Most small businesses fail a HIPAA Security Rule review not because they ignored security, but because they treated the wrong parts of it as optional. The Security Rule, the part of HIPAA that governs electronic protected health information (ePHI), requires documented administrative, physical, and technical safeguards on every system that creates, stores, or transmits patient data. For years, small organizations leaned on the rule’s “addressable” language to skip controls like encryption and multi-factor authentication. That loophole is closing. The 2026 Security Rule overhaul proposed by the HHS Office for Civil Rights removes most of the addressable-versus-required distinction, and the same expectations now apply to a five-person practice and a hospital system alike. We see the same six mistakes land small businesses in trouble, and every one of them is preventable.
The 5 Things Every SMB Should Know First
HIPAA Security Rule compliance for small businesses comes down to proving your safeguards exist, not just intending to have them. Before we get into the specific mistakes, these five principles frame everything that follows.
- “Addressable” never meant “optional.” It meant you either implemented the control or documented a defensible reason not to. Most SMBs skipped both. The 2026 overhaul is expected to make MFA, encryption, and annual risk analysis flatly required.
- The Security Rule is size-neutral. A solo provider and a 400-bed system face the same requirements. Smaller teams feel the change hardest because they started from the least formal programs.
- Evidence is the product. Auditors and investigators do not grade good intentions. They ask you to produce the risk analysis, the access logs, the training records, and the signed agreements.
- The Security Risk Analysis drives everything. Nearly every OCR settlement traces back to a missing, stale, or incomplete risk analysis. It is the first document an investigator requests.
- Vendors are your exposure. A breach at your billing company or cloud host is your reportable event unless the paperwork and oversight are in place.
Mistake 1: Treating Encryption and MFA as Optional
The most expensive HIPAA Security Rule mistake is assuming “addressable” safeguards can be safely ignored. Encryption of ePHI and multi-factor authentication both sat in the addressable category for years, and countless small businesses read that as permission to skip them. The proposed 2026 rule ends that reading. Under the overhaul, encryption of ePHI at rest and in transit becomes mandatory with no alternative controls permitted, and MFA becomes required across every system that touches patient data.
We have investigated breaches where a single unencrypted laptop turned a minor loss into a six-figure reportable event. Had the drive been encrypted, the same lost device would have qualified for safe harbor and triggered no notification at all. The fix is not exotic. Turn on full-disk encryption everywhere ePHI can land, enforce TLS on every transmission, and require phishing-resistant MFA on email, remote access, and any application that reaches patient records. If you want a full picture of the technical controls the rule expects, our breakdown of what HIPAA compliance consists of for IT and security teams walks through each safeguard category.
Mistake 2: Skipping the Annual Security Risk Analysis
A missing or outdated Security Risk Analysis is the fastest way to lose a HIPAA case. The Security Risk Analysis, or SRA, is the formal assessment of where ePHI lives, how it moves, and what could go wrong. The current rule requires it “periodically,” which many SMBs interpreted as “once, years ago.” The proposed 2026 update is expected to require the SRA annually and after any significant change to your systems.
There are two honest sides to how burdensome this is. On one hand, an annual SRA is real work for a small team with no dedicated compliance staff, and the documentation load is heavier than a periodic check. On the other hand, the SRA is the single control that would have caught most of the breaches we respond to, because it forces you to find the shadow database, the unmanaged phone, and the ex-employee account before an attacker does. The balanced view is that the SRA is expensive precisely because it is the control that works. Run it every year, tie each identified risk to a written remediation plan, and keep both. A structured cybersecurity audit is the cleanest way to produce that evidence on a repeatable schedule.
Mistake 3: Weak or Missing Business Associate Agreements
Small businesses lose HIPAA cases over vendors they forgot were vendors. A Business Associate Agreement (BAA) is the contract that binds any outside party handling your ePHI to the same safeguards you follow. If your cloud host, billing service, IT provider, or email platform touches patient data, they need a signed BAA and you need proof they are living up to it.
The mistake has two failure modes. The first is no agreement at all, which leaves you fully liable for the vendor’s breach. The second is subtler and more common: a signed BAA sitting in a drawer with zero follow-up. A signed agreement does not encrypt anything or patch anything. Some argue the BAA is a formality, and others treat it as full vendor management. The accurate position sits between them. The BAA sets the legal floor, but you still owe reasonable oversight, checking that critical vendors carry current attestations and disclose their own subcontractors. Inventory every service that reaches ePHI, confirm each has a current BAA, and review the high-risk ones yearly. This is also where a security-first cloud security posture pays off, because your cloud configuration is the vendor relationship you control most directly.
Mistake 4: Access Controls That Do Not Match Job Roles
HIPAA Security Rule compliance requires that access to ePHI reflect the minimum each person needs to do their job. In small businesses, everyone tends to have access to everything, and old accounts linger long after people leave. That is the exact condition attackers exploit, and it is one of the first things an investigator tests.
Enforcing the Minimum-Necessary Standard
The minimum-necessary standard means a role gets access to the data that role needs, and nothing more. In practice, that means the front-desk login should not reach clinical records it never uses. Critics of strict role-based access point out that small teams wear many hats and rigid roles can slow real work. That is a fair tension. The workable middle ground is to build a small number of practical roles that match how your team actually operates, then review them quarterly rather than chasing perfect granularity you cannot maintain. Document the roles so you can show an auditor the logic.
Closing the Offboarding Gap
The offboarding gap is the window between someone leaving and their access actually being revoked, and for many SMBs that window is measured in months. We regularly find active credentials for people who left a year earlier. Some organizations argue full deprovisioning is overkill for a trusted former employee. The Security Rule does not share that view, and neither do the attackers who buy those credentials. Tie access removal to your HR offboarding step so it happens the same day, and keep a log that proves the account was closed. Continuous managed security services make that monitoring routine instead of something you remember after an incident.
Mistake 5: No Documented, Tested Incident Response Plan
The Security Rule requires a written incident response and breach notification plan, and it must be tested, not just filed. When a breach hits, the clock on HHS and state notification deadlines starts immediately, and a plan you have never rehearsed falls apart under pressure. The proposed 2026 rule is expected to make incident response and recovery planning more prescriptive, including defined recovery time objectives.
The honest counterargument is that a small business rarely has the staff to run tabletop exercises. That is real, but it argues for a simpler plan you can actually execute, not for skipping one. Write down who declares an incident, who contains it, who counts the affected records, and who files the notifications, then walk the team through one scenario a year. The distinction between an addressable inconvenience and a reportable disaster often comes down to whether anyone knew what to do in the first hour. Our overview of IT compliance for healthcare practices shows how response planning fits alongside the rest of a HIPAA program.
Mistake 6: Controls Exist but You Cannot Prove Them
The HIPAA Security Rule does not accept good intentions, it requires that controls exist and that you can show they exist. This is where technically secure small businesses still fail, because the encryption is on, the training happened, and the accounts are locked down, but none of it is documented in a way an investigator will accept. Verbal assurance carries no weight in an OCR review.
Two documentation gaps cost SMBs the most. The first is workforce training with no records. Security awareness training is a required safeguard, yet most small teams cannot produce sign-in sheets or completion logs, and untrained staff remain the leading cause of the breaches we investigate. That is exactly why security awareness training is now a compliance line item rather than a nice-to-have, and running it through a managed security awareness training program generates the completion evidence automatically. The second gap is the absence of audit logs showing who accessed ePHI and when. Turn on access logging, retain it, and keep your policies, training records, SRA, and remediation plans in one place you can hand over on request. A platform-level approach like ShieldHQ’s compliance posture across HIPAA, SOC 2, and NIST keeps that evidence continuous instead of a scramble before an audit.
Frequently Asked Questions
What is the HIPAA Security Rule?
The HIPAA Security Rule is the federal standard that requires covered entities and their business associates to protect electronic protected health information through administrative, physical, and technical safeguards. It governs ePHI specifically, while the Privacy Rule covers patient rights and the Breach Notification Rule covers disclosure after an incident. Together they form the core of HIPAA compliance.
Does the HIPAA Security Rule apply to small businesses?
Yes, the HIPAA Security Rule applies to any covered entity or business associate that handles ePHI, regardless of size. A solo practice, a small billing company, and a large hospital face the same requirements. The proposed 2026 overhaul reinforces this by removing size-based leniency in how the addressable safeguards are applied.
What is changing in the 2026 HIPAA Security Rule update?
The 2026 HIPAA Security Rule update proposed by the HHS Office for Civil Rights is expected to make many previously addressable safeguards mandatory. Reported changes include required MFA, mandatory encryption of ePHI at rest and in transit, annual security risk analysis, regular penetration testing and vulnerability scanning, and network segmentation. Organizations typically receive a compliance grace period, often around 180 days, after a final rule is published.
How often do I need a Security Risk Analysis?
Under current HIPAA rules a Security Risk Analysis must be performed periodically and after significant changes, and the proposed 2026 update is expected to require it annually. Running it every year, and after any major system change, is the safest posture. Each identified risk should be paired with a documented remediation plan.
What happens if my SMB fails a HIPAA audit?
Failing a HIPAA review can lead to corrective action plans, civil monetary penalties, and mandatory reporting, with penalties scaled to the level of negligence. Most enforcement traces back to a missing risk analysis or undocumented safeguards rather than a lack of security tools. Maintaining current documentation is the most reliable protection.
Get Your HIPAA Security Rule Program Audit-Ready
HIPAA Security Rule compliance is less about buying more tools and more about proving the safeguards you already run, then closing the gaps the 2026 overhaul will make non-negotiable. The six mistakes above share one root cause: treating required controls as optional and leaving no evidence behind. Fix the risk analysis, lock down access, encrypt everything, sign and manage your BAAs, rehearse your incident response, and document all of it. Our team helps small businesses turn a scattered set of controls into a defensible, audit-ready cybersecurity compliance program, and we can map your current state against the proposed 2026 requirements before they take effect. If you handle other regulated data as well, the same discipline applies to adjacent regimes like the FTC Safeguards Rule. Book a free strategy call and we will show you exactly where your HIPAA program stands and what to fix first.

