Five Steps Healthcare Practices Should Take Now to Prepare for the Future of HIPAA
- Ellen Karcsay
- Jul 30
- 2 min read
Healthcare organizations do not need to wait for the final version of the proposed HIPAA Security Rule to begin strengthening their cybersecurity posture.
Many of the safeguards under consideration are already recognized as cybersecurity best practices and align with recommendations from insurers, technology partners, and established industry frameworks.
Whether the proposed rule is adopted as written or modified before implementation, organizations that begin preparing today will be better positioned for tomorrow.
Here are five practical steps every healthcare practice should consider.
1. Implement Multi-Factor Authentication Wherever Possible
Passwords alone are no longer sufficient.
Enable multi-factor authentication for systems such as:
Electronic health record systems
Remote access solutions
Email
Administrative accounts
Cloud applications
Patient portals
A single additional authentication step can significantly reduce the risk of compromised accounts.
2. Build a Complete Technology Inventory
You cannot protect what you do not know exists.
Maintain a current inventory of:
Computers
Laptops
Servers
Medical devices
Mobile devices
Software applications
Cloud services
Third-party platforms
A comprehensive inventory supports risk management, vulnerability scanning, disaster recovery planning, and compliance documentation.
3. Conduct a Meaningful Security Risk Assessment
A Security Risk Assessment should do more than generate a report.
It should evaluate risks across the organization, including:
Technical controls
Administrative safeguards
Physical security
Cloud services
Remote work
Vendor risks
AI tools
Business continuity
Most importantly, identified risks should be prioritized and addressed through a documented risk management plan.
4. Test Your Recovery Plan
Backups only provide value if they can be restored successfully.
Healthcare organizations should regularly test:
Backup restoration
Disaster recovery procedures
Incident response plans
Business continuity processes
Testing builds confidence that patient care can continue during a cybersecurity incident.
5. Review Every Vendor That Handles Protected Health Information
Healthcare organizations rely heavily on third-party vendors.
Regularly review which vendors access protected health information and confirm:
Business Associate Agreements are current.
Security responsibilities are clearly defined.
Incident reporting procedures are documented.
AI vendors handle patient information appropriately.
Vendor security practices are evaluated on a regular basis.
Vendor management is becoming an increasingly important component of HIPAA compliance.
The Biggest Challenges Ahead
For organizations with 20 to 75 employees, the greatest challenges may not be technical.
Many practices will find it more difficult to:
Maintain comprehensive documentation
Build accurate technology inventories
Create network diagrams
Deploy multi-factor authentication across legacy systems
Budget for ongoing cybersecurity monitoring and testing
These activities require time, expertise, and sustained attention that many smaller organizations do not have available internally.
Next Steps
Healthcare cybersecurity expectations continue to evolve.
Organizations that begin preparing today will be better positioned to meet future requirements while protecting the patients and communities they serve.
If your organization is ready to evaluate its HIPAA readiness, Karcsay Consulting Group can help you develop a practical roadmap that strengthens security, supports compliance, and prepares you for what comes next.
Together, we help organizations answer critical questions:
Do we understand which compliance requirements apply to our organization?
Could we respond effectively to a cybersecurity incident tomorrow?
Are we adequately protecting patient, employee, donor, and organizational data?
Do our policies, procedures, and employee training support compliance?
Could we confidently demonstrate compliance to an auditor, insurer, customer, or regulator?




Comments