Skip links
Many stacked documents on a table.

The 2026 HIPAA Security Rule Isn’t Law Yet. Here’s What’s Actually Going On.

Published on: August 3, 2026

Your business may have seen headlines about a new HIPAA Security Rule taking effect in 2026, you’re not wrong to pay attention, but you also don’t need to panic yet.

Here’s what’s actually going on. In January 2025, the Department of Health and Human Services published a Notice of Proposed Rulemaking outlining an update to the HIPAA Security Rule. The public comment period for response input closed in March 2025. Since then, HHS has been reviewing feedback, and more than 100 hospital and provider organizations have formally asked the agency to withdraw the proposal altogether, citing the cost of implementation especially for smaller institutions as the number one reason for rejection. As of mid 2026, no final rule has been issued. Federal timeline estimates now point to mid 2027 before this becomes enforceable law, and that date has already been pushed back once.

So why write a blog about it now? Because everything in the proposal is good practice for your business today. Annual risk assessments, encryption, multi factor authentication, and vulnerability testing aren’t waiting on a federal deadline to be worth doing. They’re the same things the Office for Civil Rights already cites most often when investigating a breach under the current rule.

This blog isn’t a countdown clock. It’s a checklist worth working through either way, so if the rule does become law, you’re not scrambling. And if it doesn’t, your business can have the utmost confidence that you are protecting your patient’s valuable information.

Still Worth Preparing For, Even If It’s Not Law Yet

Here’s the part that trips a lot of businesses up. Just because something is proposed instead of a finalized law, doesn’t mean it’s irrelevant. The Office for Civil Rights enforces the current HIPAA Security Rule, and its enforcement actions over the past few years point in one direction. Risk analysis failures. Weak access controls. Missing encryption. These are the same issues popping up again and again in settlements and penalties. These are the same issues the proposed rule is trying to make explicit rather than optional.

Put another way: nothing in this proposal is a surprise. It’s a formal version of what OCR has already been asking for. Getting ahead of it isn’t about beating a deadline. It’s about closing gaps that are already worth closing on your own timeline instead of a rushed one. That’s the mindset behind the checklist below. Treat it as a gap check for your medical practice today, not a last second rush whenever the rule finally passes.

What the Proposed Rule Would Actually Require

Annual Security Risk Assessments

Right now, the current rule requires a risk assessment but doesn’t say how often. A lot of medical practices interpret that gap generously, running one every few years or updating an old document instead of starting fresh. The proposed rule would close that loophole and require a full risk assessment every 12 months, reflecting your current systems, vendors, and workforce, not last year’s setup.

Encryption of ePHI at Rest and in Transit

Today, encryption is technically “addressable,” meaning a medical practice can document why it chose not to encrypt something instead of actually encrypting it. The proposed rule would remove that option entirely. Every system that stores or transmits patient data would need full encryption.

This is one area where a lot of practices are closer to compliant than they may know, especially if their office equipment is doing more of the work than they give it credit for. Sharp, Lexmark and Konica Minolta all encrypt data as soon as it hits the hard drive. If someone pulled the drive out of the machine, the data on it would be unreadable without the device itself. Both brands also make sure that data is fully wiped when it’s erased or when a device is retired, so nothing sensitive is left behind. This encryption already standard on the equipment sitting in a lot of offices today.

Access Control and the Road to MFA

The proposed rule would make multi-factor authentication a requirement rather than a recommendation for any system touching patient data. That’s a bigger conversation than any one device can solve on its own, since systems include your electronic health records, your email, your remote access, and more.

But it’s worth noting that device level access control is part of that same picture. Both Sharp and Konica Minolta devices require admin authentication and support secure print release, so jobs don’t sit exposed in an output tray waiting for the wrong person to grab them. It’s a smaller piece of a bigger requirement, but it’s one less gap to close.

Vulnerability Scanning and Penetration Testing

These are two different things. Vulnerability scanning is an automated scan of your network looking for known weak spots, like an unpatched system or an exposed service. Penetration testing is a person actually trying to break in, the way a real attacker would, to see what a scan alone might miss. The proposed rule calls for regular vulnerability scans and an annual penetration test.

This isn’t something MMIT performs directly, but it’s something we help clients get right. We work with trusted testing partners who specialize in this exact kind of assessment, so you’re not left trying to find a reputable vendor on your own or guessing whether a scan actually covered what it needed to.

Asset Inventory and Network Mapping

You can’t protect what you don’t know you have. The proposed rule would require a current, accurate list of every device, system, and application that touches patient data, along with a map of how they all connect. That includes obvious things like servers and workstations, but also the stuff that gets forgotten: old laptops, mobile devices, cloud storage, even that one machine still running in the back office nobody remembers setting up. The process of mapping out these devices is easier said than done for most businesses.

Documentation That Holds Up

Having a security policy isn’t the same as proving it works. The proposed rule raises the bar here significantly. It’s no longer enough to have a written policy sitting in a drawer. You need to show that the policy is followed, that staff are trained on it, and that gaps get tracked and fixed instead of just noted and forgotten.

In an OCR investigation, undocumented security is treated the same as no security at all, even if the practice itself is behaving safely. If it’s not written down, it didn’t happen.

Annual Vendor and BAA Verification

Every practice already knows to have a signed Business Associate Agreement with vendors who touch patient data. What’s changing is the expectation to verify it. The proposed rule would require practices to confirm, in writing, that vendors have the safeguards they claim to have, not just keep a signed agreement on file and hope for the best.

If you work with an IT provider, a billing company, or a cloud vendor, this is a good moment to ask them directly what they can prove, in writing, not just what they tell you they can protect.

Where MMIT Fits Across the Board

Sharp, Lexmark and Konica Minolta devices handle encryption and access control at the hardware level, standard, not as an upgrade. If you believe your printer or copier does not fit encryption protocol we can help confirm and get you looking at the correct device for your business.

Document management and storage solutions are built to keep patient records encrypted and access controlled long after they leave the printer. And for the pieces we don’t handle directly, like penetration testing and vulnerability scanning, we connect you with partners who specialize in exactly that, so you’re not left figuring it out alone.

Want to See Where Your Business Stands?

You don’t need to wait for a final rule to find out if you’re covered. MMIT offers a free IT assessment for practices that want to see where they stand against these proposed requirements. No pressure, no sales pitch, just a clear look at what’s already working and what might need attention. If your team wants to feel confident you’re checking the right boxes, that’s exactly what it’s there for.