The 2026 HIPAA Security Rule overhaul is the first serious rewrite of the rule since 2003, and the most consequential change is not a new tool you have to buy. It is the removal of the word “addressable.” Under the proposal published by HHS in January 2025, the long-standing split between required safeguards and addressable ones collapses, and nearly every implementation specification becomes mandatory with written proof attached. Final action has since slid to a 2027 timeframe. That slide is not a reprieve. It is the only planning window most small and midsize organizations are going to get, and the work that fills it is inventory work, not shopping.
Five Things to Take Away
- “Addressable” is what is disappearing. For two decades, an SMB could document a reasoned decision not to implement a safeguard. That escape hatch closes, which means your existing risk-analysis file is the thing most likely to fail, not your firewall.
- The delay does not shrink the workload. Once a final rule publishes, the expectation is an effective date roughly two months later with compliance owed about six months after that, and business associate agreements refreshed inside a year. That is a fast clock for work that takes longer than people think.
- Most SMBs are business associates, not covered entities. Billing companies, IT providers, transcription vendors, analytics firms, and claims processors carry the same technical obligations as the hospital they serve, and many have never been audited on them.
- Asset inventory and a network map are the choke point. Almost every proposed requirement, from encryption coverage to vulnerability scanning scope, depends on knowing exactly where electronic protected health information lives. Nobody can finish that in a sprint.
- Written evidence is the deliverable. Policies, procedures, plans, and analyses all need to exist on paper, be reviewed on a stated cadence, and be produced on request. Verbal practice does not count.
Why Your Current HIPAA Documentation Will Not Survive the Rule Change
Most SMB HIPAA files fail the new bar on paperwork rather than on technology, because they were built to satisfy a standard that let reasonable judgment stand in for implementation. I have opened dozens of these binders during audits. The pattern is consistent: a risk assessment from three or four years ago, a policy set copied from a template with the previous owner’s company name still in the footer, and a short memo explaining why full-disk encryption on the back-office machines was not reasonable at the time. Under the old wording, that memo was a legitimate answer. Under the proposal, it is an admission.
What makes this awkward for smaller organizations is that the technology gap is usually narrower than the evidence gap. A twenty-person specialty practice running Microsoft 365 with conditional access already has most of the controls in reach. What it does not have is a current asset inventory, a diagram showing how patient data moves between the practice management system and the billing vendor, or a signed record of who reviewed the security policy last year. That is a documentation project with a technical tail, and it competes for the same staff time as patient care or client delivery. Teams that treat it as an IT purchase tend to buy tools and still fail the review. We see the same failure pattern in the HIPAA Security Rule compliance mistakes that cost SMBs the most, where the control existed but the proof did not.
What the 2026 HIPAA Security Rule Overhaul Actually Changes
The 2026 HIPAA Security Rule overhaul converts a flexible, judgment-based framework into a prescriptive one with documentation attached to every clause. HHS published the notice of proposed rulemaking in January 2025, the comment period closed that March, and roughly 4,700 comments arrived, including a coordinated request from a large coalition of hospital and provider groups asking for withdrawal or a narrower scope. The rule remains proposed. The direction of travel, though, has been consistent across administrations, and the control set it describes mirrors what cyber insurers and enterprise clients already demand in contracts.
The end of “addressable” implementation specifications
Removing the addressable category is the single change that reshapes SMB compliance work, because it converts discretion into obligation. The argument in favor is straightforward: two decades of breach investigations showed that “addressable” functioned as a permanent opt-out rather than a considered alternative, particularly for encryption. Regulators watched organizations document a reason to skip a control, then lose a laptop carrying thousands of records.
The argument against is equally real, and the comment file is full of it. Rural clinics, solo practices, and small vendors operate on margins where a mandatory control set with no flexibility can force a choice between compliance spend and clinical staffing. Critics also point out that a uniform mandate treats a two-provider dental office and a regional health system as the same risk surface, which no security professional actually believes. Both positions can hold at once. The likely outcome is a final rule that keeps the mandatory posture and softens the edges through timelines and narrow exceptions, which means planning for the strict reading is the safer bet even while the softer one stays possible.
Written documentation for everything
Every policy, procedure, plan, and analysis needs to exist in writing, be reviewed on a stated schedule, and be produced when asked. Supporters of this requirement note that undocumented practice is unverifiable practice, and that an auditor cannot score a control that lives only in an administrator’s head. Detractors counter that documentation volume becomes its own risk, since a thick binder nobody reads creates false assurance and consumes the hours that should go to actual hardening. The honest read is that both effects are observed in the field. What resolves the tension is scope discipline: document the systems that touch electronic protected health information precisely, and resist the urge to paper the entire company. The same discipline that makes a system security plan and POA&M useful rather than decorative applies here.
The technical controls that stop being optional
Multi-factor authentication and encryption move from recommended to expected, and the supporting cast comes with them. The proposal describes multi-factor authentication for access to systems holding electronic protected health information, encryption of that data at rest and in transit, a maintained asset inventory and network map, vulnerability scanning on a twice-yearly cadence, annual penetration testing, annual compliance audits, and notification and restoration clocks tight enough that contingency plans have to be rehearsed rather than filed. Most of that is achievable with platforms SMBs already own. Encryption coverage on unmanaged endpoints and legacy clinical devices is where the real cost sits, alongside continuous network security monitoring that can prove the scanning actually ran. For teams still mapping the baseline obligations, our breakdown of what HIPAA compliance consists of for IT and security teams covers the ground the rule assumes you already hold.
Where the 2026 HIPAA Security Rule Overhaul Hits SMBs Hardest
The 2026 HIPAA Security Rule overhaul lands heaviest on business associates, because that is the population with full obligations and the thinnest history of scrutiny. If your company processes claims, hosts a practice management system, provides IT support to clinics, handles transcription, or runs analytics on patient data, the rule treats you the way it treats the provider. Several proposed clauses aim directly at that relationship, including duties to notify the covered entity when a contingency plan activates and to verify safeguards on a stated cadence rather than by attestation alone.
Business associates carry the same technical weight
Business associates face the same mandatory control set as covered entities, with less institutional muscle to absorb it. In favor of that symmetry: attackers target the vendor precisely because it is softer, and the largest health data breaches of the past several years have run through third parties rather than hospital networks. Against it: a fifteen-person billing company cannot staff a security program the way a health system can, and the compliance cost per record is wildly higher at the small end. Neither observation cancels the other. What changes the math is consolidating the work under a single accountable provider instead of spreading it across point tools, which is also where managed security services earn their keep. Choosing that partner badly creates its own exposure, and the managed IT security services provider risks SMBs miss are worth reading before signing.
Asset inventory is the hidden workload
An accurate inventory of every system, device, and application that touches electronic protected health information is the prerequisite for nearly every other requirement, and almost nobody has one. Encryption scope, scanning scope, access review scope, and contingency planning all inherit their boundaries from that list. In practice, the inventory takes weeks of unglamorous work: walking the office, checking the imaging device that quietly writes to a network share, finding the shadow spreadsheet a scheduler maintains, tracing which cloud tenants hold backups. Cloud sprawl makes it harder rather than easier, which is why cloud security posture and the inventory have to be built together. Smaller providers hit this wall first, and the pattern is well documented in our 2026 HIPAA guide for dental practices.
Vendor contracts and the twelve-month clock
Business associate agreements will need to be reworked, and the proposal points to that happening within a year of the effective date. That sounds generous until you count your vendors. A mid-sized practice or a growing SaaS company can carry forty or fifty agreements, each owned by a different person, many auto-renewing, some signed by someone who left. Renegotiating them requires knowing which vendors touch patient data, which loops back to the inventory. Start the contract triage in parallel, not after.
How to Sequence the Work Across the Delay Window
Sequencing matters more than speed, because the later requirements depend on the earlier ones. Treat the window as three phases.
First, inventory and map. Build the asset list and the data-flow diagram, then run a current risk analysis against it. A structured cyber security audit produces both artifacts in a form an auditor recognizes, which saves rewriting them later.
Second, close the mandatory controls. Turn on multi-factor authentication everywhere it can go, extend encryption to the endpoints and backups the inventory surfaced, stand up the scanning cadence, and rehearse restoration rather than filing the plan. Pair the technical work with security awareness training, since the proposal expects workforce practices to be documented and current.
Third, put the evidence on paper. Write the policies against what you actually do, record the review dates and reviewers, and rebuild the business associate agreements. Evidence assembled while the work happens costs a fraction of evidence reconstructed under audit.
Frequently Asked Questions
Is the 2026 HIPAA Security Rule overhaul final?
No. The rule is still a proposal, published in January 2025, and HHS has moved final action to a longer-term agenda pointing at 2027. Covered entities and business associates remain bound by the current Security Rule until a final rule publishes.
When would compliance actually be due?
Based on the proposed structure, a final rule would take effect roughly sixty days after publication, with compliance expected about one hundred eighty days after that, and business associate agreements updated within a year of the effective date. That puts real deadlines inside a single budget cycle once the rule lands.
Does the overhaul apply to business associates as well as providers?
Yes. Business associates carry the same technical and documentation obligations, and several proposed clauses add duties that run specifically from the associate to the covered entity, including notification when a contingency plan activates and periodic verification of safeguards.
What should a small organization do first?
Build the asset inventory and the data-flow map, then run a current risk analysis against them. Every other requirement, from encryption coverage to scanning scope, inherits its boundaries from that work, and it cannot be compressed into the final weeks before a deadline.
Will multi-factor authentication and encryption really be mandatory?
Under the proposal, both move out of the addressable category and become expected across systems that hold electronic protected health information. Even if the final rule softens the edges, cyber insurers and enterprise clients already require both, so the practical answer for planning purposes is yes.
Talk to a Mindcore Strategist Before the Clock Starts
The organizations that will handle this well are the ones treating 2026 as inventory season rather than waiting for a publication date to force a scramble. The controls are largely reachable. The evidence trail is what takes months, and it cannot be bought late. If you are sitting on a risk analysis older than a year, an asset list that lives in someone’s memory, or a stack of business associate agreements nobody has read since signing, that is the starting point, and it is a better problem to have in July 2026 than the week a final rule publishes.
Our team works with providers and with the vendors serving them, on both sides of the business associate relationship, and we build the inventory, the risk analysis, and the control coverage as one piece of work instead of three disconnected projects. Book a free strategy call and we will tell you honestly where your gap sits and what order to close it in.

