If you run a small clinic, you have probably heard three different versions of the same story. One says the HIPAA Security Rule updates are already law. Another says they were cancelled. A third says you need to spend a fortune on IT before the end of the year.
None of those is accurate. The revised HIPAA Security Rule is still only proposed, but the current rule is fully enforceable today. The smartest move for a small medical office is to start closing the gaps the proposal targets now, because regulators already expect you to.
At ZIA Networks, we help small practices turn these requirements into a practical, affordable plan. This guide explains where the rule stands, what would change, what it means for a practice with ten staff (not ten thousand), and the exact steps to take first.
What Are the HIPAA Security Rule Updates?
The HHS Office for Civil Rights announced the proposed changes to the Security Rule (2025) on January 6, 2025, which would require certain cybersecurity requirements for HIPAA-regulated organizations.
These encompass mandatory encryption, multi-factor authentication, network segmentation, and periodic testing. The idea hasn’t been solidified yet.
The Security Rule itself is from 2003. It provides guidelines for covered entities, such as clinics and hospitals, as well as business associates (billing companies, IT vendors, cloud providers) of those covered entities to ensure the security of ePHI.
For two decades, it was deliberately flexible. That flexibility is the whole story behind the update.
Why regulators want to change it
This regulation was designed for a time when everyone had a desktop PC and a fax machine. Today, your patients’ records don’t sit in one filing cabinet. They move between cloud-based EHRs, patient portals, staff smartphones, and the billing platforms you rely on.
But the threat landscape also evolved very quickly. The Change Healthcare ransomware attack of 2024 threw healthcare transactions into turmoil and compromised the personal information of around 190 million people.
And when one vendor failure can immobilize thousands of clinics, “flexible” begins to sound like “Doubtful.”
The “addressable” loophole
Under the current rule, many safeguards are labeled addressable rather than required. Many small practices assume “addressable” means they can skip it. That was never the intent.
Addressable means you must implement the control, or document why it is not reasonable for you and put an equivalent in place. In practice, a lot of clinics skipped the second half, the documentation, and treated the control as optional. The proposal would remove the distinction for most safeguards, so every control becomes required.
Where Do the HIPAA Security Rule Updates Stand Right Now?
As of October 2026, the HIPAA Security Rule overhaul is still a proposed rule. HHS moved its projected final action to July 2027, and the current Security Rule remains fully in effect and enforceable until a final rule replaces it.
Here is the timeline in plain terms:
Date | What happened |
January 6, 2025 | OCR published the proposed rule in the Federal Register. |
Spring 2025 | The public comment period closed. OCR received close to 5,000 comments. |
May 2026 | The original target for a final rule. It passed with no final rule published. |
July 2026 | The federal regulatory agenda moved the rule to “long-term actions” and the projected final action to July 2027. |
Today | The proposal is active but not binding. The 2003 rule, as amended, is what OCR enforces. |
Trade groups pushed back hard, arguing that the proposal carries high costs and aggressive timelines, especially for smaller providers. That pushback is a big reason the date keeps sliding.
Should you wait for the final rule?
No. There are three reasons.
- Enforcement has not paused. Current penalties run from roughly $145 to more than $73,000 per violation after the 2026 inflation adjustment, with annual caps above $2 million per violation category.
- The final rule may look different. Comments could soften timelines or scope, but almost nobody expects regulators to back away from encryption and MFA.
- Most of the proposal is just good security. The insurer, health systems, and larger partner organizations are all already requesting these controls from cyber insurers and vendor questionnaires.
In our experience reviewing small-practice environments, the clinics that feel least stressed about regulatory news are the ones that treated security as an ongoing habit instead of a yearly paperwork sprint.
What Would the Proposed HIPAA Cybersecurity Requirements Change?
The proposed HIPAA cybersecurity requirements would mandate encryption of ePHI at rest and in transit, multi-factor authentication, network segmentation, vulnerability scanning every six months, annual penetration testing, a documented asset inventory and network map, and the ability to restore critical systems within 72 hours.
That is the headline list. Here is how each item translates to a small clinic.
Proposed requirement | What it means in plain English | Typical clinic example |
Encryption (at rest and in transit) | Scramble patient data so a stolen device or intercepted file is unreadable | Encrypted laptops, encrypted EHR database, secure email for PHI |
Multi-factor authentication (MFA) | A password alone is no longer enough to reach ePHI | Code or app prompt when logging in to the EHR or remote desktop |
Network segmentation | Separate systems so one infected device cannot reach everything | Guest Wi-Fi isolated from the network that holds patient records |
Asset inventory and network map | Know every device and system that touches ePHI, reviewed at least yearly | A living list: workstations, printers, tablets, imaging devices, cloud apps |
Vulnerability scans every 6 months | Regularly check for known weaknesses | Scheduled scan of your office network and servers |
Annual penetration test | A controlled “break-in attempt” to find what scans miss | Third-party tester probes your firewall and remote access |
72-hour restoration | Get critical systems back within three days of an incident | Tested backups and a written recovery plan |
Annual compliance audit | A formal yearly check that controls actually work | Documented review against the Security Rule |
Vendor notification (24 hours) | If a vendor that handles your patient data switches to its emergency plan, it would have to let you know right away. | Clause in your billing and IT vendor contracts |
Two more changes get less attention but matter just as much.
- Written documentation for everything. Policies, procedures, plans, and risk analyses would all need to be in writing.
- Annual vendor verification. You would need written confirmation that your business associates have the technical safeguards they claim.
The part most articles miss: it changes how you buy IT
Here is the angle you will not find in a generic summary. The update quietly shifts responsibility from “did you buy a tool?” to “can you prove it works?”
An antivirus license on a receipt is not evidence. A dated scan report, a tested restore log, and a signed vendor attestation are. If you are choosing HIPAA IT services for your practice, ask every provider one question: what proof will you hand me each quarter?
What Does HIPAA Compliance Look Like for Small Clinics?
HIPAA compliance for small clinics is based on protecting the ePHI through doing the written risk assessment, making policies, training the staff, access controls, encrypting, testing backups, and signing any protocols with vendors that will have access to the patient information. The rule is scalable; however, the rule never goes away.
This is the part that worries clinic owners most, and it should be addressed honestly.
The Security Rule has always been “scalable.” A three-doctor family practice is not expected to run a hospital-grade security operations center. But scalable never meant exempt.
In the proposed rule, regulators signaled little appetite for carve-outs based on size. A small clinic holds the same kind of data, and attackers know small clinics are easier targets.
Why small clinics get hit
Small practices tend to share a few traits:
- One person (often the office manager) doubles as the “IT person.”
- Software and operating systems are updated when someone remembers.
- Shared logins are common because they are convenient.
- Backups exist, but nobody has ever tried restoring from them.
None of the above represents a character weakness. This is simply a resourcing issue. The aim should be to develop this behavior into a routine.
A realistic scenario
Picture a four-provider clinic with a cloud EHR, a front-desk PC, a shared printer, and Wi-Fi that patients can also use. A receptionist clicks a convincing “fax delivery” email. Without MFA and segmentation, the stolen password opens the EHR, and the infection can spread to the billing machine.
With MFA, the password alone fails, Segmentation, the damage stays in one corner, and tested backup, recovery takes hours instead of weeks. That chain of three inexpensive controls is exactly what the proposed rule is trying to make universal.
Your HIPAA Compliance Checklist for the Proposed Updates
To begin with, a HIPAA compliance checklist should have a risk analysis followed by MFA, encryption, inventory of assets, network segmentation, patch management, backup testing, contractual arrangements, and employee training. Follow this order to address the most critical vulnerabilities first.
Make use of this as a checklist. Get it printed, give it to your tech manager, and mark the dates on each item.
Step 1: Complete a real risk analysis
The risk analysis is the foundation of everything.OCR has frequently found the omission of a valid risk analysis as one of the most frequent deficiencies in its investigation reports.
It must document all areas where ePHI is stored, any potential threat to it, the probability of such a threat becoming true, and steps that you will take to mitigate the risk.
Step 2: Activate MFA everywhere where ePHI can be accessed
Begin with email, EHR, remote access, and administrative log-ins. This one control alone thwarts a great number of attacks based on credential theft, and comes included with most systems without additional charge.
Step 3: Encryption of devices and information
- Enable encryption of all laptops, desktops, and cell phones that may access patient information.
- Make sure your EHR provider encrypts stored data and encrypts transmission of data, in writing.
- Stop using regular email to send PHI. Use an encrypted system.
Step 4: Create an asset inventory and network diagram
You can’t protect what you don’t know about. Identify every machine, program, and connection that is involved with the ePHI, down to that old computer in the storage closet and the imaging machine no one has patched up since setup.
Step 5: Segregate your network
Separate guest access Wi-Fi, work computers, medical equipment, and the database containing the patient information. With a good configuration, your business-class firewall does most of this.
Step 6: Patch and scan regularly
The proposed solution links the necessary scanning process to an acceptable period for fixing any major vulnerabilities identified. Schedule your patching process monthly and your scanning process twice a year.
Step 7: Prove your backups actually work
Saving a copy of your data isn’t the same as being able to get it back. Until you’ve done a test restore, you’re guessing. Run a restore test, time it, and write down the result. The 72-hour target in the proposal is a reasonable benchmark to aim for today.
Step 8: Tighten vendor and business associate agreements
Review each Business Associate Agreement and ensure that all Business Associates report and document the security measures performed in a timely fashion and on an annual basis.
Step 9: Train your staff, then train them again
People click links. Short, regular sessions with simulated phishing beat a once-a-year slideshow. Document who attended and when.
Step 10: Document everything
Write it down: policies, risk analysis, decisions, test results, training logs. If OCR ever calls, documentation is your defense.
Current Rule vs. Proposed Rule: Side-by-Side
The current HIPAA Security Rule updates let organizations treat many safeguards as addressable and document few specific technical standards. The proposed update makes most safeguards mandatory and names specific controls, such as MFA, encryption, and testing intervals.
Area | Current Security Rule | Proposed update |
Safeguard types | “Required” and “addressable” | Nearly all become required |
Encryption | Addressable | Required at rest and in transit |
MFA | Not specifically mandated | Required for ePHI access |
Asset inventory | Implied by risk analysis | Written inventory and network map, reviewed yearly |
Vulnerability scanning | Not specified | At least every six months |
Penetration testing | Not specified | At least annually |
Recovery | Contingency plan required | Restore critical systems within 72 hours |
Vendor oversight | BAAs required | Annual written verification of safeguards |
Compliance audit | Periodic evaluation | Formal annual audit |
Status | In force today | Proposed, final action projected July 2027 |
Read that last row twice. Everything in the right-hand column is a preview, not a deadline. Everything in the left-hand column is what you can be fined for today.

What are HIPAA IT Requirements, and Who Is Responsible?
HIPAA IT requirements are the administrative, physical, and technical safeguards the Security Rule requires to protect ePHI. Responsibility is shared: the clinic remains legally accountable even when it outsources IT to a vendor, so you must verify that vendor’s work.
This is where many practices get caught. Handing IT to an outside company does not hand off the liability.
Here is the practical split.
Safeguard type | What it covers | Who usually handles it |
Administrative | Risk analysis, policies, training, vendor agreements | You, with guidance from your IT partner |
Physical | Locked server closets, screen privacy, device disposal | You and your facility manager |
Technical | Encryption, MFA, logging, patching, backups | Your IT provider, verified by you |
If you already work with an IT company, ask whether they will sign a Business Associate Agreement. If the answer is no, or hesitant, that is a serious red flag.
How to pick HIPAA IT services without getting oversold
Look for a provider that:
- Signs a BAA without a fight.
- Delivers written reports (scans, patch status, restore tests) on a fixed schedule.
- Explains controls in plain language you can repeat to an auditor.
- Prices by clear scope, not vague “security packages.”
- Has experience with clinics your size, not only enterprises.
At ZIA Networks, we build our healthcare IT support around that evidence-first approach: fewer promises, more paper trail.
How Much Will It Cost, and Where Should You Spend First?
The highest-impact control mechanisms (MFA, encryption, backup tests, and training of employees) are also relatively inexpensive to implement. Penetration testing and audits are relatively costly but happen periodically; hence, you should allocate an annual budget for the costs involved.
We are not able to give a universal price as the cost depends on your practice size, number of facilities, and modernity of your infrastructure. However, the priority of measures remains the same.
Priority | Control | Relative cost | Risk reduction |
1 | MFA | Low | Very high |
2 | Tested, offsite backups | Low to moderate | Very high |
3 | Device and data encryption | Low | High |
4 | Staff phishing training | Low | High |
5 | Network segmentation and firewall | Moderate | High |
6 | Vulnerability scanning | Low to moderate | Moderate to high |
7 | Penetration testing and audit | Moderate to high (annual) | Moderate |
Spend in that order, and you capture most of the benefit before the expensive items arrive.
Common Mistakes Small Clinics Make
After years of watching practices approach compliance, the same errors keep surfacing.
- Treating “addressable” as “optional.” It is not, and the proposal would end the confusion.
- Misconception about HIPAA-compliant software and a HIPAA-compliant office. The software is there to help you, but the responsibility is yours.
- Skipping the risk analysis. It is the document regulators ask for first.
- Never testing backups. The first restore should never happen during a crisis.
- Ignoring old equipment. Forgotten devices are the easiest way in.
- Waiting for the final rule. Delay is the most expensive strategy.
FAQs
Is the HIPAA Security Rule update final?
No. As of October 2026, it is still a proposed rule. HHS now projects final action for July 2027, and nothing in the proposal is legally binding until a final rule is published.
Does the current HIPAA Security Rule still apply?
Yes. The current rule remains fully and equally applicable and enforceable until replaced by a final rule. Violations are still subject to penalties.
Do small clinics have to follow the new requirements?
The proposal does not exempt small providers. The Security Rule applies to all covered entities and business associates, whatever their size.
What is the first thing a small clinic should do?
Complete a thorough, documented risk analysis, then turn on multi-factor authentication for every system that can reach patient data.
Is encryption required under HIPAA today?
Encryption is currently an addressable control, which means that you either have to put it in place or find another way to fulfill the requirements.
How often should a clinic review its HIPAA security?
At least annually and when new systems are added, when vendors are changed, or when a problem occurs. The proposed process will be made formal through an annual compliance audit.
Does outsourcing IT make my clinic compliant?
Absolutely not. You must be able to protect patient information yourself. Your IT partner should help you, but a BAA agreement and evidence of ongoing work must be provided.
Final Thoughts
The HIPAA Security Rule updates and modifications are taking more time than originally expected but are still here to stay. The path forward has been laid out clearly – hard, verifiable cybersecurity controls versus guidelines and flexibility.
For your clinic, that means you have a gift of time. Use it well.
Here is your action plan at a glance:
- This week: Make sure no one can reach your email, patient records, or remote access with just a password.
- Monthly: Do a risk assessment and develop an inventory of assets.
- Quarterly: Back up/restore testing, network segmentation, and encryption of all devices.
- This year: Review every vendor agreement, train staff, and schedule your first scan and audit.
None of this is wasted if the final rule changes. Every item reduces your breach risk and your liability today.
Get a Clear Picture of Your HIPAA Gaps
This is something you don’t have to figure out on your own. ZIA Networks makes the HIPAA cybersecurity compliance requirements easy for small clinics by putting together a realistic and inexpensive strategy with easily understandable documentation that you can present to an auditor, insurer, or partner.
Book a free HIPAA readiness conversation with ZIA Networks, and we will walk through your current setup, flag the highest-risk gaps, and give you a prioritized to-do list you can start on Monday.