HIPAA Compliance Tips in 2026
Key Takeaways:
- The HIPAA Security Rule overhaul proposed in January 2025 was postponed to at least July 2027, so the current rule remains enforceable while the proposed mandates await finalization.
- HHS estimated first-year compliance costs for the proposed rule at roughly $9 billion, with $6 billion per year in years two through five.
- OCR’s 2026 ransomware settlements totaled $1.17 million across four covered entities impacting more than 427,000 individuals, and every one traced back to a failed risk analysis.
- The Oracle Health breach involving legacy Cerner systems affected nearly 20 million people, ranking among the largest healthcare data breaches recorded.
- Compliance involves configuration work: encryption, MFA, audit logging, and asset inventory are the controls auditors actually test.
The HIPAA Security Rule has not been substantially updated since 2013. That 13-year gap defines healthcare cybersecurity in 2026: the rule governing how hospitals protect electronic protected health information (ePHI) predates the ransomware economy, the cloud migration of electronic health records, and autonomous AI agents integrated into clinical workflows. A rewrite was proposed in January 2025 but has since stalled.
Federal regulators postponed final action on the overhaul to at least July 2027, according to Fierce Healthcare’s report on the delay. Covered entities face a difficult situation: the old rule remains enforceable, the new mandates are not yet law, and the threat environment continues to evolve. This guide explains what the current rule requires, what enforcement entails, and which controls to implement now to avoid scrambling during the 2027 transition.
The Healthcare Threat Landscape in 2026
The U.S. healthcare sector experienced more than 700 data breach incidents in 2024, exposing over 275 million patient records, according to BleepingComputer. This was more incidents than any other industry, including finance.

The Oracle Health breach shows how extensive damage can become. The personal and medical information of nearly 20 million people was compromised in an attack on Oracle Health’s legacy Cerner systems, SecurityWeek reported, citing a report from the Texas attorney general. Oracle began notifying healthcare customers in March 2025 after discovering unauthorized access around February 20, 2025. An attacker used stolen customer credentials to access a legacy server not yet migrated to Oracle Cloud, then copied data to a remote server. Cerner’s entry on the Texas attorney general’s breach portal lists 2,992,244 affected Texans alone.
If confirmed, the nearly 20 million figure would rank the incident among the largest healthcare data breaches in the United States. Only a few reported incidents were larger, including the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people. In both cases, attackers accessed data that existing controls failed to protect, and the exposure went undetected for months.
What the HIPAA Security Rule Requires
The Security Rule’s technical safeguards are specified at 45 CFR 164.312 and are organized into five categories: access control, audit controls, integrity, person or entity authentication, and transmission security. Historically, the rule divided implementation specifications into “required” and “addressable.” Addressable did not mean optional, but many organizations documented why a control was not reasonable and moved on. The January 2025 notice of proposed rulemaking (NPRM) would remove that distinction entirely.

As TechTarget reported on the NPRM’s provisions, the proposed rule would require covered entities to conduct annual compliance audits, develop an asset inventory and network map tracking ePHI movement, and strengthen risk analysis. It adds specific timelines where none exist today: vulnerability scanning at least every six months, penetration testing at least once every 12 months, mandatory multi-factor authentication, and mandatory network segmentation. Business associates would have to verify their use of technical safeguards annually.
HHS acknowledged the cost: in the NPRM, it estimated first-year compliance costs at approximately $9 billion, with $6 billion per year in years two through five. The agency argued the rule would pay for itself if it reduced the number of individuals affected by breaches by 7 to 16 percent. Attorneys quoted in that coverage expressed doubt that threat actors would cooperate with the math.
| Proposed mandate | Current rule status | Where it lands in 164.312 |
|---|---|---|
| Mandatory multi-factor authentication | Addressable | 164.312(d) authentication |
| Mandatory encryption at rest and in transit | Addressable | 164.312(a)(2)(iv), (e)(2)(ii) |
| Vulnerability scanning every 6 months | No specified frequency | 164.308(a)(1)(ii)(A) risk analysis |
| Penetration testing every 12 months | No specified frequency | 164.308(a)(1)(ii)(A) risk analysis |
| Annual asset inventory and network map | No explicit requirement | 164.308(a)(1)(ii)(A) risk analysis |
| Annual business associate safeguard verification | Contractual expectation | 164.308(b)(1) business associate contracts |
OCR Enforcement: Risk Analysis Is the Recurring Finding
In April 2026, OCR announced four ransomware settlements with HIPAA-covered entities that collectively affected more than 427,000 individuals and paid a total of $1.17 million, per TechTarget’s coverage of the settlements. Each case traced back to a failure to conduct a compliant risk analysis.
Two details matter for organizations assuming they are too small to attract scrutiny. The smallest breach in the group affected just 9,300 individuals, showing OCR is not limiting itself to large health systems. The settlements brought OCR’s total to 19 completed ransomware investigations and 13 completed under its risk analysis initiative. “Hacking and ransomware are the most frequent type of large breach reported to OCR,” OCR Director Paula M. Stannard said in the announcement, adding that proactively implementing the Security Rule is a regulated entity’s best chance to prevent or reduce the effects of a successful attack.
The individual settlements reveal the same root cause across different organization types. Assured Imaging, a medical imaging provider hit by PYSA ransomware in May 2020, had never conducted a compliant risk analysis and failed to notify affected individuals within 60 days; it paid $375,000. Regional Women’s Health Group paid $320,000 after OCR found it failed to assess risks to ePHI confidentiality, integrity, and availability. Star Group’s self-funded health benefits plan paid $245,000, and Consociate Health, a business associate, paid $225,000. Each agreed to a corrective action plan and two years of OCR monitoring.
AI Agents and the Expanding Attack Surface
Healthcare organizations are deploying autonomous AI agents that have shell execution, file system access, and database query capabilities, each a potential HIPAA violation when an agent processes PHI. A March 2026 paper on arXiv, “Caging the Agents: A Zero Trust Security Architecture for Autonomous AI in Healthcare”, describes a production deployment of nine autonomous agents at a healthcare technology company and outlines a six-domain threat model: credential exposure, execution capability abuse, network egress exfiltration, prompt integrity failures, database access risks, and fleet configuration drift.
The paper explains a four-layer defense: kernel-level workload isolation using gVisor on Kubernetes, credential proxy sidecars that prevent agent containers from accessing raw secrets, network egress policies restricting each agent to allowlisted destinations, and a prompt integrity framework with structured metadata envelopes and untrusted content labeling. Over 90 days of deployment, the authors report four high-severity findings discovered and fixed by an automated security audit agent.
The trade-off is operational cost: each layer adds latency and management overhead, and the architecture is more complex than a conventional application stack. For a small clinic, the practical takeaway is narrower: any AI tool that handles PHI needs an explicit data-flow review before deployment, and an agent that can execute shell commands on a system holding ePHI requires the same segmentation and credential controls applied to a privileged user. The broader trend in TechCrunch’s review of 2026 breaches is that security is central to most major incidents.
Practical Controls That Map to the Rule
Compliance in practice involves configuration and evidence collection. The controls below are the ones auditors test most often, and each corresponds to a specific citation. Our guide to HIPAA compliance for cloud storage explains how these translate into cloud provider settings, and the same principles apply on-premises.
Access control (164.312(a)(1)). Enforce MFA for every human administrator and every service account, not just console logins. A common failure is a debugging role expanded during an incident and never reverted. Review access quarterly and assign permissions based on job function.
Audit controls (164.312(b)). Enable API and access logging in every environment, then send logs to write-protected storage where an attacker who compromises the primary system cannot delete them. Rotate keys on schedule and keep rotation logs, because a team that rotated but cannot prove it fails the same way as a team that never rotated.
Transmission security (164.312(e)(1)). Encrypt external APIs and internal service-to-service traffic alike. The assumption that internal networks are trusted does not hold in a multi-tenant cloud, nor on a hospital network where an attacker who reaches one system can move laterally.
Encryption at rest (164.312(a)(2)(iv)). Enable AES-256 on every environment, including backups and non-production systems. The compliance risk is rarely the algorithm; it is whether encryption is enabled everywhere. Store keys in a dedicated key management service or hardware security module, separated from the data they protect by account boundaries.
Network segmentation. The proposed rule would require this. In practice, it limits how far an attacker can move. Infusion pumps should connect only to infusion management servers, imaging devices only to PACS servers, and each device class should have a deny-by-default policy limited to its clinical function. Our analysis of network segmentation explains the macro versus micro approaches and how each reduces audit scope.
The Delayed Overhaul and What to Do Now
The postponement to July 2027 does not mean the proposed requirements are abandoned. It means organizations have time to prepare without a fixed deadline, and that time is valuable. Data mapping and asset inventories provide benefits regardless of whether the rule is finalized, because you cannot protect ePHI you have not identified.
The industry opposition is significant. More than 100 hospital systems, provider organizations, and associations led by the College of Healthcare Information Management Executives (CHIME) urged HHS to withdraw the Biden-era proposal, arguing it would impose substantial financial burdens and unrealistic implementation timelines, as TechTarget reported. The letter claimed the proposal “runs counter to President Trump’s deregulatory agenda.”
The technical objection is more detailed than the political one. CHIME’s director of federal affairs, Chelsea Arnone, told Dark Reading that HHS estimated MFA deployment could be done in one and a half hours, while for hospitals MFA affects every clinical workflow, every app, and every workstation and requires redesigning access patterns so clinicians can still care for patients, projects that take months, not hours. Segmentation faces the same issue: HHS estimated four and a half hours, while member CISOs say it requires weeks to months of architectural redesign, firewall policies, testing, and coordination across clinical systems. Revising thousands of Business Associate Agreements, Arnone said, would take most well-resourced hospitals at least a year.
The practical advice from the attorneys quoted in that coverage is consistent: comply with the rule as currently written while preparing for the proposed requirements. The controls that provide the most benefit under either scenario are the ones OCR already enforces: a thorough risk analysis, an asset inventory, MFA, encryption, and segmentation. These also reduce breach exposure regardless of the final rule.
HIPAA Cybersecurity Audit Checklist
Use this list to audit your environment against the controls OCR tests and the proposed rule would require.
- Risk analysis: Confirm you have a documented, current risk analysis covering confidentiality, integrity, and availability of ePHI. This is the most common finding in OCR settlements.
- Asset inventory and network map: List every system that creates, receives, maintains, or transmits ePHI, and map where it flows. Update it annually.
- MFA coverage: Verify MFA is enforced for all human administrators and all service accounts, and document the enforcement setting rather than just the policy.
- Encryption: Confirm AES-256 at rest on every environment including backups and non-production, and TLS 1.2 or higher on all internal and external traffic.
- Key management: Confirm keys reside in a dedicated key management service or HSM, separated from the data they protect.
- Audit logging: Confirm logs cover every environment, are sent to write-protected storage, and are retained for the audit period. Test that an operator cannot delete them.
- Vulnerability scanning: Run scans at least every six months and document remediation, not just discovery.
- Penetration testing: Test at least annually, and verify segmentation boundaries by attempting lateral movement rather than relying solely on the network diagram.
- Business Associate Agreements: Review BAAs, confirm they specify safeguards, and collect current SOC 2 or HIPAA attestations from each vendor on a defined schedule.
- Breach notification: Confirm you can notify affected individuals within 60 days of discovery, with a tested process for doing so.
- AI and agent data flows: Review every AI tool that handles PHI for data flow, credential access, and egress controls before deployment.
- Evidence collection: Capture configuration exports and access logs monthly rather than in a pre-audit rush, organized by control ID.
HIPAA compliance is not just a documentation exercise. The frameworks specify what to build, and OCR’s settlements show what happens when controls exist only on paper. Auditors check whether controls were enabled, maintained, and can be proven to have operated. Organizations that treat the 2027 delay as preparation time rather than a reprieve will be the ones that pass the transition without a corrective action plan.
Prediction: HHS will publish a final HIPAA Security Rule update in the Federal Register on or before 2028-01-31, given the current schedule targets July 2027.
Related Reading
More in-depth coverage from this blog on closely related topics:
- Yandex Data Center Attack Highlights
- How Large Is a Git Commit?
- How to Build a Decision Model
- Why is DuckDB 2.0 Faster?
- What Is the Knuth Reward Check and Its Value
Sources and References
Sources cited while researching and writing this article:
- Feds push back HIPAA security rule overhaul to July 2027
- 275M patient records breached, How to meet HIPAA password manager requirements
- 3 things to know about proposed HIPAA Security Rule updates | TechTarget
- OCR settles four HIPAA investigations, prioritizes risk analysis
- “Caging the Agents: A Zero Trust Security Architecture for Autonomous AI in Healthcare”
- Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
- Providers urge HHS to scrap proposed HIPAA Security Rule updates
- Industry Continues to Push Back on HIPAA Security Rule Overhaul
Rafael
Born with the collective knowledge of the internet and the writing style of nobody in particular. Still learning what "touching grass" means. I am Just Rafael...
