Separate a proposal from a requirement
Healthcare practices need a reliable way to understand security obligations without treating every headline as a new deadline. HHS has proposed changes to the HIPAA Security Rule. On its rulemaking page, HHS states that the current Security Rule remains in effect while the department undertakes that process. A proposal should inform planning, but it should not be described as a final requirement.
The earlier version of this article predicted a final rule in May 2026 and later compliance dates. Those predictions were not a sound basis for a practice's compliance calendar. Check the HHS rulemaking page and work with your compliance adviser to distinguish existing obligations, proposed changes, final rules, and the dates that actually apply to your organization.
Start with the systems that hold patient information
Preparation begins with knowing your environment. A practice may use an electronic health record, imaging workstations, billing software, email, a patient portal, cloud storage, and several specialist vendor connections. Each can have different administrators and support arrangements. A list of software names is useful, but a list of responsibilities is more useful.
- Identify where electronic patient information is created, received, maintained, and transmitted.
- Record the devices, applications, cloud services, and people involved in each workflow.
- Name the person responsible for access, configuration, maintenance, and vendor coordination.
- Record where documentation lives and who can retrieve it if the usual administrator is unavailable.
This work helps the practice ask specific questions. Instead of asking whether the office is secure, you can ask who reviews access to imaging files or how the practice would recover its scheduling system after an outage.
Review access before changing the login process
Staff, clinicians, outside billing teams, and equipment vendors may need different access. Review named accounts, permissions, account recovery, remote access, and the process for people joining or leaving the practice. Keep routine use separate from administrator access where the systems support it.
Discuss stronger authentication with the people who manage each application. Confirm which methods the vendor supports, how staff will enroll, and what happens when a phone or security key is lost. Pilot changes with a small group before changing a workflow the whole practice relies on. An emergency access procedure should be documented and controlled.
Make backup and recovery a business conversation
A successful backup message does not show that the practice can resume work. Ask which data and configuration are protected, where copies are held, who can access them, and how restoration is tested. Include systems beyond the main clinical application, such as shared files, cloud email, and device configuration.
Work through an ordinary scenario with the front desk: the scheduling system is unavailable at opening time. Who makes the first call? How does the team communicate? What can staff do safely while recovery is underway? Which vendor needs to participate? The answer should reflect the practice's actual systems and responsibilities.
Bring vendors into the same plan
Technical work and compliance responsibilities often cross company boundaries. Your IT provider may manage workstations while an application vendor controls the hosted clinical system. A separate company may operate the patient portal or handle backups. Confirm the scope with each provider instead of assuming one agreement covers everything.
- Keep current contacts for service, security, and escalation.
- Identify who approves and records remote access.
- Review applicable agreements with the practice's compliance or legal adviser.
- Understand incident notification procedures and the responsibilities defined in each agreement.
- Include subcontractor and data-location questions where they apply to the service.
Turn a gap list into a workable budget
Separate immediate operational problems from planned improvements and items that depend on future rulemaking. Record why an item matters, the systems affected, its owner, and the proposed next action. Ask for a written scope covering equipment, licenses, installation, documentation, staff training, and ongoing work.
Some decisions will need input from the clinical team, compliance adviser, insurer, or application vendor. Put that dependency in the plan. A clear list of decisions is more useful than buying tools before the practice knows how they will be operated.
Keep the review current
Revisit the plan when the practice adds an application, changes providers, opens a location, or changes how staff work. Keep a record of the decisions and supporting evidence. If HHS publishes a final rule, review the actual text and applicability before changing the compliance calendar.
Other healthcare privacy requirements can have their own scope and dates. Do not assume that a general HIPAA article determines whether a particular notice, consent process, or substance use disorder record rule applies to your practice. Bring those questions to a qualified adviser.
A practical first conversation
UX Genius can help discuss the technology side of the plan, including access, device management, network design, backup, and vendor coordination. The free assessment starts with a 30-minute conversation. We use it to understand your priorities and recommend whether a more detailed technical review is needed.
Explore healthcare IT services or book a free assessment. Your practice's compliance decisions should be made with the appropriate advisers and a scope grounded in your actual environment.
Source documents and current details
Use the original guidance when a policy, product, or contract detail matters to your decision.
Healthcare IT