Sep 16, 2026

Resource

2026 HIPAA Security Rule Update: What to Know

HHS has proposed the biggest update to the HIPAA Security Rule since 2013, and while the final rule has been delayed to July 2027, the direction is already clear. If you run a medical or dental practice in Palm Beach, Broward, or Miami-Dade, the requirements coming your way go well beyond "have a firewall and call it a day." Here's what's actually in the proposed rule, and why waiting until 2027 to start is a mistake.

Multi-factor authentication becomes mandatory. Every system that touches patient data, your EHR, email, patient portal, billing software, would require MFA, with only narrow exceptions. If your staff is still logging in with just a password, this alone is a multi-week project once you factor in staff training and vendor coordination.

Encryption of ePHI at rest and in transit, with limited exceptions. That means patient data sitting on a server, a laptop, or a backup drive needs to be encrypted, not just data moving over the internet. A lot of older practice management systems and legacy backup setups were never built with this in mind.

A real technology asset inventory and network map. You would need to document every device and system that can access ePHI, and how patient data actually moves through your network, reviewed at least annually. Most small practices have never done this formally.

Vulnerability scans every six months, penetration testing annually, and a full security audit at least once a year. This is a meaningful jump from the current rule's vaguer "periodic" language, and it's not something your front desk can do between patients.

Network segmentation and a 72-hour data restoration requirement. Your guest Wi-Fi, your practice management system, and your medical devices should not all sit on the same flat network, and you need a tested plan to restore data within 72 hours of an incident.

Annual verification of your business associates' security measures. If your IT vendor, billing company, or answering service touches patient data, you're on the hook for confirming they're actually secure, not just trusting the contract you signed three years ago.

Why this matters even with the delay: OCR has already signaled these are "current cybersecurity best practices," which means they're increasingly the standard auditors and cyber insurance carriers expect right now, final rule or not. Practices that wait until the deadline is imminent typically end up paying rush pricing for the same work a phased rollout would have covered gradually.

Not sure where your practice stands against these requirements? Get a free HIPAA security gap assessment →









Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence