HIPAA Tip: HIPAA in 2026
As you may be aware, the Notice of Proposed Rule Making (NPRM) for the HIPAA Security Rule was issued in December 2024. Public comment period closed in March 2025, allowing anyone to voice their concerns on the proposals made to change or amend the original HIPAA Security Rule. Since that time to present we have seen no changes to the original Rule.
With a new year ahead of us the HHS Office for Civil Rights (OCR) is expected to push significant changes to the HIPAA Security Rule in 2026, with a final rule targeted for May 2026. Instead of denying changes are coming move your healthcare organization forward by enabling the following security measures:
- Enhanced Risk Management: once the annual HIPAA Security Risk Analysis (SRA) is completed, follow up on the areas with medium and high risks right away. Create a checklist with the most critical risks or vulnerabilities, set target dates to address and put into motion necessary changes, and revisit the risk level once security measures are put into place (has this successfully mitigated the risk?).
- Multifactor Authentication (MFA): whenever possible add another security layer of protection with MFA, ensuring only authorized personnel access ePHI. Use MFA on what? Remote access to the EMR/PM or servers located in the organization, accessing emails from cell phones, even logging into a cloud solution from the business environment.
- Vulnerability Scans: security assessments that identify weaknesses in networks, systems and medical devices protect ePHI and ensure HIPAA compliance. Scans should cover internal networks, external-facing applications, cloud services and medical devices connected to the network.
Focus efforts on Cybersecurity Awareness, mitigating hacking and ransomware attacks.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.