Back to Field Notes
Compliance & Regulation/Field Note

HIPAA Security Rule Modernization — What's Coming

Encryption stops being 'addressable.' MFA becomes mandatory. Asset inventories become testable. Start now.

Author

Mark Velasquez

Principal Standards Architect

Published

January 12, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Encryption of ePHI at rest and in transit moves from 'addressable' to 'required' — every legacy ePHI system without end-to-end encryption becomes a remediation project on the day the rule lands.
  • 02MFA on all access to ePHI, mandatory asset inventories, network maps, annual penetration tests, biannual vulnerability scans, and risk-based patch SLAs all become testable requirements.
  • 03Business associates pick up subcontractor verification with annual written attestations. SaaS vendors handling ePHI should plan for a wave of enhanced security questionnaires the moment the rule is finalized.
  • 04Asset and data-flow inventory is the lowest-risk, highest-leverage thing to start now — every other proposed control depends on knowing where ePHI lives and what touches it.

The HHS Office for Civil Rights's Notice of Proposed Rulemaking for the HIPAA Security Rule signals the most consequential changes since the rule was finalized in 2003. While the final rule may shift, several changes are widely expected to land.

Likely material changes

  • 01Encryption of ePHI at rest and in transit becomes 'required,' not 'addressable'
  • 02Multi-factor authentication for access to ePHI
  • 03Mandatory technology asset inventory and network mapping
  • 04Annual penetration testing and biannual vulnerability scans for in-scope systems
  • 05Documented patch management with risk-based timelines
  • 06Mandatory written incident response plan with annual exercises

The implication for business associates

The proposed rule sharpens business-associate obligations. BAs must verify the security practices of their subcontractors annually, with written attestations. SaaS vendors handling ePHI should expect a wave of enhanced security questionnaires the moment the rule lands.

Start with the inventory

Every other proposed control depends on knowing where ePHI is and what touches it. An accurate, automatically refreshed asset and data-flow inventory is the lowest-risk, highest-leverage thing to start now, regardless of how the final rule is worded.

#HIPAA#Healthcare#Privacy

/WRITTEN_BY

Mark Velasquez

Principal Standards Architect · Alexa Cybersecurity