Every few weeks a practice manager asks us whether the new HIPAA Security Rule has come out yet. The answer, as of this writing in late March 2026, is no. The Office for Civil Rights published a notice of proposed rulemaking on January 6, 2025. Public comments closed on March 7, 2025, and OCR has said it received roughly 4,700 of them. In December 2025 a coalition of more than a hundred provider and health IT organizations, led by CHIME, wrote to the HHS Secretary asking for the proposal to be withdrawn outright. OCR has said publicly that it is working on a final rule. Nothing has been published, and the regulatory agenda dates keep moving.
We think the waiting is the wrong frame. The Security Rule that exists today already requires a risk analysis, access controls, audit logs, encryption where reasonable, and business associate agreements, and OCR has been enforcing the risk analysis requirement aggressively since it announced an enforcement initiative on that topic in late 2024. Most of the settlements OCR announced in 2025 cited a missing or inadequate risk analysis. Practices that are behind on the current rule are exposed now, and practices that are current on it are most of the way to whatever the final rule says.
Key takeaways
- There is no final HIPAA Security Rule as of March 2026, and no reliable date for one. The current rule is what OCR is enforcing, and the risk analysis is what it enforces most.
- Multifactor authentication, encryption and an asset inventory are almost certain to survive in the final rule in some form, because OCR already asks for them in every investigation.
- The seven steps below are required or expected under the current rule as enforced. None of them will be wasted.
- Billing is where ePHI moves the most. Encrypted transfer to the clearinghouse, no patient data in unencrypted spreadsheets, and a BAA with the billing company are the minimum.
What the proposal would change
The proposed rule would remove the distinction between required and addressable implementation specifications. Today a practice can document why it chose not to implement an addressable control. Under the proposal, with narrow exceptions, everything is required. The specific items that would matter most for a small or mid-sized practice:
| Proposed requirement | What it means in practice |
|---|---|
| Technology asset inventory and network map | A written list of every system, device and application that creates, receives, stores or transmits ePHI, and a diagram of how data moves |
| Multifactor authentication | Required for access to ePHI systems, with limited exceptions |
| Encryption at rest and in transit | Required, not addressable; laptops, phones, backups and email included |
| Vulnerability scanning and penetration testing | Scans at least every six months; penetration test at least annually |
| Restore within 72 hours | Written procedures to restore critical systems and data within 72 hours of a loss |
| Annual compliance audit | A yearly review of compliance with each standard |
| Business associate verification | Written verification from each business associate, at least annually, that it has deployed the required safeguards |
| Workforce access termination | Access removed within one hour of termination; other covered entities notified within 24 hours when applicable |
The final rule may soften some of these. Comments from provider groups argued hard against the annual penetration test and the 72-hour restoration standard for small practices, and the December 2025 coalition letter argued that the whole approach was unworkable for small providers. But we would be surprised if multifactor authentication, encryption and the asset inventory do not survive in something close to the proposed form, because those are the controls OCR already asks about in every investigation.
What OCR asks for when it investigates
A breach report or a complaint triggers a data request from OCR, and the requests are consistent enough that we can describe them. The practice is asked for its most recent risk analysis and the one before it, the risk management plan that came out of the analysis, its policies and procedures for access control and audit review, evidence of workforce training with dates and attendance, the list of business associates with signed agreements, and the incident response documentation for the event being investigated. Every settlement announced under the risk analysis initiative reads the same way: the practice either had no risk analysis, had one that covered only the EHR, or had one that was several years old.
That list is a useful mirror. If you could not assemble those documents in a week, you are not compliant with the current rule, and the final rule is not your most pressing problem.
Seven steps to take this spring
- Do a real risk analysis. Not a checklist from a vendor. An enterprise-wide analysis that lists where ePHI lives, the threats to each location, the likelihood and impact of each, and the controls in place. Date it and sign it. If your last one is more than a year old or was done before you changed EHRs, it is not current.
- Build the asset inventory. Every workstation, laptop, phone, tablet, server, network device, cloud application and vendor connection. Include the personal phones that receive work email. This is tedious and it is the foundation for everything else.
- Turn on multifactor authentication for the EHR, the practice management system, email, the clearinghouse portal, payer portals, remote access and the bank. Most of these support it already at no charge.
- Encrypt every portable device and confirm the EHR vendor and clearinghouse encrypt data at rest. Ask for it in writing.
- Test a restore. Backups that have never been restored are a hope, not a control. Restore one day of data to a test environment and time it.
- Review business associate agreements. Make a list of every vendor that touches ePHI, confirm there is a signed BAA for each, and ask each one for a current SOC 2 report or equivalent. Vendors that cannot produce one are your biggest risk.
- Write the termination procedure. Who removes access when someone leaves, within what time, and who confirms it. Then run it the next time someone leaves and note how long it took.
A realistic timeline for a practice of eight to twelve providers with an outside IT firm: the asset inventory takes two to three weeks of part-time effort, the risk analysis another three to four weeks once the inventory exists, and the technical steps (MFA, encryption, restore test) can run in parallel over the same period. The whole program is a quarter of work, mostly by the practice manager and the IT vendor, and most of the cost is time rather than software.
Why small practices are being targeted
Attackers have learned that a 12-provider practice has the same kinds of data as a hospital and a fraction of the defenses. The common entry points we see in incident reviews are a phishing email that captures an email password without multifactor authentication, a remote desktop connection left open to the internet, and a vendor whose own systems were compromised. None of those require sophistication to prevent. The breach notification rule requires notice to affected individuals within 60 days and to HHS, and for breaches affecting 500 or more people the practice ends up on the public breach portal. The reputational cost in a small community is larger than the fine.
The vendor route is the one that has grown most. A practice can do everything right and still have its patient data exposed because a transcription service, a billing clearinghouse or a scheduling tool was breached. You cannot control the vendor's security, but you can control how many vendors have your data, whether each has signed a BAA, and whether you asked for evidence of their controls before signing.
What this means for revenue cycle work
Billing is where ePHI moves the most: claim files to the clearinghouse, remittances back, eligibility queries, statements to patients, spreadsheets emailed to the payer for a reprocessing project. Every one of those is in scope. The habits that matter are encrypted file transfer to the clearinghouse (not email), no patient data in unencrypted spreadsheets, payer portal access under individual logins with MFA, and a BAA with the billing company. When practices ask what we do on our side, the answer is that Revelrex operates as HIPAA compliant and SOC 2 compliant and signs a business associate agreement with every client. Ask the same of everyone who touches your claims.
The reprocessing spreadsheet is the habit we see broken most often. A biller finds forty underpaid claims, builds a spreadsheet with patient names, dates of service and claim numbers, and emails it to the payer's provider relations representative. That is a disclosure of PHI through an unencrypted channel, and it happens in practices that are otherwise careful. Use the payer's secure portal, or encrypt the file and send the password separately, and write that down as the procedure.
Questions we hear
Should we wait for the final rule before spending money?
No. Every item in the seven steps is required or expected under the current rule as OCR enforces it, and none of them will be wasted under the final rule. The only things worth waiting on are the specific frequencies (how often to scan, how often to test) that the final rule may adjust.
Our IT company says we are compliant. Is that enough?
Ask them for the risk analysis document, the asset inventory and the last restore test result. If those exist and are dated within the year, you are in decent shape. If the answer is a certificate or a badge, be careful; there is no government HIPAA certification and OCR does not recognize one.
How much of this is a legal question?
The obligation to comply is legal. The controls are operational. This article is operational guidance; for questions about your specific obligations or a suspected breach, talk to a healthcare attorney. Our RCM audit includes a review of how ePHI moves through the billing process, which is a useful input to the risk analysis but not a substitute for it.
What to do this week
- Find your most recent risk analysis and check its date and scope. If it is older than a year or covers only the EHR, schedule a new one.
- Turn on multifactor authentication for email and the EHR if either is still without it.
- Start the asset inventory with a walk through the office: every device that touches patient data, on one sheet.
- List every vendor that receives ePHI and mark which ones have a signed business associate agreement on file.
- Ask the billing team how the last payer reprocessing spreadsheet was sent, and fix the channel if the answer is email.
