For more than two decades, HIPAA compliance operated on an honor system. Covered entities and business associates could label many security safeguards “addressable,” document a reasonable justification if they skipped one, and move on. A signed Business Associate Agreement (BAA) was often treated as sufficient proof that a vendor’s technology was secure.
That era is ending.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has proposed the most sweeping update to the HIPAA Security Rule since it was first adopted, and the message to healthcare organizations, dental practices, behavioral health providers, insurance brokers, and every business associate that touches protected health information (PHI) is unambiguous: you can no longer just say you’re compliant. You have to prove it.
What’s Actually Changing in the 2026 HIPAA Security Rule Update
The proposed rule was issued as a Notice of Proposed Rulemaking and, as of mid-2026, is still working through the federal review process — OCR has been reviewing thousands of public comments, and the finalization timeline has slipped from an original spring 2026 target. But the direction of travel is not in question, and organizations that wait for a final rule before preparing are setting themselves up for an impossible compliance sprint once the effective date hits. Here’s what the update is expected to require:
The end of “addressable” safeguards
Under the current rule, safeguards like encryption and multi-factor authentication (MFA) are classified as “addressable,” meaning an organization can decide they’re not reasonable for its environment and document why. Under the new rule, that flexibility disappears. Encryption of ePHI at rest and in transit, MFA across all systems touching patient data, regular vulnerability scanning, and penetration testing all become mandatory, full stop.
Written technology asset inventories and network maps.
Organizations will need a current, annually updated inventory of every system and every vendor that creates, receives, maintains, or transmits ePHI — along with a network map showing exactly where that data flows. Ad-hoc server deployments and “shadow IT” are no longer an option regulators will accept.
Mandatory network segmentation.
To limit how far an intruder can move if one system is compromised, the proposed rule calls for network segmentation as a standard requirement, not a best practice left to individual judgment.
Annual, written verification of business associate safeguards.
This is the change that should get every business owner’s attention. A signed BAA will no longer be enough. Covered entities will be required to obtain written, annual verification — with real evidence, not just a signature — that every business associate and subcontractor has actually implemented the required technical safeguards. Business associates will also face new direct-liability requirements, including confirming their contingency and safeguard status within a tight window after any activation of a disaster recovery plan.
Stricter documentation and audit requirements.
Comprehensive written security policies, risk analyses tied to the asset inventory, incident response plans, and regular internal audits will all need to exist in a form that can withstand outside scrutiny — not just internal peace of mind.
A short compliance runway once the rule is final.
Once published, organizations are expected to have roughly 240 days (a 60-day effective date plus a 180-day compliance window) to fully implement the new requirements. For any organization still running on legacy systems, unmanaged devices, or informal vendor relationships, that is not a lot of time.
Why “Proving” Compliance Is So Much Harder Than “Having” Compliance
The practical effect of these changes is a shift from a policy-driven compliance model to an architecture-driven one. It’s no longer enough to have a HIPAA policy binder on a shelf. Regulators, auditors, cyber insurers, and increasingly your own customers will expect you to demonstrate — in writing, with evidence — that:
- Every phone system, softphone, and voicemail platform handling patient calls is encrypted and access-controlled
- Every network device, firewall, and Wi-Fi access point is segmented and monitored
- Every laptop, server, and endpoint is patched, encrypted, and covered by MFA
- Every cloud application storing or processing PHI has a verifiable, audited security posture
- Every vendor in your technology stack can produce its own proof of compliance on demand
For most small and mid-sized businesses, that’s not a one-department problem. It touches phones, networking, IT support, cloud infrastructure, and cybersecurity all at once — and very few in-house IT teams have the bandwidth, specialized expertise, or vendor relationships to manage all five simultaneously while also running day-to-day operations.
Why a Technology Advisory Firm Is No Longer Optional
This is exactly the gap a technology advisory firm is built to close. Rather than trying to become an expert in HIPAA-compliant VoIP, network architecture, managed IT, cloud hosting, and cybersecurity all on your own — or gambling on a single vendor that’s strong in one area and weak in the rest — a technology advisory firm gives you access to a curated bench of leading HIPAA-compliant providers across every layer of your technology stack, and helps you assemble the right combination for your business.
Here’s what that looks like in practice:
Phones. HIPAA-compliant voice systems need encrypted calls, secure voicemail transcription, business associate agreements from the carrier itself, and call-recording controls that don’t create new compliance exposure. An advisory firm already knows which providers meet this bar and which merely claim to.
Networking. Network segmentation, secure Wi-Fi, firewalls configured to HIPAA standards, and continuous monitoring aren’t a single product — they’re a designed system. A technology advisor can architect and source that system instead of leaving it to whichever hardware happens to be on hand.
IT Support. Ongoing patch management, endpoint encryption, MFA rollout, and help-desk support all need to be delivered by a team that understands HIPAA documentation requirements, not just general IT troubleshooting.
Cloud & Cybersecurity Solutions. From HIPAA-compliant cloud hosting and backup to vulnerability scanning, penetration testing, and incident response planning, this is where most of the new rule’s technical burden lands — and where the risk of getting it wrong is highest.
The Real Value: One Partner, Verified Vendors, Continuous Proof
The organizations best positioned for the 2026 HIPAA Security Rule update won’t be the ones scrambling to interpret a 200-page proposed rule on their own. They’ll be the ones who partnered early with a technology advisory firm that:
- Already vets vendors against HIPAA’s technical safeguard requirements, so you’re not the one auditing every provider from scratch
- Can produce and organize the written documentation, verification records, and asset inventories regulators will expect
- Coordinates phones, networking, IT support, cloud, and cybersecurity as one connected compliance strategy instead of five disconnected vendor relationships
- Keeps pace with the rule as it moves from proposal to final form, so your compliance posture doesn’t go stale the moment the ink dries
Compliance is moving from a checklist to an architecture. Businesses that treat this shift as a one-time IT project will fall behind. Businesses that treat it as an ongoing partnership — with a technology advisor who already knows which solutions actually hold up — will be the ones who can answer OCR’s central question with confidence: not “we think we’re compliant,” but “here’s the proof.”
Get a FREE HIPAA Compliance Assessment
You don’t have to wait for a final rule — or an audit — to find out where your organization stands. The technology advisors at My Resource Partners offer a FREE HIPAA Compliance Assessment that reviews your current phones, networking, IT support, cloud, and cybersecurity setup against the safeguards regulators are already signaling will become mandatory.
In this no-cost assessment, the My Resource Partners team will:
- Identify gaps in encryption, MFA, and network segmentation across your existing systems
- Review whether your current vendors can actually produce written proof of HIPAA compliance — not just a signed BAA
- Map out where PHI lives across your phones, network, cloud, and endpoints
- Recommend a prioritized, budget-conscious path to close any gaps before they become audit findings or breach liabilities
There’s no obligation and no pressure — just a clear picture of where you stand today and what the 2026 HIPAA Security Rule update will mean for your business. Reach out to My Resource Partners and get ahead of the deadline before it arrives.


