HIPAA Security Rule update 2026 DFW medical practices
| |

HIPAA Security Rule Update 2026: What DFW Practices Need To Know

The Proposed HIPAA Security Rule Update: What DFW Medical Practices Need to Know

What’s changing, what isn’t final yet, and what Dallas–Fort Worth medical practices should do now.

Quick answer: HHS has proposed the biggest overhaul of the HIPAA Security Rule in over 20 years, but as of mid-2026 it is still a proposed rule, not final law. The target date for a final rule has already slipped, with the federal Unified Agenda now pointing to July 2027. Nothing is required yet — but the direction is clear: encryption, multi-factor authentication, network mapping, and 72-hour incident recovery are moving from “nice to have” to “mandatory.” DFW medical practices that get ahead of these changes now avoid a scramble later and close gaps that OCR already penalizes under the current rule.

What’s Actually Changing (and What Isn’t, Yet)

In late December 2024, HHS’s Office for Civil Rights proposed sweeping updates to the HIPAA Security Rule — the first major rewrite since the rule was written over two decades ago. The proposal was published in the Federal Register in January 2025, and public comments closed in March 2025.

Since then, federal timelines for finalizing the rule have moved more than once. The most recent federal agenda update pushes final action out to July 2027, and industry groups — including major hospital systems and physician associations — have formally asked HHS to withdraw or significantly narrow the proposal. In short: the rule is not in effect, and OCR is not enforcing it. OCR is still enforcing the existing Security Rule, under which an incomplete or missing risk analysis remains the single most common deficiency cited in investigations.

That said, proposed rules like this rarely disappear entirely. They usually get finalized in a modified form. For a medical office in Plano, Fort Worth, or anywhere in the metroplex, the safest assumption is: build toward these standards now, because most of them are good security practice regardless of whether they become law.

What the Proposal Would Require, If Finalized as Written

  • Mandatory encryption of electronic protected health information (ePHI), both at rest and in transit — no longer an “addressable” (optional) safeguard
  • Multi-factor authentication on any system that touches ePHI
  • A current, accurate network map and asset inventory of every device and system that stores or transmits patient data
  • 72-hour incident reporting and recovery requirements after a security event
  • Annual penetration testing and more frequent vulnerability scanning
  • Tighter oversight of business associates, including IT vendors, billing companies, and cloud platforms

If finalized as proposed, covered entities would likely get roughly 240 days from publication to comply — 60 days until the rule takes effect, plus 180 days to implement most requirements.

Why DFW Practices Shouldn’t Wait for a Final Rule

Two things make this relevant today, not just “someday”:

  1. OCR is already enforcing similar expectations under the current rule. A missing or outdated risk analysis, unencrypted laptops, and no documented incident response plan are among the most common findings in real OCR investigations right now — with or without a new rule.
  2. Small and midsize practices take the longest to get compliant. A 10–25 employee practice in the metroplex doesn’t have an in-house security team. Building an asset inventory, rolling out MFA everywhere, and documenting an incident response plan takes months, not days — so starting after a final rule publishes means starting behind.

A Practical Starting Point for Medical Offices

If you want to get ahead of this without overhauling everything at once, this is the order that pays off fastest:

  1. Run or refresh your risk analysis. This is already required today and is the single most-cited gap in OCR enforcement.
  2. Build a real asset inventory. Every device, server, and cloud system that touches patient data — including anything staff access remotely.
  3. Turn on MFA everywhere it isn’t already. Email, EHR access, remote desktop, admin portals.
  4. Confirm encryption status on all workstations, laptops, backups, and mobile devices.
  5. Document (and actually test) an incident response plan — including who calls whom, and how fast you can report.
  6. Review vendor and business associate agreements for anyone handling PHI on your behalf.

Frequently Asked Questions

Is the new HIPAA Security Rule in effect yet?
No. As of mid-2026, it remains a proposed rule. HHS has pushed the target date for final action to July 2027, and that date could still move again.

Do medical practices have to comply with the proposed changes right now?
No — only the current HIPAA Security Rule is enforceable today. However, several of the proposed changes (encryption, MFA, documented risk analysis) reflect what OCR already expects to see during an investigation.

What’s the biggest HIPAA compliance gap OCR finds in practices today?
An incomplete, outdated, or missing risk analysis is consistently the most common deficiency cited in OCR enforcement actions, independent of the proposed rule changes.

How long would practices have to comply once a final rule is published?
Based on the current proposal, roughly 240 days total — a 60-day effective date plus a 180-day compliance window for most requirements.

What should a DFW medical practice do first?
Start with a current risk analysis and an accurate inventory of every system touching patient data. Everything else — encryption, MFA, incident response — builds on knowing what you actually have to protect.

Not Sure Where Your Practice Stands?

SilverStorm Solutions has supported HIPAA-regulated practices across Dallas–Fort Worth for over 20 years. Get a straightforward read on where your practice stands against both current requirements and what’s coming.


Schedule a Technology Assessment

Related resources:
What IT Services Does a Medical Office Need to Stay HIPAA Compliant? ·
What Happens If My Medical Practice Has a HIPAA Data Breach? ·
Cybersecurity Assessment

#HIPAA #Cybersecurity #Compliance #DFW IT support #Medical Offices

Similar Posts