Under the old rule, many security controls were labeled "addressable," meaning a practice could choose not to implement them as long as it documented a reasonable alternative or justification. The 2026 update removes that flexibility for most core controls — they're now required, full stop, with very narrow exceptions.
Multi-factor authentication is now required on every system that touches patient data, not just recommended. Encryption is required both for stored data and data in transit, with very limited exceptions. Vulnerability scanning must happen quarterly, and penetration testing annually. A written, tested incident response plan is mandatory, not optional documentation. And every practice needs a current inventory of every device and system that touches PHI.
Non-compliance exposure comes from two directions: OCR enforcement (fines that, for small practices, have historically ranged from roughly $10,000 to $80,000 depending on severity and circumstances) and the much higher cost of an actual breach — incident response, patient notification, potential lawsuits, and reputational damage that can be fatal to a small practice.
Most practices don't need to build an internal security team. They need a clear-eyed assessment of where they stand today, a prioritized plan for closing the gaps, and either the in-house discipline or an outside partner to keep it maintained as requirements keep evolving.
If you haven't had a formal assessment against the 2026 rule yet, that's the place to start — and it's free to find out where you stand.
Get a free 30-minute readiness check — no pressure, just clarity on what you need.
Get My Free Readiness Check