What Changed in 2026: The Dual Attestation Requirement You Can't Afford to Miss

What Changed in 2026: The Dual Attestation Requirement You Can't Afford to Miss

For years, the MIPS Security Risk Analysis measure asked one question: did you conduct a risk assessment this year? A "yes" kept your Promoting Interoperability score intact. A "no" zeroed it out.

Starting with the 2026 performance year, that single question became two. And the second one is where practices are going to get caught.

The New Attestation

CMS's 2026 QPP Final Rule amended the Security Risk Analysis measure to require clinicians to attest to both of the following:

  1. They conducted a security risk analysis in accordance with the HIPAA Security Rule during the 2026 performance period.

  2. They conducted security risk management activities - meaning they identified risks and vulnerabilities and implemented security measures to address them.

The second attestation is not a formality. It reflects a fundamental shift in what CMS (and HHS's Office for Civil Rights) considers a compliant security program. Identifying risks without addressing them is no longer enough. You need to show your work.


What "Risk Management Activities" Actually Means

Under the HIPAA Security Rule, risk management means implementing security measures sufficient to reduce identified risks to a reasonable and appropriate level. In practical terms for 2026, this means:

  • Your SRA identified specific vulnerabilities - unpatched software, gaps in access controls, inadequate encryption, weak authentication, uncontrolled third-party access.

  • You documented a plan to address those vulnerabilities, with assigned owners and timelines.

  • You took action on that plan and can show evidence of it.

A spreadsheet listing potential risks with no follow-through does not satisfy this requirement. A consultant's report filed in a drawer does not satisfy it. What satisfies it is a documented, traceable record showing that your practice found problems and fixed them - or has a credible, active plan to do so.


The SAFER Guide Update

The 2026 rule also replaced the High Priority Practices SAFER Guide requirement. Prior years referenced the 2016 edition. Beginning in 2026, practices must use the 2025 edition of the High Priority Practices SAFER Guide for their annual EHR safety self-assessment.

This is not a minor update. The 2025 SAFER Guides reflect current cybersecurity threats and EHR use patterns. Practices still working from outdated assessments or templates built around the 2016 guide need to update their approach.

A "no" attestation to the SAFER Guide measure - like a "no" on the SRA measure - results in a zero score for the entire PI performance category.


Why This Matters Beyond MIPS

The dual attestation requirement mirrors exactly what the OCR has been enforcing through its Risk Analysis Initiative, which has resulted in more than a dozen enforcement actions since late 2024. The OCR's position is consistent: organizations that conduct risk assessments but fail to act on them are not in compliance with the HIPAA Security Rule. The formal rule change simply codifies in MIPS what the OCR has already been enforcing in the field.

In other words, passing your MIPS attestation and passing an OCR audit now require the same thing: evidence that you found your security vulnerabilities and did something about them.


What a Compliant SRA Looks Like in 2026

A compliant Security Risk Assessment for 2026 should:

  • Cover all systems that create, receive, maintain, or transmit ePHI

  • Identify specific threats and vulnerabilities - not generic categories

  • Assess the likelihood and impact of each risk

  • Document a risk management plan with remediation steps

  • Produce reports that demonstrate both the assessment and the follow-through

  • Be conducted within the 2026 calendar year (January 1 - December 31)

That last point deserves emphasis. You cannot carry forward a 2025 assessment. The SRA must be performed during the performance year in which you attest.

The Clock

December 31, 2026 is the deadline. Practices that begin this process in Q4 routinely underestimate how long it takes to gather the information, work through the assessment thoroughly, and produce documentation that would hold up to scrutiny. Starting now leaves room to do it right. Starting in November leaves room to panic.

Chirpy Bird's DIY tool walks your practice through a comprehensive, HIPAA-aligned Security Risk Assessment at your own pace -with structured questions, built-in guidance, and the audit-ready reports you need for both CMS attestation and OCR compliance. Prefer to hand it off entirely? Our full-service option puts our privacy and security experts to work for you, delivering a complete assessment, issue report, remediation recommendations, and the full documentation package. Either way, you get the reports. Start your SRA today →


Previous
Previous

Healthcare Leaders Are Carrying More Operational Anxiety Than They Discuss Publicly

Next
Next

The Mid-Year APP Plus Validation Framework