TLDR: Federal regulators have proposed the first major overhaul of the HIPAA Security Rule in more than two decades, and the final version is now projected for July 2027. The update would require encryption of patient data, multifactor authentication, annual penetration testing, a written technology asset inventory, and the ability to restore critical systems within 72 hours. Practices will have roughly 240 days after the final rule publishes to come into compliance, which is not enough time to start from zero. The smartest approach is to begin closing gaps now, starting with a current risk analysis and an honest inventory of every system that touches patient records.

 

Most small medical, dental, and specialty practices did not build their technology around a security framework. They built it around getting patients through the door. The practice management software came first, then a server in a back closet, then a few laptops, then a cloud portal, then remote access so the billing person could work from home on Fridays.

That patchwork has been good enough under the current HIPAA Security Rule, which was written in 2003 and left most safeguards optional as long as a practice documented why. The proposed update changes that. It removes the flexibility that small practices have leaned on and replaces it with specific, testable requirements.

The 2027 HIPAA Security Rule update is not law yet, and the timeline has already slipped once. But the direction is clear, and the preparation work is the same work that protects a practice from ransomware today. At Inland Productivity Solutions, we help small healthcare organizations across the Inland Empire get ahead of these requirements instead of scrambling after them.

What the 2027 HIPAA Security Rule Update Actually Changes

The Office for Civil Rights published a notice of proposed rulemaking in January 2025. The final rule was originally expected in 2026, but the federal regulatory agenda now projects July 2027. Once it publishes, covered entities and business associates get about 240 days to comply.

The single biggest structural change is the removal of the difference between required and addressable safeguards. Under the current rule, an addressable safeguard such as encryption can be skipped if a practice writes down a reasonable justification and puts an alternative in place. Under the proposal, nearly everything becomes mandatory with only narrow exceptions.

Here are the changes that matter most for a small practice.

Encryption of all patient data at rest and in transit

Records sitting on a server, a laptop hard drive, a backup drive, or moving across email would all need to be encrypted.

Multifactor authentication for access to patient records

A password alone would no longer be enough to open the practice management system or the email account that receives referrals.

A written technology asset inventory and network map

Every device, application, and connection that touches patient data would need to be documented and updated at least once a year.

Vulnerability scans every six months and penetration testing every year

These are active tests that look for weaknesses, not a checklist someone fills out from memory.

Restoration of critical systems and data within 72 hours

The practice would need written procedures that prioritize which systems come back first, and those procedures have to be tested.

Notification within 24 hours when staff access changes

When an employee leaves or changes roles, certain partners have to be told within a day.

Annual verification of vendors and business associates

A signed agreement is no longer enough. Practices would need written confirmation each year that vendors actually have the required safeguards in place.

 

Why Small Practices Feel This More Than Large Health Systems

A hospital network has a security officer, a compliance department, and a budget line for penetration testing. A six-person dental office has an office manager who already handles scheduling, insurance verification, payroll questions, and the copier that jams every Tuesday.

The requirements do not scale down. A practice with eight employees would need the same asset inventory, the same annual testing, and the same 72-hour recovery capability as an organization with eight hundred. Federal estimates put first-year industry compliance costs near nine billion dollars, and small practices absorb a disproportionate share of that relative to their revenue.

There is a second problem. Small practices are already the preferred target. Attackers know that a clinic running an unpatched server with no network segmentation is a faster payday than a hospital with a security operations center. The requirements in this update are not arbitrary. They map closely to how healthcare breaches actually happen.

Common Mistakes Practices Make Before a Compliance Deadline

The gaps we see most often are the same ones that will be hardest to close in an eight-month window.

Treating the risk analysis as a form

Many practices have a risk assessment document from 2019 that nobody has looked at since. A real analysis lists actual systems, actual threats, and actual decisions.

Assuming the software vendor handles security

A cloud practice management vendor secures its own platform. It does not secure the laptop a staff member uses to log in from a coffee shop.

Confusing a backup with a recovery plan

Files copying to an external drive is a backup. Knowing that the schedule, the charts, and the billing system can be running again by Thursday is a recovery plan.

Leaving former employees with active accounts

Access that was never turned off is one of the most common findings in breach investigations and one of the easiest to fix.

Running everything on one flat network

When the guest Wi-Fi, the front desk computers, and the server all sit on the same network, one infected device reaches everything.

A Real Example of What Goes Wrong

A four-provider physical therapy clinic stored patient charts on a single server in a supply room. Backups ran to a USB drive that stayed plugged into that same server. Staff shared one login for the scheduling system because it was faster during busy mornings.

Ransomware arrived through an email attachment opened at the front desk. It encrypted the server and the attached backup drive at the same time. The clinic could not tell investigators which records were accessed, because the shared login made it impossible to trace activity to a person. Rebuilding took eleven days, and the practice canceled appointments the entire time.

Every failure in that story maps to a proposed requirement. Separate backup controls, unique user accounts with multifactor authentication, network segmentation, and a tested 72-hour restoration procedure would have changed the outcome.

How Should a Small Healthcare Practice Prepare for the 2027 HIPAA Security Rule Update?

How to Prepare Between Now and 2027

Preparation does not require guessing at final rule language. Work through these in order.

Build the asset inventory first

List every server, workstation, laptop, phone, application, and cloud service that stores or transmits patient data. Nothing else can be planned accurately until this exists.

Run a current risk analysis

Use the inventory to identify where data lives, who can reach it, and what would happen if each system failed or was compromised.

Turn on multifactor authentication everywhere it is available

Email, remote access, and the practice management system are the priorities. This is usually free and can be done in an afternoon.

Verify encryption on every device and backup

Full disk encryption is built into current versions of Windows and macOS. Confirm it is actually turned on rather than assuming.

Test a restore, not just a backup

Pick a system and actually bring it back from backup. Time it. If it takes longer than 72 hours, the plan needs work.

Segment the network

Separate guest Wi-Fi, clinical systems, and any connected medical devices so one compromise does not become a practice-wide outage.

Tighten the onboarding and offboarding process

Write down who grants access, who removes it, and how quickly. Twenty-four hours is the standard to aim for.

Collect written security attestations from vendors

Ask each vendor that handles patient data to confirm in writing what safeguards they have. Start now so it is routine by 2027.

Working with a partner that provides managed IT services and cybersecurity support services lets a small practice cover these requirements without hiring internal security staff. 

What This Costs and How to Budget for It

Cost depends heavily on where a practice is starting. A clinic already running current hardware, cloud email with multifactor authentication, and a managed backup service may only need documentation work, testing, and vendor attestations.

A practice running an aging on-site server, no formal backup testing, and a flat network is looking at real infrastructure spending. Spreading that across two budget years is far easier than absorbing it in a single eight-month compliance sprint, which is exactly why starting now matters more than the exact final rule text.

A reasonable approach is to fund the inventory and risk analysis first, since those determine everything else. Then address the highest-risk gaps, usually backup and recovery plus access control. Infrastructure replacement can follow on a normal refresh cycle rather than an emergency purchase.

 

Frequently Asked Questions

Is the 2027 HIPAA Security Rule update already law? No. It is a proposed rule published in January 2025, and the final version is currently projected for July 2027. The timeline has already moved once, so the date could shift again. The underlying security expectations are unlikely to disappear.

How much time will practices have to comply after the final rule publishes? The proposal allows roughly 240 days, or about eight months. That window is short for a practice that has not started, especially if hardware needs to be replaced or a network needs to be redesigned.

Are small practices exempt because of their size? No exemption based on practice size has been proposed. The requirements apply to covered entities and business associates regardless of headcount, though how they are implemented will look different at a six-person clinic than at a hospital.

Do these rules apply to our billing company and IT vendor? Yes. Business associates are covered, and the proposal adds annual written verification that they have the required technical safeguards in place. Ask your vendors now what their plan is.

What is the single most valuable thing to do first? Build an accurate inventory of every system that touches patient data, then run a real risk analysis against it. Almost every other requirement depends on knowing what you actually have.

Will our current backup system meet the 72-hour restoration requirement? Only testing will tell you. Many practices discover that a restore takes days longer than expected, or that the backup was never capturing a critical database. A tested data backup and recovery process is the only reliable answer.

 

Building a Practice That Is Ready Before the Rule Takes Effect

The 2027 HIPAA Security Rule update is best understood as regulators writing down what good healthcare security already looks like. Encryption, multifactor authentication, tested backups, network segmentation, and knowing what is on your network are not compliance chores. They are the controls that keep a practice open when something goes wrong.

A practice that spends the next eighteen months closing gaps steadily will meet the deadline without disruption and will be far harder to attack in the meantime. A practice that waits will be making expensive decisions under pressure. The work is the same either way. Only the cost and the stress level change.

If your practice needs help building a technology asset inventory, running a current risk analysis, or closing the security gaps the 2027 HIPAA Security Rule update will require, contact Inland Productivity Solutions today to discuss a practical compliance roadmap and the IT consulting services that get you there on your own timeline.