Here is the short answer: most of what you have heard about for 2026 is still proposed, not law. The HIPAA Security Rule overhaul that has driven the headlines was published as a notice of proposed rulemaking by the HHS Office for Civil Rights in late 2024, and as of mid-2026 it is still proposed. But two things are already true today: federal regulators are enforcing the existing rules harder than ever, and the proposed changes signal exactly where the bar is heading.
So the honest answer to “what do I actually have to worry about” has two layers. Below is a plain-English watchlist of the seven IT and security compliance shifts that matter most for physician practices this year. For each one, we say clearly whether it is proposed or already enforced, so you know what to prepare for versus what to act on now.
1. What is the proposed HIPAA Security Rule overhaul?
The proposed HIPAA Security Rule overhaul is a set of changes that would make many currently optional safeguards mandatory for protecting electronic protected health information (ePHI). It is proposed, not final. As of mid-2026, the Office for Civil Rights has not issued a final rule, and the requirements could still change, be delayed, or be withdrawn.
The single biggest shift is structural: the proposed rule removes the long-standing distinction between “required” and “addressable” safeguards. Under today’s rule, a practice can decide some controls are not reasonable for its size. Under the proposal, nearly everything becomes required and auditable. If it is finalized, practices would generally have about 240 days from publication to comply, which is a tight window for the items below.
2. Will multi-factor authentication become mandatory under HIPAA?
Under the proposed rule, yes. Multi-factor authentication (MFA) would be required for all users and systems accessing ePHI, meaning a username and password alone would no longer meet the standard. This is proposed, not yet required.
For most practices this is the easiest item to get ahead of, because MFA is widely available and inexpensive to turn on. Waiting for the rule to finalize is the wrong play here. MFA is already considered a baseline safeguard, and the absence of it is a common finding in breach investigations, so enabling it now reduces real risk regardless of the rule’s timing.
3. Will encryption of ePHI be required at rest and in transit?
Under the proposed rule, yes. ePHI would have to be encrypted both at rest (stored on devices and servers) and in transit (moving across networks and email). This is proposed, not yet required, though encryption is already one of the strongest protections a practice can have in place.
Encryption matters for a practical reason beyond the rule: when data is properly encrypted, a lost laptop or stolen device is far less likely to trigger a reportable breach. Practices carrying unencrypted ePHI on aging workstations or in everyday email are carrying avoidable exposure right now.
4. Why is the annual risk analysis the one to act on today?
Because it is not proposed, it is current law, and it is the single most enforced requirement in healthcare IT compliance. A HIPAA risk analysis has been required for years, and according to the Office for Civil Rights, failure to conduct a thorough one is the most common finding in its breach investigations.
This is the item with real teeth today. OCR has run a dedicated risk analysis enforcement initiative through 2025 and into 2026, and has said it is expanding to include risk management as well. Recent OCR settlements with practices and health systems have ranged from tens of thousands of dollars to several million, frequently tied to a missing or inadequate risk analysis that preceded a ransomware or phishing breach. If you do one thing from this list, make it a current, documented risk analysis.
A risk analysis is only “adequate” in OCR’s eyes if it covers every system that creates, receives, stores, or transmits ePHI, documents the specific threats and vulnerabilities to each, and is updated when something material changes rather than filed once and forgotten. A generic checklist a vendor ran two years ago does not meet the standard. If you cannot point to a current document that names your actual systems and the risks to each, treat that as your first gap to close.
5. What is a technology asset inventory and network map, and will it be required?
A technology asset inventory is a written record of every device, system, and piece of software that touches ePHI, and a network map shows how that data flows between them. Under the proposed rule, both would be required, kept current, and updated after major changes. This is proposed, not yet required.
Most practices cannot produce either document on request today, which is exactly why it appears in the proposal. You cannot protect what you have not catalogued, and regulators increasingly treat “we did not know that system held ePHI” as a failure rather than an excuse. Building the inventory now also makes every other safeguard on this list easier to apply.
6. Will practices have to do vulnerability scanning and penetration testing?
Under the proposed rule, yes. Practices would be expected to run vulnerability scans at least every six months and a penetration test at least once a year. This is proposed, not yet required.
The difference between the two matters: a vulnerability scan is an automated check for known weaknesses, while a penetration test is a deeper, often manual attempt to actually exploit them. Together they move a practice from “we think we are secure” to “we have evidence.” Even ahead of any final rule, this kind of testing is what separates a defensible security posture from an assumed one.
7. How do expanding state privacy laws affect medical practices in 2026?
State privacy laws are expanding in 2026, with roughly 20 states now operating broad consumer privacy laws, and several of them reach health-related data beyond what HIPAA covers. This is current law, not proposed, and it varies by state.
For a practice, the practical effect is that HIPAA is now a floor, not a ceiling. Depending on where your patients live, you may face additional obligations around consent, data access, and how long you retain information. Practices operating across state lines, or marketing across them, should not assume HIPAA alignment alone covers every requirement that applies to them.
How can my practice prepare for 2026 compliance changes?
Start by confirming the one thing already being enforced: a current, documented risk analysis. From there, the proposed rule gives a clear preparation list. Enable MFA, encrypt ePHI, build an asset inventory, and schedule security testing. None of these require waiting on a final rule to begin.
The fastest way to see where you stand is to check your current security posture against several of these exact areas, MFA, encryption, risk analysis, and training, before a regulator or an attacker does it for you. PEAKE’s cybersecurity quiz is a quick, no-cost way to do that first read in a few minutes.
Find your practice’s gaps before they become findings. Take the free PEAKE cybersecurity quiz for a quick read on where your security posture stands.
PEAKE Technology Partners is a healthcare-focused managed services provider serving multi-location physician practices across the Mid-Atlantic and North Carolina. This article is general information, not legal advice; consult your compliance counsel on how these requirements apply to your practice.
