• Client Portal
  • Blog
(804) 612-9876
Bastionpoint Technology
  • About Us
    • Blog
    • Press Releases
    • Video Library
  • What You Need
    • An Outsourced IT Department
    • A Partner in Managing IT
    • A Help Desk to Call
    • Cybersecurity and Compliance
  • What We Offer
    • Fully Managed IT
    • Co-Managed IT
    • Remote Helpdesk
    • Cybersecurity and Compliance
    • Structured Cabling
    • Wireless Survey
  • Careers
  • Get Started
  • Menu Menu

HIPAA Is Changing. Here’s What You Need to Know.

Cybersecurity
Cybersecurity professional monitoring healthcare data systems as medical organizations prepare for HIPAA Security Rule changes.

The HIPAA Security Rule is about to go through its most significant overhaul in over 20 years. If your organization touches electronic protected health information, or works with partners who do, this affects you, and the time to start preparing is now.

At Bastionpoint, we’re a business associate to many of our healthcare clients, so these changes land on us, too. Here’s where things stand and what we’re doing about it.

Quick Overview

Key Point What It Means
Proposed rule published HHS proposed the biggest HIPAA Security Rule update since 2003. The proposed rule was published January 6, 2025.
Final rule status As of June 2026, the final rule has not been published, and the original May 2026 target has passed.
Compliance timeline Once finalized, organizations are expected to get roughly 240 days to comply, likely putting the deadline around Q1 2027.
Major proposed changes Key changes include mandatory encryption, MFA, annual penetration testing, vulnerability scanning, documented risk analysis, and 72-hour incident response expectations.
Separate NPP deadline A separate deadline for updating your Notice of Privacy Practices was February 16, 2026.
Current enforcement risk OCR is actively enforcing the current Security Rule now, so compliance gaps carry real risk today.

What’s Happening

HHS published a Notice of Proposed Rulemaking in late 2024, marking the first major HIPAA Security Rule update since 2003. As of June 2026, the final rule has not been published. There has been real industry pushback, and the original May 2026 target has passed.

But the direction is clear. OCR has already shifted enforcement priorities toward the controls this rule would require. Once a final rule lands, organizations get roughly 240 days to comply, putting the deadline around Q1 2027. That is not much runway.

Note: This is still a proposed rule, not final law. But waiting for finalization before you start preparing is the wrong move.

What’s Changing

The biggest shift is that the current rule’s “addressable” safeguards, which gave organizations flexibility to document why a control was not practical, may go away. Under the proposed changes, nearly everything becomes mandatory.

  • Encryption: ePHI at rest and in transit must be encrypted. No workarounds.
  • Multi-Factor Authentication: MFA is required across all systems accessing ePHI. “Our vendor doesn’t support it” will not be acceptable.
  • Security Testing: annual penetration tests and vulnerability scans every six months must be documented.
  • Risk Analysis: general assessments will not hold up. Structured, evidence-backed methodologies will be required.
  • Asset Inventories and Network Maps: you will need current documentation of every ePHI-touching system and how data flows through your environment.
  • Annual Compliance Audits: formal audits will be required at least once every 12 months.
  • 72-Hour Incident Response: business associates, including Bastionpoint, must report incidents and demonstrate the ability to restore critical systems within 72 hours. Paper disaster recovery plans will not cut it.

These proposed changes make one thing clear: HIPAA compliance is moving from flexible documentation to provable security execution. Organizations will need to show not only that policies exist, but that encryption, MFA, testing, audits, recovery planning, and ePHI visibility are actually in place.

That is why preparation matters now. Even before the final rule is published, reviewing your current safeguards against these proposed requirements can help uncover gaps, reduce last-minute costs, and put your organization in a stronger position when the compliance clock officially starts.

What Should You Do Now?

The rule is not final, but OCR’s enforcement posture has already moved. Organizations that start now will be in a different position than those that wait.

If you are a current client and want to know where you stand, reach out. If you are not a client yet and are trying to get ahead of this, we would be glad to talk. We are already doing most of this for clients, and we are tightening the belt to meet the new requirements.

Ready to Know Where You Stand?

HIPAA compliance is not a once-a-year checkbox anymore, and the proposed changes will raise the bar significantly. Whether you are a covered entity or a business associate, getting ahead of this now is the right move.

Bastionpoint Technology helps small and mid-size organizations in the Richmond area and beyond navigate HIPAA compliance alongside the rest of their IT and security strategy.

Schedule a free HIPAA readiness conversation with us today.

Frequently Asked Questions About HIPAA Changes

Is the new HIPAA Security Rule already in effect? Not yet. As of June 2026, the updated Security Rule is still a proposed rule. OCR’s May 2026 finalization target has passed without a final rule being published. That said, OCR is actively enforcing the current Security Rule, especially risk analysis requirements, so compliance gaps still carry real risk today.

Does HIPAA apply to my business if we’re not a healthcare provider? Yes, if you handle, store, transmit, or access protected health information on behalf of a covered entity, you are a business associate and HIPAA applies to you. The proposed rule significantly expands direct liability and documentation requirements for business associates, including IT firms, billing companies, and practice management vendors.

What does “addressable vs. required” mean, and why does the change matter? Under the current rule, some safeguards are “addressable,” meaning organizations can document why a control is not practical and use an alternative measure when reasonable and appropriate. The proposed rule would eliminate that distinction. Encryption, MFA, penetration testing, and other previously addressable controls would become universally mandatory, with no opt-out.

How long will we have to comply once the final rule is published? The proposed rule includes a 240-day compliance window from the date of final publication. If a final rule issues later in 2026, that puts the deadline around Q1 2027. Organizations that start gap assessments now will have more time and significantly lower costs than those that wait.

What’s the first step we should take to prepare? Start with a security risk analysis tied to your actual asset inventory. The security risk analysis is the foundation every other requirement builds on, and it is also one of the most common deficiencies OCR cites in current enforcement actions. If you do not have a current, documented security risk analysis, that should be your first priority.

July 1, 2026/0 Comments/by Eric Clary
Share this entry
  • Facebook Facebook Share on Facebook
  • X-twitter X-twitter Share on X
  • Square-x-twitter Square-x-twitter Share on X
  • Whatsapp Whatsapp Share on WhatsApp
  • Pinterest Pinterest Share on Pinterest
  • Linkedin Linkedin Share on LinkedIn
  • Reddit Reddit Share on Reddit
  • Mail Mail Share by Mail
https://bastionpoint.com/wp-content/uploads/2026/07/cybersecurity-professional-works-on-medical-hackin-2026-01-11-08-45-40-utc-1-scaled.jpg 1707 2560 Eric Clary https://bastionpoint.com/wp-content/uploads/2020/09/BPLogoTransparentBG-300x251.png Eric Clary2026-07-01 09:00:092026-07-02 07:05:12HIPAA Is Changing. Here’s What You Need to Know.
0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Pages

  • About
  • Auditing
  • Bastionpoint Technology Featured on 12 On Your Side for $10K Shelter Security Donation
  • Blog
  • Careers
  • Co-Managed IT
  • Computer Hardware
  • Contact
  • Customer Support
  • Cybersecurity
  • Cybersecurity Policies and Procedures
  • Disaster Prevention and Recovery
  • Email Security
  • Find Your “Furever” Valentine: Bastionpoint Technology’s Adoption Event on CBS6
  • Fully Managed IT
  • Giving Back in Richmond: Bastionpoint Technology’s Toys for Tots Event on CBS6
  • Hardware and Wiring
  • IT Consulting
  • IT Health Survey
  • IT Project Management
  • IT Services
  • Kickers Ticket Rules
  • Kickers Tix
  • Managed IT Services Midlothian, Virginia
  • Managed IT Services Petersburg, Virginia
  • Managed IT Services Richmond, Virginia
  • Midlothian VA Outsourced IT
  • Otter Cam
  • Partner Managed IT Services Richmond, Virginia
  • Phone Systems
  • Privacy Policy
  • Remote Helpdesk
  • Richmond VA Disaster Recovery
  • Richmond VA IT Support
  • Richmond, Virginia Cybersecurity Services
  • Richmond, Virginia Outsourced IT
  • RVA Today – Bastionpoint Compliance and AI
  • RVA Today – Bastionpoint Cybersecurity Tips
  • RVA Today – Bastionpoint Enterprise Security and Growing your Business
  • RVA Today – Bastionpoint In the Community
  • RVA Today – Bastionpoint Polices, Procedures and Best Practices
  • RVA Today – Bastionpoint Technology Intro
  • Sample Blog
  • Strengthen Your Business with the Right IT Partner
  • Structured Cabling
  • Terms and Conditions
  • Thank You
  • Unlimited Flat Fee Support
  • vCIO
  • Video Library
  • We Are Your Full-Service IT Company
  • Why Not Us
  • Williamsburg IT Support Company
  • Williamsburg, Virginia Cyber Security Company
  • Wireless Networks
  • Wireless Survey

Categories

  • artificial intelligence
  • Case Study
  • Cloud Computing
  • Cloud Security
  • Co-Managed IT Solutions
  • Company News
  • Customer Service
  • customer support
  • Cyber-Attacks
  • Cybercrime
  • Cybersecurity
  • Data Back-Up
  • Disaster Recovery
  • From the Desk of the CIO
  • help desk support
  • Information Technology
  • IT helpdesk
  • IT helpdesk support
  • IT risks
  • Managed IT Solutions
  • Managed Services
  • phishing
  • Press Releases
  • ransomware attacks
  • Structured Wiring
  • Tech Tips
  • Technical Notes
  • threat intelligence
  • Uncategorized
  • vCIO
  • Wireless Network Survey

Archive

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • August 2020
  • May 2020
  • April 2020
  • February 2020
  • January 2020
  • November 2019
  • August 2019
  • June 2019
  • February 2019
  • December 2018
  • May 2018

1618 Hull St
Richmond, VA 23224

(804) 612-9876

About Bastionpoint Technology

  • About
  • Blog
  • Why Not Us
  • Contact
  • Careers

Services We Offer

  • IT Services
  • IT Consulting
  • Disaster Prevention and Recovery
  • Hardware and Wiring
  • Computer Hardware
  • Cybersecurity Policies and Procedures
  • Email Security
© 2026 - Bastionpoint Technology. All Rights Reserved.
  • Link to LinkedIn
  • Link to Facebook
  • Link to X
  • Privacy Policy
  • Terms and Conditions
Link to: EDR Explained: How It Detects Attacks Before They Cause Damage Link to: EDR Explained: How It Detects Attacks Before They Cause Damage EDR Explained: How It Detects Attacks Before They Cause DamageFingerprint cybersecurity interface displaying endpoint detection and response technology protecting connected business devices and cloud systems Link to: Bastionpoint Technology Named #155 on the 2026 Channel Futures MSP 501, Marking Five Straight Years on the Global List Link to: Bastionpoint Technology Named #155 on the 2026 Channel Futures MSP 501, Marking Five Straight Years on the Global List Bastionpoint Technology graphic announcing its 2026 MSP 501 win, with the MSP 501 Winner badge and text reading “Ranked Top in RVA for Five Years in a Row.”Bastionpoint Technology Named #155 on the 2026 Channel Futures MSP 501, Marking...
Scroll to top Scroll to top Scroll to top