Try Interactive Demo
No-code database platforms are transforming the way web apps are…
Template Marketplace
Use Knack’s Patient Portal Template to give patients, providers, and…
Knack’s Telemedicine App Template gives healthcare providers, clinics, and independent…
Knack’s Patient Intake Form Template helps healthcare teams digitally collect…

What the 2026 HIPAA Security Rule Update Means for Small Teams

  • Written By: Samantha Suser
What the 2026 HIPAA Security Rule Update Means for Small Teams

What the Proposed 2026 HIPAA Security Rule Update Means for Small Healthcare Teams

The HIPAA Security Rule has not been substantially updated since 2013. In January 2025, HHS proposed the most significant overhaul in more than two decades. The hipaa security rule update 2026 conversation has dominated healthcare compliance circles ever since. Before you change anything about how your organization operates, here is the honest breakdown: the proposed rule is not yet law. OMB moved the finalization target to July 2027. The current Security Rule is still what OCR enforces today.

Key takeaways

  • The proposed HIPAA Security Rule update (NPRM published January 6, 2025) would make encryption of electronic protected health information mandatory, removing the current “addressable” flexibility.
  • Multi-factor authentication (MFA) would be required for all access to ePHI systems. The proposal makes no size exceptions for smaller organizations.
  • As of August 2026, the rule is still proposed, not final. OMB’s Unified Agenda (RIN 0945-AA22) targets July 2027 for final action.
  • OCR continues enforcing the current Security Rule. Incomplete or missing risk analysis remains the most frequently cited deficiency in OCR investigations.
  • Once a final rule publishes, covered entities and business associates would have 240 days to comply: 60 days until effective, then 180 days to the compliance deadline.
  • Small healthcare organizations already running HIPAA-compliant infrastructure, with encryption, role-based access controls, and audit logs built in, have a head start regardless of when the rule finalizes.

What Is the Proposed HIPAA Security Rule Update?

The proposed HIPAA Security Rule update is an overhaul of the 2003 Security Rule. If you are new to HIPAA compliance fundamentals, start there before diving into the proposed updates. HHS’s Office for Civil Rights issued the Notice of Proposed Rulemaking in December 2024. The Federal Register published it on January 6, 2025. Two main factors drove it: a sharp rise in healthcare data breaches and a Security Rule that had gone more than two decades without a substantive update. HHS received approximately 4,700 public comments in response. The agency is still reviewing them.

The core issue the proposal addresses is flexibility. The current Security Rule allows covered entities to document a reason for not implementing certain “addressable” controls, including encryption of ePHI at rest. The proposal would close that flexibility. It would eliminate the “required vs. addressable” distinction and make every major implementation specification a hard requirement. It would also add new mandates for multi-factor authentication, technology asset inventory, and penetration testing.

What Would Change Under the Proposed Rule?

The proposed hipaa security rule update 2026 would affect every covered entity and business associate, regardless of size. Here is what small healthcare teams should know about each major proposed change.

Encryption becomes mandatory

Under the current Security Rule, encryption is “addressable.” Organizations can document why encryption is unreasonable and implement an equivalent alternative instead. The proposed rule would eliminate that option entirely. Encryption of ePHI at rest and in transit would become a hard requirement with no documented-alternative path.

Organizations already on HIPAA-compliant platforms with encryption built into the infrastructure would face no additional burden here. Organizations storing patient data in unencrypted spreadsheets, shared drives, or standard SaaS tools without HIPAA plans face a significant gap to close.

Multi-factor authentication for all ePHI access

Under the current rule, MFA is a best practice but not an explicit mandate. The proposed rule would make it a specific technical safeguard requirement. That applies to every user who can access patient data: front desk staff, billing coordinators, remote care teams, and clinical staff alike.

This is operationally significant for small healthcare teams. Organizations running single-password logins on patient management tools, scheduling platforms, or intake systems would need MFA in place before the compliance deadline.

Asset inventory and network documentation

The proposed rule would require a current, accurate inventory of every technology asset that creates, receives, maintains, or transmits ePHI. Hardware, software, cloud services, and connected devices would all need to appear in that inventory. Organizations would also need documented maps of how ePHI flows across their systems, including flows to business associates and third-party tools.

For small healthcare teams running a mix of tools, this documentation requirement is often the hardest to meet from scratch. An EHR here, a scheduling app there, a custom intake form in another system: each one is a line in the inventory.

Annual penetration testing

Under the current rule, covered entities must conduct risk analysis, but the specific methods are not prescribed. The proposed rule would make penetration testing an explicit, annual requirement rather than one option among many for satisfying the risk analysis standard. Organizations would need to schedule and document it annually.

72-hour internal incident reporting

The proposed rule would require organizations to report security incidents internally within 72 hours. This is separate from the current Breach Notification Rule’s 60-day window for notifying affected individuals. The 72-hour requirement is an internal operational trigger, not a public disclosure deadline.

Enhanced business associate oversight

The proposal would require covered entities to verify annually that business associates have implemented the required technical safeguards. Under the current rule, a signed Business Associate Agreement has generally served as the compliance anchor. That would no longer be sufficient on its own.

What Has Not Changed: The Current Security Rule Is Still in Force

The most important thing to understand about the hipaa security rule update 2026 is that none of the proposed changes are enforceable yet. OCR continues to enforce the Security Rule as it has existed since 2003. The NPRM remains a proposal, and the current rule governs until a final rule takes effect.

OCR’s enforcement record in 2025 was the second-highest on record: 21 settlements and civil monetary penalties. The most frequently cited deficiency in those investigations was incomplete or missing risk analysis. That is a current-rule requirement. It has nothing to do with the proposed update.

Small healthcare teams should treat the proposed rule as a directional signal, not a compliance deadline that has already arrived.

Why the Proposed Rule Has Faced Pushback

The hipaa security rule update 2026 proposal attracted substantial opposition. A coalition of more than 100 hospital systems and provider organizations formally asked HHS to withdraw it. The core objection was cost. HHS’s own Regulatory Impact Analysis estimated approximately $9 billion in year-one industry compliance costs, with roughly $6 billion annually for years two through five. Small and rural providers raised specific concerns about absorbing those costs on thin margins.

The final rule could be finalized roughly as proposed, finalized with material modifications, delayed further, or withdrawn entirely. OMB’s Unified Agenda currently targets July 2027. That timeline is not legally binding, and it has already shifted once from an earlier May 2026 target.

What the 240-Day Compliance Window Means in Practice

If a final rule publishes, covered entities and business associates would have 240 days to comply. The clock runs from the publication date: 60 days until the rule takes effect, then 180 days to the compliance deadline. BAA updates would get a separate and longer transition period.

For a small healthcare team that has not yet implemented encryption, MFA, asset documentation, or a documented risk analysis, 240 days is a tight window. Each of those controls takes time to procure, configure, document, and train staff on. Organizations that start closing these gaps now, regardless of when the final rule arrives, will be in a materially better position than those waiting for a finalization date.

A compliance dashboard showing HIPAA security settings with encryption and MFA toggles enabled, representing the proposed 2026 HIPAA Security Rule update requirements for small healthcare teams.

What This Means for Small Healthcare Teams Specifically

The proposed hipaa security rule update 2026 would apply uniformly to all covered entities and business associates, regardless of size. A solo practice, a home care agency, and a small health system would face the same technical safeguard requirements as a large hospital system. The compliance burden scales with IT environment complexity, not with organizational size.

For many small healthcare teams, the most practical response is not to wait for finalization. Teams focused on healthcare workflow automation will find that the compliance controls and the workflow improvements often overlap: the same platform that automates intake and scheduling is the one that needs to provide encryption, audit logs, and role-based access. Instead, close the gap between your current setup and the proposed standard now. The controls that would be newly mandated under the proposal, encryption, MFA, audit logging, documented risk analysis, role-based access, are already the baseline that HIPAA-compliant platforms provide today.

Build on infrastructure that already meets the proposed standard

One efficient path for small healthcare teams is to run operations on a platform that provides these safeguards at the infrastructure level, so the team handles none of them separately. Knack Health includes encryption at rest and in transit, role-based access controls, record change tracking, and a signed BAA on every HIPAA plan. The technical safeguards that would be mandatory under the proposed rule come built into the platform rather than as separate vendor relationships to manage.

Teams building custom apps, patient registries, intake workflows, or internal tracking tools inherit the compliance posture of whatever platform they build on. For teams that have been relying on spreadsheets or general-purpose no-code tools without HIPAA plans, this is especially relevant: those environments typically cannot meet even the current Security Rule’s requirements.

Document what you have and close the asset inventory gap

Even before any final rule, covered entities must conduct and document risk analysis under the current Security Rule. That documentation should include a current list of every tool, system, and vendor that touches ePHI. Building that inventory now achieves two things at once. First, it satisfies an existing requirement that OCR consistently cites as a deficiency. Second, it positions your organization to respond quickly if the proposed asset inventory requirement finalizes.

Prioritize MFA on every ePHI-touching system

MFA is the most operationally significant change in the proposed rule for small healthcare teams. It is also one of the most achievable. Organizations that have not yet enabled MFA on patient management tools, scheduling systems, and intake platforms should treat it as a near-term action item. The proposed rule’s finalization timeline does not change that calculus.

Revisit your BAA checklist

The proposed rule would require annual verification of business associate safeguards, not just a signed BAA. Even under the current rule, vendor compliance posture can shift in ways that affect whether a signed BAA is backed by actual technical safeguards. An annual BAA review is good practice now. The Knack Health Business Associate Agreement explainer covers the full BAA management framework.

Is Knack Health Already Aligned to the Proposed Standard?

The proposed hipaa security rule update 2026 would require encryption at rest and in transit, role-based access controls, record change logs, MFA capability, and a signed BAA. Knack Health provides all of these on every HIPAA plan. SOC 2 Type II certification provides independent third-party verification of the platform’s security controls.

FAQ

Is the 2026 HIPAA Security Rule update already in effect?

No. As of August 2026, the proposed HIPAA Security Rule update is not in effect. HHS published a Notice of Proposed Rulemaking on January 6, 2025, and the public comment period closed on March 7, 2025. OCR is still reviewing approximately 4,700 public comments. OMB’s Unified Agenda targets July 2027 for a final rule. The current Security Rule remains fully in effect, and that is what OCR enforces today.

Under the current Security Rule, implementation specifications carry one of two labels. A “required” specification must be implemented as stated. An “addressable” specification must be implemented, or an equivalent alternative documented, or non-implementation formally recorded as not reasonable given the organization’s circumstances. Encryption of ePHI at rest is currently addressable. The proposed 2026 update would eliminate that distinction. Every major implementation specification would become required, with no alternative path.

Yes. The proposed HIPAA Security Rule changes would apply to all covered entities and business associates, regardless of size. A solo practice and a large health system would face the same technical safeguard requirements. How those requirements get met may look different: a solo practice might use a HIPAA-compliant cloud platform rather than an on-premises server environment. The standards themselves are uniform either way.

The proposed rule specifies a 240-day window from publication of the final rule. The rule becomes effective 60 days after publication, and compliance is required 180 days after that. BAA updates would have a separate, longer transition period. These timelines reflect the proposal as written. A final rule could modify them.

The most useful actions close gaps under the current Security Rule and align to the proposed standard simultaneously. A HIPAA-compliant patient portal or intake workflow built on Knack Health satisfies these requirements without requiring a separate technical safeguard implementation for each tool. The HIPAA compliance checklist for no-code teams covers each requirement in detail.

Knack Health already provides the core technical safeguards the proposed rule would require: encryption at rest and in transit, role-based access controls, record change logs, and a signed BAA.