Compliance and Regulatory Updates
HIPAA Security in 2026: What Is Required Now, What Is Proposed, and What Healthcare Organizations Should Harden First

Healthcare organizations face two parallel responsibilities in 2026: comply with the HIPAA Security Rule that is currently in effect and prepare intelligently for stronger requirements proposed by the U.S. Department of Health and Human Services.
The distinction is essential. HHS explicitly states that the current Security Rule remains in effect while rulemaking continues. Proposed requirements should not be presented as final law, yet many of the proposed practices—asset inventory, stronger authentication, segmentation, vulnerability management, recovery testing, and documented incident response—also address risks that organizations should already evaluate under the current rule.
This article is general cybersecurity and compliance information, not legal advice.
Executive summary
- The current HIPAA Security Rule remains in effect.
- Covered entities and business associates must implement reasonable and appropriate administrative, physical, and technical safeguards for electronic protected health information.
- The current rule requires an accurate and thorough risk analysis and risk management appropriate to the organization’s circumstances.
- HHS’s proposed rule is not final. It proposes more prescriptive requirements, including asset inventory and network mapping, written documentation, multifactor authentication with limited exceptions, vulnerability scanning, penetration testing, segmentation, encryption, backup and recovery controls, and recurring compliance review.
- HHS’s January 2026 guidance emphasizes system hardening: patching, removing unnecessary software and services, enabling security controls, and maintaining security baselines.
- Organizations should strengthen controls now based on documented risk, while labeling proposed-rule readiness separately from current-rule compliance.
What the current Security Rule requires
HHS’s current Security Rule summary states that regulated entities must protect the confidentiality, integrity, and availability of ePHI; protect against reasonably anticipated threats and impermissible uses or disclosures; and ensure workforce compliance.
The current rule applies to covered entities and business associates. It is designed to be scalable and technology-neutral, allowing security measures to reflect an entity’s size, complexity, capabilities, infrastructure, costs, and the probability and criticality of risks to ePHI.
That flexibility is not permission to leave choices undocumented. HHS says regulated entities must perform an accurate and thorough assessment of potential risks and vulnerabilities to ePHI and implement measures that reduce risks and vulnerabilities to a reasonable and appropriate level.
What is proposed—not final
HHS issued a Notice of Proposed Rulemaking in December 2024. Its NPRM page and fact sheet describe proposed modifications. HHS states plainly that the current Security Rule remains in effect during rulemaking.
The proposed changes include:
- removing the distinction between required and addressable implementation specifications, with limited exceptions;
- written documentation for Security Rule policies, procedures, plans, and analyses;
- an ongoing technology asset inventory and network map showing ePHI movement;
- more specific written risk analysis;
- strengthened contingency and incident-response planning;
- restoration procedures for certain systems and data;
- recurring compliance audits;
- business-associate verification of technical safeguards;
- encryption of ePHI at rest and in transit, with limited exceptions;
- standardized system configuration controls;
- multifactor authentication, with limited exceptions;
- vulnerability scanning and penetration testing at specified intervals;
- network segmentation;
- separate backup and recovery controls; and
- recurring effectiveness testing.
These are proposals as of the fact-check date. A future final rule may differ in content, timing, exceptions, or applicability.
Why current compliance and proposed readiness should be tracked separately
An organization should maintain two columns:
| Current Security Rule | Proposed-rule readiness |
|---|---|
| Applicable requirements now | Gap analysis against NPRM concepts |
| Risk-based implementation and evidence | Preliminary design and budget planning |
| Current policies, procedures, and evaluations | Potential future documentation and testing expansion |
| Current legal compliance conclusion | Not represented as final-law compliance |
This avoids both underreaction and overstatement. A clinic should not delay a necessary control because it appears in a proposal; it should implement based on current risk and current duties. It also should not claim that an NPRM requirement is already mandatory.
HHS’s 2026 hardening message
The January 2026 OCR Cybersecurity Newsletter defines system hardening as customization that reduces attack surface, typically through patching, removing or disabling unnecessary software and services, and enabling and configuring security measures.
HHS connects hardening to the current rule’s risk-analysis and risk-management provisions. The newsletter also emphasizes that hardening and security baselines are not one-time activities; their effectiveness must be evaluated as threats, vulnerabilities, systems, and operations change.
What healthcare organizations should harden first
1. Build an accurate asset and ePHI map
Inventory:
- endpoints and mobile devices;
- servers and virtual machines;
- network and security devices;
- electronic health record systems;
- imaging and laboratory systems;
- medical devices;
- cloud and hosted services;
- email and collaboration;
- backup and recovery systems;
- remote access;
- service accounts and integrations;
- business-associate connections; and
- applications that store, transmit, or can access ePHI.
Map ePHI flows, trust relationships, and operational dependencies. An inventory without an owner, location, version, support status, and data relationship is difficult to use for risk analysis.
2. Patch vulnerabilities with clinical context
HHS says operating systems, applications, databases, web servers, EHRs, office software, firmware, routers, and firewalls may require patching. The guidance points organizations to vendor alerts, vulnerability scanning, the National Vulnerability Database, and CISA’s Known Exploited Vulnerabilities catalog.
Use a risk-based process:
- confirm the affected asset and version;
- identify ePHI and clinical impact;
- assess exposure and known exploitation;
- obtain vendor or manufacturer guidance;
- test where feasible;
- schedule and document change;
- preserve evidence if exploitation is plausible;
- validate the update; and
- document compensating controls when patching is not possible.
Medical-device changes must follow manufacturer instructions and safety requirements. Do not apply an ordinary workstation baseline blindly to a clinical device.
3. Remove unnecessary software, services, accounts, and protocols
HHS specifically discusses unneeded software and insecure or unnecessary services such as RDP, Telnet, and FTP. It also warns about default and orphaned privileged accounts.
Review:
- installed software;
- enabled features;
- listening services and ports;
- legacy remote access;
- default credentials;
- unused administrator accounts;
- service accounts left by removed applications;
- unsupported protocols; and
- vendor remote-support access.
Test changes before production where removal could affect clinical or business operation.
4. Establish secure configuration baselines
Define approved configurations by technology family, with exceptions for clinical safety and vendor support. A baseline should cover:
- authentication;
- privileged access;
- encryption;
- audit logging;
- endpoint protection;
- firewall and host rules;
- removable media;
- local accounts;
- software allow/deny controls;
- remote management;
- time synchronization;
- update configuration; and
- backup agents.
Track deviations, owners, rationale, compensating controls, and review dates.
5. Strengthen identity and access
The current rule includes access control and authentication safeguards. HHS’s 2026 hardening guidance notes that risk analysis may determine multifactor authentication is needed to reduce unauthorized-access risk.
Prioritize:
- remote access;
- email and cloud services;
- privileged accounts;
- EHR and ePHI repositories;
- backup administration;
- vendor access;
- password reset and recovery;
- terminated and transferred workforce access; and
- periodic access review.
Use phishing-resistant methods where feasible, particularly for privileged and high-risk access.
6. Make logging usable
Confirm that logs can answer:
- who accessed ePHI;
- which privileged changes occurred;
- whether remote or vendor access was used;
- what security alerts fired;
- whether logs are protected from alteration;
- how long evidence is retained;
- who reviews it; and
- what escalation occurs.
Collecting logs without review, time synchronization, retention, or ownership does not create reliable detection evidence.
7. Test backup and recovery as clinical resilience
Backups should cover ePHI and the configurations, identity, integrations, and applications needed to restore care and operations. Test:
- restore from protected copies;
- independence from production credentials;
- application consistency;
- recovery sequence;
- minimum viable clinical operation;
- downtime procedures;
- data reconciliation;
- communication; and
- ransomware or destructive-event scenarios.
Record actual recovery time and gaps rather than relying on a vendor’s theoretical recovery objective.
8. Validate business associates
Contracts matter, but operational assurance also matters. Review:
- services and ePHI involved;
- access paths;
- security responsibilities;
- incident notification;
- subcontractors;
- logging and evidence;
- backup and continuity;
- vulnerability management;
- termination and data return or deletion; and
- assurance reports or testing relevant to the service.
Do not assume a general certification proves that the specific service configuration protects your ePHI.
A 90-day hardening sequence
Days 1–30: establish visibility
- Update asset and ePHI-flow inventory.
- Confirm security and privacy ownership.
- Review risk analysis for current systems and changes.
- Identify internet-facing, remote-access, privileged, and unsupported assets.
- Find overdue high-risk patches and default or orphaned accounts.
- Verify backups exist and are protected.
Days 31–60: reduce priority exposure
- Remediate known exploited and critical exposure.
- Strengthen privileged, email, cloud, remote, and vendor authentication.
- Remove unnecessary services and accounts.
- Implement or update baselines.
- Improve log coverage for identity, endpoints, servers, EHR, cloud, network, and backup.
- Assign business-associate gaps.
Days 61–90: prove operation
- Test restoration and downtime procedures.
- Exercise incident reporting and escalation.
- Sample access reviews and configuration compliance.
- Validate remediation through rescanning or direct inspection.
- Report residual risks to leadership.
- Maintain a separate NPRM-readiness gap list.

Evidence to retain
- current risk analysis and risk-management plan;
- asset inventory and ePHI flow;
- approved baselines and exceptions;
- vulnerability, patch, and validation records;
- identity and access reviews;
- logging and alert-review records;
- backup and restoration tests;
- incident-response exercises;
- workforce access changes;
- business-associate oversight;
- periodic evaluations; and
- remediation and risk-acceptance decisions.
For a deeper overview, see What Is HIPAA? A Practical Guide for Orange County Healthcare Businesses and the HIPAA Compliance Roadmap for Orange County Healthcare Practices. For readiness exercises and first-response decisions, use Incident Response After the First Alert as a practical companion.
Harden current risk while tracking proposed change accurately
OC Security Audit can review HIPAA security risk, evidence, identity, network, cloud, vulnerability, backup, and incident-readiness controls. Legal interpretation should be confirmed with qualified counsel. Contact OC Security Audit to discuss the cybersecurity assessment.
Prepared and reviewed by Ali Hassani, CISO.
Primary sources
- HHS: Summary of the current HIPAA Security Rule
- HHS: HIPAA Security Rule NPRM
- HHS: HIPAA Security Rule NPRM fact sheet
- HHS: January 2026 OCR Cybersecurity Newsletter—System Hardening and Protecting ePHI
- HHS: Security Risk Assessment Tool
- CISA Known Exploited Vulnerabilities Catalog
Last fact-checked July 2026. This is general information, not legal advice. The current rule, any final rule, and authoritative HHS guidance control.