Key HIPAA Security Rule Updates: What's Changing and How to Prepare

10 min read

Key HIPAA Changes in 2026

HIPAA compliance has evolved from a primary focus on patient privacy to a broader framework that also emphasizes cybersecurity, operational resilience, and organizational accountability. That shift reflects today's healthcare environment, where cyberattacks continue to target providers of every size, digital health technologies have become increasingly interconnected, and protecting patient information requires stronger technical, administrative, and workforce safeguards.

For specialty practices – including ophthalmology, dermatology, plastic surgery, and med spas – these changes reach far beyond IT. They influence how practices manage access to patient information, evaluate vendors, train employees, document security efforts, and invest in technology. And regardless of practice size, protecting patient information is a fundamental responsibility.

While some HIPAA requirements are already enforceable today, other significant updates remain under consideration by the U.S. Department of Health and Human Services (HHS). Understanding the difference allows practices to strengthen compliance today while preparing for what's ahead.

In this guide, we'll cover:

  • The biggest HIPAA updates affecting specialty practices in 2026  
  • Which changes are already in effect versus still proposed
  • Practical steps every practice should take now
  • How specialty healthcare organizations can strengthen security while improving operational efficiency

The Biggest HIPAA Updates for 2026

HIPAA continues to evolve in response to growing cybersecurity threats, expanding digital healthcare, and increasing regulatory scrutiny. Some changes represent new compliance deadlines under existing regulations, while others are part of HHS's proposed modernization of the HIPAA Security Rule. Although the proposed rule has not yet been finalized, it provides a clear indication of where regulatory expectations are heading. The most significant developments include stronger cybersecurity safeguards, expanded risk assessment expectations, enhanced identity protection, more structured incident response planning, increased oversight of third-party vendors, and a greater emphasis on ongoing workforce training.

A Note About the HIPAA Privacy Rule: The updates covered below focus specifically on the HIPAA Security Rule, which establishes standards for protecting electronic protected health information (ePHI). A separate regulatory development is also underway for the HIPAA Privacy Rule. That rulemaking has now advanced to the final-rule stage with the Office of Management and Budget (OMB). Because the Privacy Rule changes involve a separate rulemaking process and address a different set of requirements, this article focuses on the proposed Security Rule changes and the steps specialty practices can take to strengthen cybersecurity and protect ePHI.

1. Proposed Security Rule Updates Focus on Modern Cybersecurity

The most significant development is HHS's proposed overhaul of the HIPAA Security Rule — the first comprehensive update since 2013. Released as a Notice of Proposed Rulemaking (NPRM) in late 2024, the proposal is intended to strengthen cybersecurity protections for electronic protected health information (ePHI) in response to the sharp increase in ransomware attacks and healthcare data breaches. The proposal remains under review, and the current Security Rule is still the enforceable standard until a final rule is issued.

What's changing

If finalized, the rule would replace many of today's flexible "addressable" implementation specifications with mandatory requirements, establish more explicit implementation timelines, and require organizations to maintain written security policies, technology asset inventories, and network maps. It would also expand technical safeguard expectations for both covered entities and business associates, creating clearer and more consistent cybersecurity standards across the healthcare industry.

What it means

Healthcare organizations would be expected to document and demonstrate how security controls are implemented rather than relying on broad interpretations of "reasonable and appropriate" safeguards.

Why it's important

Office for Civil Rights (OCR) investigations frequently identify incomplete documentation and inconsistent security practices as contributing factors in HIPAA violations. More explicit requirements are intended to reduce those gaps while improving consistency across healthcare organizations.

When it applies

The proposed Security Rule has not been finalized. Current HIPAA Security Rule requirements remain fully enforceable while HHS reviews public comments and develops a final rule.

How specialty practices should prepare

  • Rather than waiting for a final rule, practices should:
  • Review existing HIPAA policies  
  • Identify documentation gaps  
  • Inventory systems containing ePHI  
  • Evaluate whether existing security controls align with current cybersecurity best practices

2. Risk Assessments Are Receiving Greater Regulatory Attention

Risk analysis has always been a foundational HIPAA requirement, but OCR continues to emphasize that many organizations either perform incomplete assessments or fail to update them as their environments change. HHS has also proposed more detailed requirements describing what a compliant risk analysis should include.

What's changing

The proposed rule emphasizes comprehensive evaluations of every system that stores or transmits electronic protected health information (ePHI), formal documentation of identified risks and mitigation efforts, and ongoing risk management as a continuous process rather than a one-time or annual exercise.  

What it means

Risk assessments should become part of an ongoing governance process rather than an annual compliance exercise.

Why it's important

Technology environments change constantly. New software, cloud applications, imaging systems, connected medical devices, remote work, and third-party integrations all introduce new security considerations. For specialty practices, this includes:

  • Ophthalmic imaging devices  
  • Dermatology photography systems  
  • Plastic surgery imaging platforms  
  • Patient portals  
  • Practice management software  
  • Connected payment systems  

When it applies

Covered entities are already required to conduct risk analyses under the current Security Rule. The proposed rule would add greater specificity to how those analyses should be performed and documented.

How specialty practices should prepare

Practices should:

  • Complete a current risk assessment  
  • Update it whenever significant technology changes occur  
  • Document mitigation plans  
  • Review findings with leadership annually

3. Incident Response and Breach Preparedness Are Becoming More Structured

Every healthcare organization should assume that security incidents are possible and prepare accordingly. Regulators increasingly expect organizations to demonstrate not only how they prevent attacks but also how they respond when incidents occur.

What's changing

The proposed rule would require organizations to maintain more formal contingency planning, incident response procedures, system testing, and recovery documentation. It would also establish additional expectations around backup and recovery capabilities.

What it means

Organizations should be able to quickly identify security incidents, contain them, restore operations, and document their response.

Why it's important

A well-prepared incident response plan can reduce operational downtime, minimize patient disruption, and improve recovery following ransomware or other cybersecurity events.

When it applies

Current HIPAA requirements already require contingency planning and breach notification. The proposed rule would make those expectations more detailed and prescriptive.

How specialty practices should prepare

Practices should:

  • Review incident response plans annually  
  • Test backup restoration procedures  
  • Establish clear internal reporting processes  
  • Define staff responsibilities before an incident occurs  
  • Conduct tabletop cybersecurity exercises

For a more detailed description of how specialty practices should prepare, read our “How to Protect Your Practice from Healthcare Data Breaches” blog post.

4. Vendor and Business Associate Oversight Is Receiving Greater Scrutiny

Most specialty practices rely on numerous third-party vendors, including EHR providers, billing companies, cloud hosting services, patient communication platforms, payment processors, imaging software vendors, and managed IT providers. Because these organizations often access protected health information, HIPAA requires appropriate oversight through Business Associate Agreements (BAAs).

What's changing

The proposed rule changes reinforce the importance of maintaining current BAAs, conducting ongoing vendor security reviews, assessing third-party cybersecurity risks, and documenting how vendors protect electronic protected health information and support contingency planning.  

What it means

Vendor management should become an ongoing process rather than a one-time contract review.

Why it's important

Many healthcare data breaches originate through third-party vendors rather than internal systems.

When it applies

Business Associate Agreements are already required under HIPAA. The proposed rule expands expectations for how organizations evaluate and manage vendor security over time.

How specialty practices should prepare

Practices should:

  • Review all BAAs  
  • Verify vendors maintain appropriate security safeguards  
  • Periodically reassess vendor risk  
  • Document vendor review activities

5. Workforce Training Remains One of the Strongest Security Controls

Technology alone cannot prevent every security incident. Employees continue to play a critical role in protecting patient information.

What's changing

Regulators continue emphasizing more frequent workforce education, ongoing security awareness, role-based HIPAA responsibilities, and human error reduction through training and documentation. While these concepts already exist under HIPAA, organizations are expected to demonstrate that training remains current, relevant, and effective.

What it means

Annual HIPAA training should be viewed as the minimum standard. Regular reminders, phishing awareness campaigns, and role-specific education help reinforce secure behaviors throughout the year.

Why it's important

Many breaches begin with phishing emails, weak passwords, or accidental disclosures. Consistent education helps reduce these risks before they become reportable incidents.

When it applies

HIPAA already requires workforce training. The proposed Security Rule reinforces ongoing education as part of a mature security program.

How specialty practices should prepare

Practices should:

  • Provide recurring HIPAA and cybersecurity training (our CIO shows you how)
  • Simulate phishing exercises  
  • Educate new hires during onboarding  
  • Tailor training for clinical, administrative, and IT roles  
  • Document all workforce education activities

6. Mandatory Multi-Factor Authentication and Identity Protection Continue to Grow in Importance

Compromised user credentials remain one of the most common entry points for cyberattacks. Recognizing this, HHS has proposed requiring multi-factor authentication (MFA) in most circumstances while strengthening broader identity management practices.

What's changing

The proposed rule places greater emphasis on strengthening identity protection through multi-factor authentication (MFA), enhanced user identity verification, stronger password management, and more robust access controls. Together, these measures are intended to reduce unauthorized access to systems containing ePHI by ensuring users are properly authenticated and only have access to the information necessary to perform their roles.  

What it means

Organizations should evaluate whether passwords alone provide sufficient protection for systems containing ePHI.

Why it's important

Healthcare organizations increasingly operate across multiple cloud applications, remote connections, mobile devices, and integrated software platforms. Strong authentication significantly reduces the likelihood that stolen credentials can be used to access patient information.

When it applies

Mandatory MFA remains part of the proposed rule and is not yet required by HIPAA in every circumstance. However, OCR and cybersecurity experts increasingly view MFA as a leading security practice, and many cyber insurance providers already expect it.

How specialty practices should prepare  

Practices should:  

  • Enable MFA wherever supported  
  • Review user permissions regularly  
  • Remove inactive accounts promptly  
  • Limit administrative privileges  
  • Strengthen password management policies

What HIPAA Regulations Are Already in Effect vs. What's Still Proposed

Already Enforced Proposed/Pending
HIPAA Privacy Rule and current Security Rule requirements remain fully enforceable. Security Rule modernization remains under federal review and has not been finalized.
Security risk analyses are required today. More prescriptive risk analysis documentation requirements are proposed.
Business Associate Agreements are required. Expanded third-party oversight expectations are proposed.
Workforce HIPAA training remains mandatory. More structured, ongoing security awareness expectations are proposed.
Proposed requirements such as mandatory MFA, network mapping, vulnerability scanning, and annual penetration testing would only become enforceable if included in a final rule.

What These Updates Mean for Specialty Practices

HIPAA compliance touches every role within a specialty practice. While IT teams often lead security initiatives, protecting patient information depends on coordinated efforts across clinical, administrative, and leadership teams. Understanding each department's responsibilities helps create a stronger security culture while supporting efficient daily operations.

Practice Owners

Owners and executive leaders are responsible for setting the strategic direction of HIPAA compliance. As cybersecurity threats evolve and regulatory expectations become more detailed, compliance planning should become part of broader business planning. Strong governance helps practices reduce regulatory risk while protecting business continuity.

Key priorities include:

  • Budgeting for cybersecurity investments and technology upgrades
  • Reviewing and approving HIPAA policies and procedures
  • Evaluating vendor security and Business Associate Agreements
  • Monitoring organizational risk assessments
  • Supporting ongoing workforce training and compliance oversight

Providers and Clinical Staff

Providers interact with protected health information (PHI) throughout the patient journey. Every login, documentation workflow, image capture, and patient communication contributes to the practice's overall security posture.

Integrated, specialty-specific EHR workflows can also reduce manual workarounds that increase compliance risk.

Key priorities include:

  • Accessing only the information necessary to perform their role
  • Documenting patient encounters securely within approved systems
  • Protecting mobile devices used for clinical care
  • Following secure messaging and patient communication policies
  • Reporting suspected security incidents immediately

Front Desk and Administrative Staff

Administrative teams often serve as the first line of defense for protecting patient information. Because administrative staff frequently interact with patients through email, text messaging, phone calls, and patient portals, regular security awareness training remains essential.

Key priorities include:

  • Verifying patient identities before releasing records
  • Following secure scheduling and registration workflows
  • Handling payment information appropriately
  • Protecting printed documents and physical records
  • Recognizing phishing attempts and suspicious requests

IT and Operations Teams

Technology and operations teams help translate HIPAA requirements into practical security controls. Whether these responsibilities are handled internally or through a managed service provider, practices benefit from documenting security activities and reviewing them regularly.

Key priorities include:

  • Managing user access and permissions
  • Applying software updates and security patches
  • Monitoring systems for unusual activity
  • Maintaining encrypted backups
  • Testing disaster recovery procedures
  • Supporting ongoing risk assessments

Why HIPAA Matters More Than Ever for Specialty Practices

HIPAA has always centered on protecting patient privacy, but today's healthcare environment has expanded the role compliance plays in practice operations. Modern specialty practices depend on interconnected technologies, cloud-based applications, digital imaging, patient engagement tools, and third-party integrations to deliver efficient care. Each connection creates opportunities to improve the patient experience while introducing additional security considerations.

Maintaining HIPAA compliance helps practices protect sensitive patient information, reduce the likelihood of costly data breaches, demonstrate accountability during audits or investigations, maintain business continuity following cybersecurity incidents, and preserve patient confidence and trust.

Specialty practices also face unique security considerations based on the types of information they collect and the technologies they use.

Ophthalmology

Ophthalmology practices manage large diagnostic imaging files, integrate with ophthalmic devices, and coordinate data across clinics, surgery centers, and optical operations. Securing these connected systems helps protect both patient information and clinical workflows.

Dermatology

High patient volumes, digital photography, pathology documentation, and frequent patient communications in dermatology practices create numerous opportunities for handling PHI. Standardized documentation workflows and secure image management help reduce compliance risks.

Plastic Surgery

Plastic surgery practices often manage cosmetic photography, treatment planning, financing information, and highly sensitive elective procedure records. Strong access controls and secure patient communications are especially important when protecting confidential information.

Med Spas

Many med spas have expanded into wellness services, memberships, recurring treatments, patient marketing, and online scheduling. Practices should evaluate how patient communications, payment processing, CRM systems, and treatment documentation fit within their HIPAA responsibilities.  

A Practical HIPAA Readiness Checklist

Preparing for HIPAA compliance doesn't require completing every initiative at once. Breaking compliance activities into manageable categories can help practices strengthen security while maintaining daily operations.

Governance

  • Review HIPAA privacy and security policies
  • Update written procedures and documentation
  • Assign clear compliance responsibilities
  • Schedule annual policy reviews

Security

  • Complete a current security risk assessment
  • Review user access permissions
  • Enable multi-factor authentication where supported
  • Verify encrypted backups are functioning properly
  • Review incident response procedures

Workforce

  • Conduct HIPAA and cybersecurity training
  • Review phishing awareness with staff
  • Update incident reporting procedures
  • Document completed training activities

Vendors

  • Review Business Associate Agreements
  • Evaluate vendor security practices
  • Confirm third-party compliance responsibilities
  • Maintain documentation of vendor reviews

For a more detailed walkthrough of HIPAA requirements, read our Complete HIPAA Compliance Checklist for Specialty Practices.

HIPAA Compliance Preparation Timeline

While every practice's compliance journey will differ, establishing a timeline can help prioritize improvements and reduce last-minute efforts.

Do Immediately

  • Review current HIPAA policies and procedures
  • Complete or update your security risk assessment
  • Verify backup and recovery processes
  • Identify any known compliance gaps

Within the Next 30 Days

  • Update workforce HIPAA training
  • Review Business Associate Agreements
  • Evaluate access controls and authentication methods
  • Update incident response documentation

Before Year-End

  • Address identified security gaps
  • Complete policy revisions
  • Document compliance activities
  • Review your technology roadmap to support future regulatory requirements

Frequently Asked Questions

Are the new HIPAA rules already in effect?

Some HIPAA requirements are already enforceable, including the existing Privacy Rule and Security Rule. Several significant cybersecurity updates – including expanded Security Rule requirements – remain proposed and have not yet been finalized by HHS. Practices should continue complying with current regulations while preparing for likely future expectations.

Could the proposed HIPAA Security Rule change?

Yes. HHS may revise portions of the proposed rule before issuing a final version. Final compliance dates and implementation requirements will not be established until the rulemaking process is complete.

Do small specialty practices have to comply with HIPAA?

Yes. HIPAA applies regardless of practice size when an organization qualifies as a covered entity or business associate. While implementation may vary based on resources and risk, protecting patient information remains a fundamental responsibility for practices of every size.

What are the biggest HIPAA risks facing specialty practices?

Common risks include phishing attacks, ransomware, unauthorized access to patient information, weak password practices, unsecured mobile devices, third-party vendor vulnerabilities, and incomplete security risk assessments.

How often should practices perform HIPAA risk assessments?

HIPAA requires organizations to conduct an accurate and thorough assessment of risks to electronic protected health information. Rather than treating risk assessments as annual events, practices should review them whenever significant technology, workflows, or operational changes occur.

Compliance Must Be an Ongoing Strategy

HIPAA compliance continues to evolve as healthcare technology, cybersecurity threats, and regulatory expectations become more sophisticated. Preparing for future HIPAA changes doesn't require waiting for every proposed rule to become final. Practices that regularly evaluate security risks, strengthen workforce training, review vendor relationships, and invest in secure technology are better positioned to protect patient information while maintaining efficient operations.

For specialty healthcare organizations, technology also plays a meaningful role in simplifying compliance. A connected platform can reduce fragmented systems, improve user access controls, support secure documentation workflows, and provide greater visibility across clinical and administrative operations.

Nextech's intelligent, specialty-specific platform helps practices strengthen security while streamlining daily operations. From connected EHR and practice management software to secure patient engagement and integrated workflows, our solutions are designed to help specialty practices protect patient information and support ongoing compliance efforts.

Schedule time with us to learn how Nextech can help your practice build a stronger foundation for HIPAA compliance while delivering exceptional patient care.


About the Author

Courtney Tesvich is a registered nurse with more than 20 years in the healthcare field, 15 of which have been focused on quality improvements and regulatory compliance. She also holds an MBA and a master’s in jurisprudence in Health Law and Corporate Compliance. As VP of Regulatory and Compliance at Nextech, Courtney is responsible for ensuring that Nextech’s products meet government certification requirements and client needs related to the regulatory environment, as well as monitoring overall corporate compliance.

Explore Our Current Openings

Transform your career with the leading EHR & Practice Management Provider.

Explore our Current Openings
Career Mentoring, Wellness Days, Paid Leave