HomeBlogCompliance & regulatory

Compliance

HIPAA Security Rule changes: what PT practices do now

HHS pushed its Security Rule overhaul to July 2027. The proposed floor, MFA, encryption, 72-hour recovery, is still the standard your practice will be held to.

The Orion team 5 min read
Abstract illustration of a shield-shaped lattice assembling around a cluster of records while an hourglass stands beside it

The short version

  • HHS moved the HIPAA Security Rule overhaul to its long-term list. Final action is now targeted for July 2027, about a year later than planned.
  • The proposal makes encryption, MFA, a technology asset inventory, and 72-hour recovery mandatory, ending the era of 'addressable' safeguards.
  • The current Security Rule still applies, and OCR keeps investigating under it. The delay buys preparation time, not permission to wait.
  • Most of the proposed checklist is your software vendor's job. Get their answers in writing before you buy or renew.

The biggest healthcare cybersecurity rule change since 2013 just slipped a year, and most of outpatient therapy never heard it move. In its latest regulatory agenda, HHS quietly shifted the HIPAA Security Rule update onto its “Long-Term Actions” list and penciled in July 2027 for final action. The old target was May 2026. Law firms tracking the docket, including Clark Hill, flagged the slip in mid-July.

For a PT practice owner, a year of slack on a federal deadline sounds like a reason to file this under later. It is the opposite. The delay is the one window you will get to meet the new floor on your own schedule and your own budget. The alternative is meeting it in a scramble, alongside every other covered entity in the country.

What would the HIPAA Security Rule update change?

The short answer: security measures that have been officially optional since 2003 become mandatory. The proposed rule, published in the Federal Register on January 6, 2025, removes the Security Rule’s distinction between “required” and “addressable” safeguards. Today, a small practice can document a reason for skipping encryption. Under the proposal, with narrow exceptions, it cannot.

Per HHS’s own fact sheet, the proposal would require, among other things:

  • Encryption of electronic PHI at rest and in transit
  • Multi-factor authentication, with limited exceptions
  • A written technology asset inventory and a network map, refreshed at least every 12 months
  • Written procedures to restore critical systems and data within 72 hours of losing them
  • A compliance audit at least once every 12 months
  • Vulnerability scans every six months and an annual penetration test
  • Annual written verification that each business associate has its required safeguards deployed

Read that list twice. Nothing on it is exotic. It is what a competent IT person would set up unprompted, which is exactly the problem for a six-provider clinic that does not have one.

Why the delay is not a pass

Three things stay true while the rule sits on the long-term list.

The current Security Rule remains fully in effect; HHS says so in the fact sheet itself. OCR keeps enforcing it, and the proposal exists in the first place because of what the agency calls, in the rule’s own summary, “common deficiencies” it keeps finding in its investigations. The agency even built an enforcement program around the most common one. Its Risk Analysis Initiative, launched in October 2024, had collected nearly $900,000 across eight settlements by spring 2025, per a Wilson Elser analysis. Every one was for failing to assess where PHI was at risk.

The threat has not paused either. HIPAA Journal’s 2025 Healthcare Data Breach Report, compiled from the OCR breach portal, counts at least 61.5 million people whose health information was exposed or impermissibly disclosed last year. That was the good year: it was a 78.7% drop from 2024, the year of the Change Healthcare breach.

And the rule itself may yet shrink. The proposal drew nearly 5,000 comments, and Troutman Pepper Locke reports that a coalition of 100 healthcare organizations wrote to the HHS secretary in December 2025 urging full withdrawal, arguing the rule conflicts with the administration’s deregulatory priorities. Maybe they win and the mandates soften. Before you bank on that, pull your last cyber insurance renewal questionnaire and count how many of these same items are already on it. Insurers stopped waiting for HHS a while ago.

Which safeguards are your job, and which are your EHR’s?

Split the list in two and it stops being intimidating.

Your half is administrative, and none of it requires buying anything. A written risk analysis that names where PHI actually lives in your practice, including the front-desk laptop and the shared drive of scanned intake forms. Access that gets turned off the day a tech leaves, not at the end of the month. MFA on email, since compromised email accounts sat behind roughly a quarter of last year’s large breaches in the same HIPAA Journal data. A one-page plan for the Friday-night scenario: the system is down, Monday is fully booked, who calls whom.

The other half lives inside your software, which means it was decided the day you picked your vendor. Encryption at rest and in transit, MFA on login, audit logs, backups, and that 72-hour restoration window are all engineering, and for a cloud EHR they are the vendor’s engineering. You cannot patch them in from the clinic side. You can only ask, in writing: do you encrypt at rest and in transit, do you enforce MFA, can I export the audit log, what is your tested restore time? Orion’s answers are on the record: signed BAA, encryption both ways, exportable audit log, IP allowlisting included. Any vendor that wants your PHI should be willing to match that in an email you can file.

The annual business associate verification is the sleeper item. If it survives to the final rule, you will be collecting written security certifications every year from every vendor that touches PHI: the EHR, the clearinghouse, the eFax service, and yes, the AI scribe. Start the folder now. The vendors who answer in a day and the ones who go quiet for three weeks are telling you something you want to know before 2027.

What to do before 2027

Book one afternoon this fall. Write or refresh the risk analysis, turn on MFA everywhere it is off, and send the four security questions to every vendor on your PHI list. That afternoon covers most of your half of the proposal and all of the diligence on theirs.

Then treat the answers as data. A vendor that cannot state its encryption posture in writing in 2026 is showing you its 2027. A security gap you cannot close from the clinic side is a fair reason to run the switching math this year.

July 2027 is a target on a government to-do list, and targets on that list have moved before. Build to the checklist anyway. Ransomware crews do not read the regulatory agenda.

Book a live demo

See Orion run your practice.

A PT-specific walkthrough, transparent pricing, and straight answers. Your current EHR stays live the whole time.