocks known malicious domains 

Endpoint and Malware Protection 

☐ Endpoint detection and response (EDR) is deployed on every workstation, laptop, and server (SentinelOne, CrowdStrike, or equivalent)
☐ Anti-malware protection covers email, web, and endpoint layers
☐ Patch management applies critical updates within 15 days and high-priority updates within 30 days
☐ Software inventory is maintained and unauthorized software is prevented or flagged
☐ USB and removable media policies are documented and technically enforced 

Audit and Logging 

☐ Audit logs are enabled on all systems accessing ePHI
☐ Logs capture: user access, file access, changes to permissions, authentication attempts, administrative actions
☐ Logs are stored for at least 6 years (HIPAA minimum) in a tamper-resistant location
☐ Logs are reviewed at least monthly, with high-priority alerts reviewed daily
☐ A security information and event management (SIEM) tool or equivalent aggregates logs from all critical systems 

Vulnerability Management 

☐ Vulnerability scanning runs at least every 6 months (proposed: quarterly is stronger)
☐ Penetration testing occurs at least every 12 months by a qualified third party
☐ Findings are prioritized, remediated on a documented timeline, and retested
☐ Vulnerability management includes third-party components (SaaS, plugins, integrations) 

Backup and Recovery 

☐ Backups run on a documented schedule (daily minimum for critical systems)
☐ Backups are encrypted, tested at least quarterly, and stored with at least one offsite/immutable copy
☐ Recovery time objective (RTO) for critical systems is documented and tested
☐ 72-hour restoration capability is verified through actual restore tests, not tabletop exercises
☐ Ransomware-resistant backup architecture is in place (air-gapped, immutable, or equivalent) 

Incident Response 

☐ Written incident response plan exists and covers detection, containment, eradication, recovery, and lessons learned
☐ Incident response plan is tested at least annually with documented results
☐ Incident notification procedures are documented, including 24-hour business associate notification and 60-day patient notification
☐ Contact information for legal counsel, cyber insurance, forensics, and regulators is kept current
☐ A designated incident response lead is named, with backup 

Workforce and Training 

☐ Security awareness training is delivered at hire and annually thereafter
☐ Training covers: current phishing tactics, password hygiene, safe email practices, physical security, incident reporting
☐ Phishing simulations run at least quarterly
☐ Training completion is documented and stored for at least 6 years
☐ Sanction policy for security violations is documented and consistently applied 

Vendor and Business Associate Management 

☐ Complete inventory of all business associates and third-party vendors with ePHI access
☐ Signed BAA on file for every business associate
☐ Annual written verification requested from each business associate confirming technical safeguards
☐ Vendor risk assessments completed at onboarding and reviewed annually
☐ Termination process defined for vendors that fail to meet security standards 

Documentation 

☐ All policies, procedures, and plans are in writing
☐ Documents are reviewed and updated at least annually
☐ Retention period of at least 6 years for all security documentation
☐ Version control and change history are maintained
☐ Documentation is accessible to workforce and OCR upon request 

Part 3: Sample Documentation Templates 

Below are the core documents every clinic should maintain. Each template outlines the minimum content structure. Fill in specifics based on your clinic’s environment. 

Template 1: Technology Asset Inventory 

Asset ID  Asset Name  Asset Type  Owner  Location  ePHI Access  Encryption Status  MFA Status  Last Updated 
001  EHR Server (Primary)  Physical Server  Practice Admin  On-premises server room  Yes – Full  AES-256 at rest, TLS 1.3 in transit  Yes  [Date] 
002  Practice Manager Laptop  Endpoint  Jane Smith  Portable  Yes – Read/Write  BitLocker enabled  Yes (Microsoft Authenticator)  [Date] 
003  Patient Portal  Cloud SaaS  Vendor Contact  Cloud-hosted  Yes – Full  Vendor confirmed AES-256  Yes  [Date] 
004  Backup System  Cloud Backup  IT Vendor  Cloud (encrypted)  Yes – Full copy  Immutable, AES-256  Yes  [Date] 
005  Front Desk Workstation  Endpoint  Front Desk Team  Reception area  Yes – Read/Write  BitLocker enabled  Yes  [Date] 

Review cadence: At least every 12 months and after any material change (new system, vendor change, workforce change, EHR upgrade). 

Template 2: Network Map (Simplified) 

A network map should visually show: 

Layer 1: External connections 

  • Internet gateway → Firewall → Internal network 
  • Remote access → VPN → Internal network 

Layer 2: Segmented networks 

  • Clinical VLAN (EHR servers, clinical workstations) 
  • Administrative VLAN (billing, front desk, admin systems) 
  • Guest VLAN (patient Wi-Fi, isolated) 
  • IoT VLAN (medical devices, printers, isolated) 

Layer 3: ePHI flow arrows 

  • EHR → Workstation → User 
  • EHR → Backup System 
  • EHR → Patient Portal (cloud) 
  • Email → Encrypted Gateway → Recipient 

A diagram tool (Lucidchart, Draw.io, or Visio) works. Update annually and after any material change. 

Template 3: Security Risk Analysis (Structure) 

Section 1: Scope 

  • Systems in scope 
  • Time period covered 
  • Assessment methodology 
  • Team conducting the analysis 

Section 2: Asset Inventory Reference 

  • Link to current technology asset inventory 
  • Confirmation that inventory is current as of assessment date 

Section 3: Threat Identification 

  • External threats (ransomware, phishing, insider threats, supply chain) 
  • Internal threats (misuse, error, workforce turnover) 
  • Environmental threats (natural disaster, power failure, hardware failure) 
  • Emerging threats (AI-generated attacks, deepfakes, LLM prompt injection) 

Section 4: Vulnerability Assessment 

  • Technical vulnerabilities (unpatched systems, weak configurations, missing MFA) 
  • Administrative vulnerabilities (missing policies, insufficient training) 
  • Physical vulnerabilities (unlocked areas, unattended workstations) 

Section 5: Risk Determination 

  • For each threat/vulnerability pairing: likelihood × impact = risk level 
  • Prioritized risk register with high, medium, low ratings 

Section 6: Existing Safeguards 

  • Documented list of current controls 
  • Effectiveness assessment of each control 

Section 7: Recommendations 

  • Specific remediation actions 
  • Assigned owner 
  • Target completion date 
  • Verification method 

Section 8: Sign-off 

  • Assessment lead signature and date 
  • Practice manager signature and date 
  • Next scheduled assessment date 

 

Template 4: Incident Response Plan (Structure) 

Section 1: Purpose and Scope 

  • What this plan covers 
  • Who this plan applies to 

Section 2: Incident Response Team 

  • Incident Response Lead (name, contact, backup) 
  • Communications Lead 
  • Technical Lead 
  • Legal/Compliance Lead 
  • Executive Sponsor 

Section 3: Incident Classification 

  • Category 1: Confirmed breach affecting ePHI 
  • Category 2: Suspected breach, under investigation 
  • Category 3: Security event without confirmed data exposure 
  • Category 4: Operational incident, no ePHI risk 

Section 4: Response Phases 

  • Detection: How incidents are identified (alerts, user reports, EDR triggers) 
  • Containment: Immediate isolation steps 
  • Eradication: Removing the threat 
  • Recovery: Restoring operations 
  • Lessons Learned: Post-incident review 

Section 5: Notification Requirements 

  • Business associates: within 24 hours of contingency plan activation 
  • Patients: within 60 days of breach discovery 
  • HHS OCR: within 60 days for breaches affecting 500+ individuals; annual for smaller breaches 
  • Cyber insurance carrier: within timeframe specified in policy 
  • Law enforcement: as directed by legal counsel 

Section 6: Contact Directory 

  • Legal counsel (name, phone, email) 
  • Cyber insurance carrier (policy number, claim phone) 
  • Forensic response vendor 
  • Managed IT/security partner 
  • HHS OCR breach notification portal link 
  • Local FBI field office 

Section 7: Testing 

  • Annual tabletop exercise (all team roles participate) 
  • Semi-annual technical restore test 
  • Documentation of test results 

 

Template 5: Business Associate Annual Verification Request 

To: [Business Associate Name]
From: [Clinic Name]
Date: [Date]
Subject: Annual HIPAA Technical Safeguards Verification 

Under our Business Associate Agreement dated [Date], and consistent with our HIPAA compliance obligations, we request your written verification that you have implemented the following technical safeguards for ePHI in your possession: 

  1. Encryption at Rest: Please confirm ePHI is encrypted at rest using industry-standard encryption (AES-256 or equivalent). 
  2. Encryption in Transit: Please confirm ePHI is encrypted in transit using TLS 1.2 or higher. 
  3. Multi-Factor Authentication: Please confirm MFA is required for all workforce access to systems containing our organization’s ePHI. 
  4. Access Controls: Please confirm role-based access controls are documented and reviewed. 
  5. Audit Logging: Please confirm audit logs are captured, retained for at least 6 years, and reviewed regularly. 
  6. Vulnerability Management: Please confirm vulnerability scanning is performed at least every 6 months and penetration testing at least annually. 
  7. Incident Response: Please confirm you maintain a written incident response plan and will notify us within 24 hours of activating contingency procedures. 
  8. Subcontractor Management: Please confirm any subcontractors with access to our ePHI have signed BAAs and meet these same standards. 

Please return this verification, signed by an authorized representative, within 30 days. 

Signed: ____________________
Name: _____________________
Title: ______________________
Company: __________________
Date: ______________________ 

Part 4: The 90-Day Compliance Readiness Roadmap 

This roadmap gives clinics a realistic path from where they are today to substantially prepared for the proposed rule. It assumes a starting point of “current HIPAA compliance in place, but not yet ready for the proposed changes.” 

Days 1-30: Assessment and Baseline 

Week 1: Scope and Team 

  • Assign an internal HIPAA compliance owner (usually practice manager or COO) 
  • Engage a HIPAA-experienced IT partner if not already in place 
  • Document current state: who owns HIPAA compliance today, what documentation exists, when was the last risk analysis 
  • Communicate the 90-day plan to leadership and clinical staff 

Week 2: Asset Inventory Build 

  • Inventory every device, application, cloud service, and vendor that touches ePHI 
  • Categorize each by asset type, owner, ePHI access level, encryption status, MFA status 
  • Identify obvious gaps (unencrypted laptops, systems without MFA, unmanaged devices) 

Week 3: Network Map Development 

  • Diagram how ePHI moves through your systems 
  • Identify segmentation gaps (is the guest Wi-Fi truly isolated? Are medical devices segmented from admin systems?) 
  • Document remote access paths and confirm all use VPN + MFA 

Week 4: Baseline Risk Analysis 

  • Conduct a documented risk analysis using the template above 
  • Identify the top 10 risks by likelihood × impact 
  • Draft the initial remediation plan 

End of Month 1 deliverables: 

  • Complete asset inventory 
  • Draft network map 
  • Documented risk analysis 
  • Prioritized 10-item remediation list 

Days 31-60: High-Impact Technical Controls 

Week 5-6: MFA Deployment 

  • Enable MFA on EHR access, email, cloud storage, VPN, remote desktop, administrative accounts 
  • Deploy MFA app (Microsoft Authenticator or equivalent) to all workforce members 
  • Document any legacy systems that cannot support MFA and implement compensating controls 
  • Train workforce on MFA setup and troubleshooting 

Week 7: Encryption Rollout 

  • Enable full-disk encryption (BitLocker or FileVault) on all laptops and workstations 
  • Verify EHR and backup encryption at rest and in transit 
  • Enable email encryption for outbound messages containing ePHI 
  • Enroll mobile devices in mobile device management (MDM) with encryption enforced 

Week 8: EDR and Network Hardening 

  • Deploy endpoint detection and response (EDR) to every endpoint if not already in place 
  • Review firewall rules and disable unnecessary services and ports 
  • Segment guest Wi-Fi, IoT devices, and medical devices from clinical networks 
  • Enforce TLS 1.2+ on all systems and disable outdated protocols 

End of Month 2 deliverables: 

  • MFA deployed and verified across all in-scope systems 
  • Full-disk encryption confirmed on every endpoint 
  • EDR deployed and monitored 
  • Network segmentation validated 

Days 61-90: Documentation, Testing, and Vendor Verification 

Week 9: Incident Response Plan 

  • Draft or update the written incident response plan using the template above 
  • Populate the contact directory with current legal, insurance, and vendor contacts 
  • Schedule an annual tabletop exercise for Month 4 

Week 10: Vulnerability Scan and Baseline Penetration Test 

  • Run an internal vulnerability scan across all in-scope systems 
  • Engage a qualified third party for a baseline penetration test (this is a real budget item, typically $5,000-$15,000 for a small clinic) 
  • Prioritize findings and set 90-day remediation targets 

Week 11: Business Associate Verification 

  • Send the annual verification request to every business associate on file 
  • Track responses and follow up on non-responsive vendors 
  • For vendors that cannot verify, document the risk and plan mitigation or replacement 

Week 12: Workforce Training and Documentation Consolidation 

  • Deliver refreshed HIPAA security awareness training to all workforce members 
  • Run a phishing simulation and document results 
  • Consolidate all documentation (inventory, network map, risk analysis, IR plan, vendor verifications, training records) in a single secure location 
  • Schedule the next quarterly review 

End of Month 3 deliverables: 

  • Written incident response plan, ready for annual tabletop 
  • Completed vulnerability scan and penetration test with remediation plan 
  • Business associate verifications collected or documented gaps 
  • Refreshed workforce training with completion records 
  • Consolidated documentation binder (digital or physical) 

Part 5: Common Pitfalls and How to Avoid Them 

Pitfall 1: Trying to do everything at once.

The proposed rule covers a lot of ground. Clinics that attempt full simultaneous implementation typically burn out staff and produce incomplete work. Follow the 90-day sequencing above. Start with the risk analysis. Then MFA and encryption. Then testing and documentation. Sequenced execution beats aspirational overhaul. 

Pitfall 2: Treating the risk analysis as a checkbox.

The most frequently cited OCR deficiency is risk analysis, not the absence of technical controls. A generic template downloaded from the internet, filled with vague statements, will not withstand OCR scrutiny. The risk analysis must reflect your actual environment, your actual vendors, and your actual threats. 

Pitfall 3: Assuming your EHR vendor handles HIPAA for you.

EHR vendors are business associates. They handle their own compliance. Your clinic is still responsible for how ePHI is accessed, stored, and transmitted at your location, on your devices, and by your workforce. The EHR being HIPAA-compliant does not make the clinic HIPAA-compliant. 

Pitfall 4: Waiting for the final rule.

Some clinics are waiting to see what OCR finalizes. This is risky for two reasons. First, most of the proposed changes are already best practices that OCR enforces under the current rule via risk analysis and reasonable security requirements. Second, when the final rule drops, the implementation window is 180 days. Six months is not enough time to build asset inventories, deploy MFA and encryption, complete a penetration test, and verify every business associate from a cold start. 

Pitfall 5: Underestimating the cost of legacy systems.

Older EHRs, imaging systems, and specialty devices often cannot support MFA or modern encryption. These will require either replacement, network isolation, or documented compensating controls. Budget accordingly. HHS estimates first-year industry compliance cost at approximately $9 billion (source: HHS regulatory impact analysis). 

Pitfall 6: Skipping the testing.

Backup systems that have never been restored may not actually work. Incident response plans that have never been tested will fail under real pressure. The proposed rule requires actual testing, not just documented procedures. Build testing into your operational calendar. 

Part 6: What SecTec Provides 

SecTec provides AI-driven managed IT and cybersecurity built for medical clinics, healthcare providers, and organizations under 200 staff. Our HIPAA compliance service maps directly to the proposed rule requirements, covering: 

  • End-to-end Security Risk Analysis with documentation 
  • Asset inventory and network map development 
  • MFA deployment across all in-scope systems 
  • Encryption at rest and in transit 
  • EDR deployment (SentinelOne) and 24/7 monitoring 
  • Vulnerability scanning and penetration testing coordination 
  • Incident response planning and tabletop exercise facilitation 
  • Business associate agreement management and annual verification 
  • Workforce security awareness training (KnowBe4) 
  • Documentation, audit preparation, and OCR response support 

Every engagement starts with a free cybersecurity risk assessment. Three weeks. Prioritized findings. Zero obligation. 

Book your free assessment | Learn more about our HIPAA compliance service

Regulatory Status Disclaimer 

This guide is based on the HIPAA Security Rule Notice of Proposed Rulemaking (NPRM) published by HHS Office for Civil Rights on December 27, 2024, and formally published in the Federal Register on January 6, 2025. As of mid-2026, this rule remains proposed. OCR has not issued a final rule, and the requirements described here could be modified, delayed, or withdrawn. 

The current HIPAA Security Rule remains in force and enforceable. This guide is intended to help clinics prepare for the direction of the industry, not to describe currently binding law. Consult qualified legal counsel for advice specific to your practice. 

Sources: 

  • HHS OCR HIPAA Security Rule NPRM (December 27, 2024) 
  • Federal Register: HIPAA Security Rule to Strengthen Cybersecurity of ePHI (January 6, 2025) 
  • HHS OCR Fact Sheet on the NPRM (December 2024) 
  • HIPAA Journal ongoing coverage (2025-2026) 

Prepared by SecTec. AI-Driven IT & Cybersecurity for Modern Businesses. SecTec provides managed IT and cybersecurity services to medical clinics, nonprofits, law firms, and mission-driven organizations across the United States. Recognized as an Industry Expert in IT and Cybersecurity by the Center for Nonprofit Advancement. 

Blogs & Insights

See More Insights

Contact SecTec

Partner With A Certified Team

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Why work with SecTec:
What happens next?
1

Schedule a call at a time that suits you.

2

We do a discovery and consulting meeting 

3

We prepare a proposal 

Schedule a Free Consultation