Back to Blog
April 22, 2026 7 min read

The 2026 HIPAA Security Rule: What Changed and What Your Practice Must Do

The headline change: "addressable" is gone

Under the old rule, many security controls were labeled "addressable," meaning a practice could choose not to implement them as long as it documented a reasonable alternative or justification. The 2026 update removes that flexibility for most core controls — they're now required, full stop, with very narrow exceptions.

The six requirements practices are asking about most

Multi-factor authentication is now required on every system that touches patient data, not just recommended. Encryption is required both for stored data and data in transit, with very limited exceptions. Vulnerability scanning must happen quarterly, and penetration testing annually. A written, tested incident response plan is mandatory, not optional documentation. And every practice needs a current inventory of every device and system that touches PHI.

What happens if you don't comply

Non-compliance exposure comes from two directions: OCR enforcement (fines that, for small practices, have historically ranged from roughly $10,000 to $80,000 depending on severity and circumstances) and the much higher cost of an actual breach — incident response, patient notification, potential lawsuits, and reputational damage that can be fatal to a small practice.

A realistic path to compliance

Most practices don't need to build an internal security team. They need a clear-eyed assessment of where they stand today, a prioritized plan for closing the gaps, and either the in-house discipline or an outside partner to keep it maintained as requirements keep evolving.

If you haven't had a formal assessment against the 2026 rule yet, that's the place to start — and it's free to find out where you stand.

Not sure where your practice stands?

Get a free 30-minute readiness check — no pressure, just clarity on what you need.

Get My Free Readiness Check