The HIPAA Security Rule Just Changed: What Every Covered Entity Needs to Understand

The HIPAA Security Rule has not seen a significant overhaul since it was finalized in 2003. That is about to change. HHS published proposed updates in early 2025 that are moving toward finalization in 2026, and the changes are not cosmetic. They represent the most substantial revision to the Security Rule in two decades - and they affect every covered entity and business associate, regardless of size.

If your practice participates in MIPS, the updates compound the PI requirements we've already discussed. But even if MIPS doesn't apply to you, these changes affect your HIPAA obligations directly.

THE END OF "ADDRESSABLE" SPECIFICATIONS

The most significant structural change is the elimination of the distinction between "required" and "addressable" implementation specifications.

Under the current rule, "addressable" specifications could be skipped if a covered entity documented a reasonable alternative - or decided the measure simply wasn't applicable. In practice, this gave organizations significant flexibility to avoid implementing controls like encryption by arguing they were unnecessary for their environment.

That flexibility is ending. Under the updated rule, all implementation specifications become required. There are no more addressable carve-outs. Every covered entity must implement:

- Encryption of ePHI, both at rest and in transit

- Multi-factor authentication (MFA) for access to systems containing ePHI

- Network segmentation to limit exposure if a breach occurs

- Formal incident response plans that are documented, implemented, and tested annually

- Audit controls with defined review intervals

For practices that have relied on "addressable" status to avoid encryption or MFA, this is a material change that requires immediate attention.


ANNUAL SECURITY RISK ASSESSMENTS - REQUIRED, NOT SUGGESTED

The proposed rule eliminates ambiguity about how often an SRA must be conducted. It mandates a documented, comprehensive Security Risk Analysis every 12 months, full stop. There is no longer a "when circumstances change" escape hatch that organizations have sometimes used to justify multi-year gaps between assessments.


This aligns directly with the MIPS PI requirement - your annual MIPS SRA and your annual HIPAA Security Rule SRA are now the same obligation, reinforced from two directions.


BUSINESS ASSOCIATE OVERSIGHT GETS TEETH

Under the updated rule, a signed Business Associate Agreement is necessary but no longer sufficient. Covered entities must obtain written verification, at least annually, confirming that their business associates have actually implemented the required technical safeguards.

This means practices need to actively track their BAs, understand what systems each one accesses, and obtain documented confirmation of their security posture. A BAA filed in a drawer and never revisited is a compliance gap - and potentially a significant liability if a BA is involved in a breach.

STRICTER BREACH NOTIFICATION TIMELINES

The updated rule tightens breach notification requirements for business associates, with a 24-hour notification window to covered entities following discovery of a breach. This compressed timeline means your incident response plan - and your BA oversight processes - need to be ready to move quickly.

WHAT "REASONABLE AND APPROPRIATE" MEANS NOW

The Security Rule has always required that security measures be "reasonable and appropriate" given the size, complexity, and resources of the organization. That standard remains, but the proposed rule makes clear that it cannot be used to justify the absence of fundamental controls like encryption and MFA. Small practices are not exempt from these requirements - they may have a longer runway to implement them, but the destination is the same.

WHEN DOES THIS TAKE EFFECT?

The final rule is expected in mid-2026. Once published, covered entities and business associates will have 240 days to comply. That means practices need to be thinking about these changes now - not waiting for the effective date to begin assessing what needs to change.

THE CONNECTION BACK TO YOUR SRA

Here is the practical implication: if your 2026 Security Risk Assessment does not account for the updated Security Rule requirements, it is already incomplete. An SRA conducted against the old framework will miss the new required controls. Your assessment needs to be built around where the rules are going, not just where they have been.

Chirpy Bird's SRA platform and full-service offering are built around current HIPAA Security Rule requirements - including the 2026 updates. Our reports are designed to satisfy OCR documentation standards and give your practice a clear, actionable picture of where you stand and what needs to change. Schedule a consultation or start your DIY assessment.

Previous
Previous

The Operational Checks Smart ACOs Are Running Now

Next
Next

Operational Discipline Will Matter More Under LEAD