AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

The HIPAA Security Rule Update Is Still a Proposal. The MFA Clock Is Not.

The HIPAA Security Rule update 2026 is still a proposal, with finalization projected for July 2027. Why MFA and encryption cannot wait for the final text.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsSeptember 2, 2026 · 6 min read

Forty seconds, six times an hour

The clinical director of an 18-clinician behavioral health group knows exactly why the nurse's station PC has a shared login. She was a charge nurse for eleven years. A clinician between sessions needs the chart in the time it takes to walk from one room to the next. Forty seconds of typing a personal password, six times an hour, is four minutes an hour, and that is time that comes out of patients.

So the password is on a sticky note under the keyboard, and it has been since 2021.

In July the IT contractor tells her not to worry about multifactor authentication because "the HIPAA update isn't final". In August she reads that a practice two counties over had its EHR locked by ransomware and the first thing the investigators asked about was how the attackers got a valid login. The answer was a password that had been shared with a former employee.

She looks at the sticky note. She counts the people who have used that login since 2021 and stops at thirty. Four of them no longer work there. One of them left angry.

She asks me the question every practice owner asks: how long do we have? The honest answer is that the regulator's clock and the attacker's clock are two different clocks, and only one of them is paused.

The rule change, in plain words

The HIPAA Security Rule is the part of HIPAA that says how electronic patient information must be protected. It was written when a fax machine was a reasonable safeguard.

An NPRM is a notice of proposed rulemaking: a draft regulation published for public comment. HHS published one in January 2025. It is still a draft, and HHS now projects finalization in July 2027.

Addressable versus required is the current rule's habit of letting a practice decide whether some safeguards, encryption and MFA among them, are "reasonable and appropriate" for its size. The proposal removes that distinction. Everything becomes required.

MFA, multifactor authentication, means a login needs something beyond a password: a code, a push notification, a badge tap. The proposal makes it mandatory for access to ePHI, with no exemption for small practices.

Here is what "not final" does not change. The current rule already requires a risk analysis, and any honest risk analysis of a shared login with thirty users and a sticky note reaches the same conclusion the proposal reaches. The proposal is telling you the answer to a question you are already required to ask.

The numbers that matter

The proposed Security Rule received more than 4,700 public comments, and the target for finalization has moved to July 2027, according to HHS OCR's 2026 rulemaking status. That is the regulator's clock.

The January 2025 NPRM from HHS removes the addressable-versus-required distinction and mandates MFA and encryption with no exemption for practice size, per the text of the proposal itself. The direction is not in doubt; only the date is.

MFA was missing where it mattered in 59% of the frontline incident cases Sophos analyzed in its 2026 report. That is the attacker's clock, and it is running.

What to do this week

  1. Count the shared logins. Walk every workstation, every tablet, every portal, and list each account that more than one person uses. You cannot fix what you have not counted. (CIS 5 Account Management)
  2. Turn on MFA for the EHR, email and any remote access, and choose a method a clinician can complete in five seconds: a badge tap or a phone push, not a six-digit code typed between rooms. The forty-second problem is a design problem, and it has been solved. (CIS 6 Access Control Management)
  3. Check that every laptop and phone that touches patient data has full-disk encryption switched on, and keep a screenshot of the status for each. A stolen encrypted laptop is a lost asset; an unencrypted one is a breach. (CIS 3 Data Protection)
  4. Route patient email through encryption, or through the portal, and tell staff which one to use for which message. Reply-all to a referral with a diagnosis attached should not be possible from a personal Gmail. (CIS 3 Data Protection)
  5. Set a patch day. Once a month, every workstation and the EHR server get their updates, and someone signs off that it happened. (CIS 7 Continuous Vulnerability Management)
  6. Write down your decision on each addressable safeguard under the current rule, today, with the reason. When the final rule lands, that document becomes your head start instead of your gap list. (CIS 6 Access Control Management)

Where AccuSights fits

We treat the proposal as the answer key for the risk analysis you already owe. Our assessment maps each addressable safeguard to what your practice runs, then our team implements the controls at a reasonable rate: MFA that fits a clinical workflow, encryption on every device, scanning that catches the missed patch. In major US cities an AccuSights cybersecurity engineer comes on site to set up the critical controls and the protection agent, so the office is protected the same week. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.

Questions people ask

When will the new HIPAA Security Rule take effect? It has not been finalized. The proposed rule was published in January 2025, drew more than 4,700 comments, and HHS now projects finalization in July 2027. A final rule normally gives a compliance window after publication, so the earliest realistic enforcement of the new text is 2028. The current Security Rule, including the risk analysis requirement, is in force today and OCR is enforcing it.

Does HIPAA require encryption of email? Under the current rule, encryption is an addressable specification: you must assess it and either implement it or document why an equivalent measure is reasonable. In practice, sending patient information over unencrypted email is a finding OCR has cited repeatedly. The proposed rule would remove the addressable label and require encryption in transit and at rest, so the sensible reading is that email carrying ePHI needs encryption now.

Will small practices get an exemption? The proposal contains no size exemption. A solo practice and a hospital system would face the same MFA and encryption requirements, with the difference being scale, not obligation. HHS asked for comment on the burden to small providers, and that is one reason the timeline moved, but nothing in the record suggests a carve-out.

A rule tells you what to do by 2027. A sticky note tells an attacker what to do tonight. Fix the note first.

Controls this post maps to

CIS 6 Access Control ManagementCIS 3 Data ProtectionCIS 7 Continuous Vulnerability Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.