HIPAA Is Changing, and Small Healthcare Practices Need to Prepare Now
- Ellen Karcsay
- Jul 2
- 2 min read
When most healthcare professionals think about HIPAA, patient privacy is usually the first thing that comes to mind.
While privacy remains a core component of HIPAA, the most significant changes on the horizon focus on something else: cybersecurity.
Over the past several years, ransomware attacks, data breaches, and cyberattacks targeting healthcare organizations have increased dramatically. In response, the U.S. Department of Health and Human Services (HHS) has proposed the most significant update to the HIPAA Security Rule since it was introduced more than two decades ago.
For independent physician practices, dental offices, behavioral health providers, specialty clinics, and nonprofit healthcare organizations, these proposed changes could represent the most significant compliance shift in years.
Why the HIPAA Security Rule Is Being Updated
The proposed updates are intended to strengthen cybersecurity across the healthcare industry and reduce the growing impact of ransomware attacks that disrupt patient care.
Historically, HIPAA provided flexibility. Certain security safeguards were considered "addressable," allowing organizations to implement alternative protections when appropriate based on their size, complexity, and available resources.
The proposed rule significantly reduces that flexibility.
Rather than asking whether a safeguard is reasonable, regulators are increasingly asking whether it has been implemented.
What Could Become Required?
Although the rule has not yet been finalized, healthcare organizations should expect significantly higher expectations around cybersecurity fundamentals.
Proposed requirements include:
Multi-factor authentication (MFA) for systems containing electronic protected health information (ePHI)
Encryption of patient information both at rest and in transit
Comprehensive inventories of devices, software, servers, cloud applications, and connected systems
Network diagrams documenting how patient information moves throughout the organization
Regular vulnerability scanning
Annual penetration testing
Written incident response plans
Disaster recovery testing
Stronger backup and business continuity capabilities
Many of these practices are already considered cybersecurity best practices. The challenge is implementing them consistently and documenting that they are working effectively.
Why Smaller Practices Will Feel the Greatest Impact
Large health systems often have dedicated cybersecurity teams, compliance departments, and significant technology budgets.
Most independent practices do not.
Many smaller organizations rely on a single IT provider, office manager, or small administrative team to oversee technology, compliance, and day-to-day operations.
Requirements such as network mapping, vulnerability management, and continuous documentation can quickly become difficult to maintain without additional expertise.
In many cases, legacy electronic health record systems may also require upgrades before newer security controls, including multi-factor authentication, can be implemented.
Preparing Before the Rules Become Final
Although the proposed Security Rule remains under review, waiting until the final rule is released could leave organizations rushing to meet new expectations.
Healthcare leaders should begin evaluating their cybersecurity posture now by identifying gaps, prioritizing improvements, and strengthening governance over time.
Organizations with documented cybersecurity programs, mature risk management practices, and trusted technology advisors will be far better positioned if these requirements become final.
Looking Ahead
Technology is only one part of compliance. In Part 2 of this series, we will explore one of the most overlooked aspects of the proposed HIPAA changes: documentation.
As cybersecurity expectations continue to evolve, demonstrating compliance may become just as important as implementing security controls.
If your organization is evaluating its cybersecurity readiness, Karcsay Consulting Group can help you assess risk, strengthen compliance, and prepare for evolving HIPAA requirements. Reach out to schedule a consultation and begin the conversation.




Comments