Author: Eunoia Consulting Co. | Published: June 10, 2026
The 2026 HIPAA Security Rule converts previously addressable safeguards into mandatory requirements. Encryption at rest and in transit, multi-factor authentication for all ePHI access, and 72-hour breach notification are no longer optional. This guide explains what changed, what it means operationally, and how to prepare before enforcement timelines arrive.
The HIPAA Security Rule has operated for two decades on a framework of "addressable" versus "required" safeguards — a distinction that allowed many healthcare organisations to treat encryption and multi-factor authentication as optional measures, subject to reasonable alternatives. That era is ending. The 2026 update to the HIPAA Security Rule converts several previously addressable safeguards into mandatory requirements, and the implications for healthcare and veterinary practices of every size are significant.
The Department of Health and Human Services has been advancing sweeping revisions to the Security Rule since early 2025. While the final rule missed its original May 2026 deadline, the direction of travel is unambiguous and many organisations are treating the proposed requirements as de facto standards given the enforcement environment.
Mandatory encryption of ePHI at rest and in transit. Electronic protected health information must be encrypted wherever it is stored — on servers, workstations, laptops, mobile devices, and backup media — and whenever it is transmitted across any network. The previous "addressable" status allowed organisations to document an equivalent alternative; that option is being removed.
Multi-factor authentication for all ePHI access. Every user, every session, every system that touches ePHI must use MFA. This applies to EHR logins, email platforms, remote access tools, and any cloud-based system storing patient data. The limited exceptions that existed under prior guidance are significantly narrowed.
72-hour breach notification. The notification window for reporting breaches to HHS is tightening from 60 days to 72 hours for covered entities, bringing HIPAA into alignment with other regulatory frameworks including GDPR.
Defined vulnerability scanning schedules. Organisations must conduct vulnerability scans at defined intervals — not simply "periodically" — and document remediation timelines.
Network segmentation standards. Systems containing ePHI must be logically separated from general business networks, limiting the blast radius of any breach.
Previous HIPAA updates were largely clarifications or enforcement guidance. This update is architectural. Mandatory encryption and MFA are not configuration changes you can implement over a weekend — they require infrastructure assessment, vendor coordination, staff training, and in many cases, hardware replacement.
For practices running legacy EHR systems, the encryption requirement is particularly challenging. Many older systems were not built with encryption at rest as a native feature, and retrofitting encryption onto legacy databases requires careful planning to avoid data corruption or performance degradation.
The MFA requirement similarly touches every workflow where staff access patient data. Practices that have resisted MFA due to workflow friction — a common objection in clinical settings where speed matters — will need to find authentication solutions that balance security with clinical usability.
The 2026 update strengthens requirements for business associate agreements (BAAs). Covered entities must now verify that their business associates implement the same encryption and MFA standards, not simply attest that they have "appropriate safeguards." This means your billing company, your transcription service, your IT vendor, and any other entity handling ePHI on your behalf must be actively assessed — not just contractually obligated.
For practices with large vendor ecosystems, this creates a significant compliance management burden. A structured vendor assessment programme, rather than a one-time BAA review, becomes necessary.
The 2026 requirements land differently depending on your practice's current technology stack and size:
| Practice Type | Highest-Risk Gap | Priority Action | |---|---|---| | Solo/small practice (1–3 providers) | Legacy EHR without native encryption | Confirm encryption status with EHR vendor immediately | | Multi-provider group practice | Inconsistent MFA adoption across staff | Implement MFA via identity provider (Okta, Azure AD) | | Multi-site organisation | Network segmentation across locations | Engage IT security firm for network architecture review | | Veterinary practice | BAA gaps with practice management software vendors | Audit all vendor BAAs for encryption and MFA language |
Practices that begin preparation now will be in a substantially better position than those waiting for final rule publication. A reasonable 90-day preparation sequence looks like this:
Days 1–30: Asset inventory and gap assessment. Identify every system, device, and application that stores or transmits ePHI. Map current encryption status and MFA coverage. Document gaps against the proposed requirements.
Days 31–60: Vendor engagement and remediation planning. Contact your EHR vendor, cloud providers, and key business associates to confirm their compliance posture. Develop a prioritised remediation plan for identified gaps, starting with the highest-risk systems.
Days 61–90: Implementation and documentation. Deploy MFA across all ePHI-touching systems. Confirm encryption at rest and in transit. Update your risk analysis to reflect the new requirements. Train staff on new authentication workflows.
OCR enforcement of HIPAA has intensified in recent years, with settlements and civil monetary penalties reaching record levels. The 2026 update creates a clearer, more objective standard — which historically correlates with more straightforward enforcement actions. Practices that can demonstrate a documented, good-faith compliance programme will be in a far stronger position if a breach occurs than those that cannot.
The 2026 HIPAA Security Rule update is not a distant regulatory concern. It is a present operational requirement that demands action now. Practices that treat it as such will emerge with stronger security posture, reduced breach risk, and a defensible compliance record.
Eunoia Consulting Co. helps healthcare and veterinary organisations design and implement HIPAA-compliant security programmes. Contact us to discuss your compliance readiness.