OneCloud IT Solutions502-268-8844Talk to OneCloud
Home / Healthcare IT / HIPAA Compliance
HIPAA compliance support

The Security Rule is being rewritten. Most practices are not ready.

HHS has proposed the first major overhaul of the HIPAA Security Rule in over twenty years. Requirements that were optional for two decades are being made mandatory — and the documentation burden is real.

Last reviewed: September 2026 · Verified against HHS guidance before publication

What is changing

From ‘addressable’ to required

The proposed rule removes the distinction that let practices document a reason for not implementing a safeguard. The reporting on it consistently identifies the following changes.

RequirementWhat it means for a practiceWhere most practices stand
Multi-factor authenticationMFA on system access, on-site as well as remote — not just the VPN.Partially done. Usually email only, rarely the EHR or workstations.
Encryption of ePHIAt rest and in transit, as a requirement rather than an option with a documented exception.Servers often yes; laptops, backups and portable media often no.
Asset inventory and data mapA written inventory of every asset touching ePHI and a diagram of how it flows.Rarely exists in writing. This is a common audit finding.
Risk analysisAnnual, and again whenever the environment changes materially.Most often done once, years ago, and never updated.
Vulnerability scanningAt least every six months.Uncommon in independent practices.
Penetration testingAnnually, against systems holding ePHI.Rare outside larger groups and hospital-affiliated practices.
Network segmentationA mandatory safeguard — clinical systems, guest wi-fi and devices separated.Flat networks are still the norm. This is often the largest gap.
72-hour restorationePHI systems restored within 72 hours of loss.Backups usually exist. Tested restores within a defined window usually do not.
Business associate verificationAnnual written verification that each BA's controls are in place.Almost never happens today.
Read this the right way

The rule is proposed, not final, and both its content and its compliance timeline can change before it takes effect. Nothing here is legal advice. Use it to understand the direction of travel and to start closing gaps that are worth closing regardless — MFA, encryption, tested restores and segmentation were good ideas before any rule required them.

The one that matters most

The risk analysis is where enforcement starts

If you do one thing this year, do this one.

A security risk analysis is the foundation requirement of the Security Rule, and a missing or stale one is among the most frequently cited findings in HHS enforcement actions. It is also the first document requested when anything goes wrong.

A real risk analysis is not a questionnaire. It identifies where ePHI lives and moves, what could reasonably compromise it, how likely and how damaging that would be, and what the practice is going to do about each item. It produces a remediation plan with owners and dates — and it gets revisited.

What ours produces

  • A written inventory of every system, device and service that touches ePHI
  • A data flow map showing how PHI enters, moves through and leaves the practice
  • Findings tested against each Security Rule safeguard, not a generic checklist
  • Risk rated by likelihood and impact, so remediation can be sequenced by what matters
  • A remediation plan with owners, effort and cost — including items we do not do
  • A document formatted to be handed to an auditor, your counsel, or your cyber insurer
Division of labor

What we take on, and what stays with you

We publish this split on the healthcare hub as well, because it is the single most common source of misunderstanding between a practice and its IT provider. In short: we own the technical safeguards and the evidence that they exist. The practice owns privacy policy, patient rights, training records beyond security awareness, and any breach determination.

Questions

HIPAA questions practices ask

When does the new Security Rule take effect?

It has not been finalized, and the compliance timeline will be set when it is. Reporting through 2026 has pointed to HHS aiming to finalize during the year with a compliance period to follow, but that is a target rather than a date you can plan a budget around.

The practical answer: the substantive controls — MFA, encryption, segmentation, tested restores — take months to implement well. Practices that wait for a final date will be implementing under time pressure.

Is there such a thing as HIPAA certification?

No. HHS does not certify software, vendors or practices as HIPAA compliant, and any product or provider advertising a HIPAA certification is describing something that does not officially exist.

What does exist: a documented risk analysis, implemented safeguards, signed BAAs, training records, and evidence you can produce. That is what is actually examined.

What happens in an OCR investigation?

Investigations usually begin with a complaint or a breach report, and the early requests are documentary: your risk analysis, your policies, your training records, your BAAs, and evidence that safeguards were in place. Practices are rarely caught out by exotic technical failures. They are caught out by paperwork that was never produced.

This is a legal process, and a practice facing one should be working with counsel, not only with its IT provider.

Does moving to the cloud make us compliant?

No, though it can help. A cloud provider handling PHI is a business associate and must sign a BAA, and the major platforms will. But the practice remains responsible for how it configures access, who has permissions, whether MFA is enforced, and what happens on the laptops and workstations connecting to it. Most breaches begin with a credential, not with the data center.

How much of this can you handle for us?

The technical safeguards, the monitoring, the documentation of both, the backup and recovery program, security awareness training, and the annual verification of our own controls. That is the majority of the technical burden.

Privacy policies, patient rights procedures, your BAA register for other vendors, and breach determination stay with the practice. We will tell you when something falls on your side rather than quietly leaving it undone.

Find your gaps before an auditor does

An assessment tells you where your practice stands against each requirement, in plain language, with a costed plan to close what matters.