The HIPAA Security Rule has always distinguished between required and addressable implementation specifications. Required means do it. Addressable means assess whether it is reasonable and appropriate, and if not, document why and implement an equivalent alternative. In practice, addressable has often been read as optional — and the proposed modernisation of the rule is aimed squarely at that reading.
What is changing
- Encryption of electronic protected health information at rest and in transit, moving from addressable to expected.
- Multi-factor authentication for access to systems holding ePHI.
- Asset inventory and network mapping — you cannot protect what you have never listed.
- Network segmentation, so a compromised front-desk workstation does not reach the clinical system.
- Tighter timelines for restoring systems and for verifying that business associates have implemented safeguards.
Why the risk analysis still comes first
Whatever the final text, the risk analysis remains the control that regulators ask about before any other. Enforcement actions are full of organisations that had firewalls, antivirus and policies, but had never performed an accurate and thorough assessment of risks to ePHI across the whole environment. A risk analysis that covers only the electronic health record, and not the imaging system, the backup vendor and the practice management laptops, is the finding waiting to happen.
Business associates are your exposure too
A signed Business Associate Agreement transfers obligations, not consequences. If a vendor loses your patient data, your patients and your regulator will start with you. The practices that handle this well keep a short vendor register, ask for evidence rather than assurances, and revisit it annually — not at renewal, when the leverage is gone.
Preparing without waiting
Almost everything in the proposed changes is something a well-run practice would want anyway. Encrypting laptops, enforcing MFA, knowing what is on the network and segmenting clinical systems are not compliance theatre; they are the controls that would have stopped most of the breaches in the enforcement record. Starting now converts a future deadline into work you have already done.
This article is general information about the HIPAA Security Rule, not legal advice. Confirm obligations for your organisation with counsel.
Go deeper
HIPAA Security Rule 2026: Compliance for Healthcare Practice
The HIPAA Security Rule is being rewritten to remove the “addressable” escape hatch that practices have leaned on for two decades. This course covers what compliance looks like now — and what changes when the update lands.

Leave a Reply