Skip to content
Bellator Cyber Guard
Healthcare17 min readDeep Dive

HIPAA Cybersecurity Requirements: 2026 Security Rule Guide

The HIPAA Security Rule requires administrative, physical, and technical safeguards for ePHI. See the 2026 requirements and OCR penalty exposure.

By Bellator Cyber Guard
HIPAA Cybersecurity Requirements: 2026 Security Rule Guide - hipaa cybersecurity requirements

The HIPAA Security Rule, codified at 45 CFR Part 164, Subparts A and C, requires every covered entity and business associate to protect electronic protected health information (ePHI), meaning individually identifiable health information created, received, stored, or transmitted electronically, through administrative, physical, and technical safeguards. In practice that means a documented risk analysis, a named security official, access controls and audit logging on every system that touches ePHI, signed Business Associate Agreements with every vendor that handles ePHI, and six years of retained policy documentation. The Office for Civil Rights (OCR), the HHS division that investigates HIPAA complaints and enforces the Security Rule, has assessed more than $135 million in penalties over the past decade. Most practices researching HIPAA cybersecurity services are trying to answer two questions at once: what does the rule actually require, and can we meet it without hiring a full-time security team. This guide answers both.

Quick Answer

The HIPAA Security Rule requires administrative, physical, and technical safeguards for ePHI, built around a documented risk analysis, unique-user access controls with audit logging, encrypted transmission, signed Business Associate Agreements with every vendor, and six years of written policy retention. Required specifications must be implemented as written; addressable specifications can be met with a documented, equivalent alternative sized to your organization. Most practices without a dedicated security team meet these requirements by combining internal policy work with a managed provider for the technical controls.

Healthcare has ranked first for the costliest data breaches of any industry for 14 consecutive years. According to IBM's Cost of a Data Breach Report 2024, the average healthcare breach now costs $9.77 million, nearly double the $4.88 million cross-industry average, once incident response, notification, and lost business are counted alongside any regulatory fine. Separately, HHS's Office for Civil Rights has assessed more than $135 million in HIPAA penalties and resolved over 30,000 complaints over the past decade. The pattern in OCR's published resolution agreements is consistent: missing risk analysis, weak access controls, missing Business Associate Agreements, and audit logs nobody reviewed. Those four gaps drive most enforcement actions, which makes them the right starting list for auditing your own program.

The Security Rule applies to three groups: covered entities (health plans, clearinghouses, and providers that transmit ePHI electronically), business associates (vendors and contractors that create, receive, maintain, or transmit ePHI on a covered entity's behalf), and subcontractors handling ePHI for a business associate. It only reaches electronic PHI; paper records fall under the separate HIPAA Privacy Rule. Because nearly every clinical workflow now runs through an EHR, patient portal, billing platform, or telehealth session (see our guide on HIPAA-compliant video conferencing for telehealth providers), almost every healthcare operation is in scope. Each safeguard category contains required specifications, which must be implemented exactly as written, and addressable specifications, which can be met through a documented, equivalent alternative. Addressable does not mean optional. NIST Special Publication 800-66 Revision 2Implementing the HIPAA Security Rule, is HHS's recommended reference for translating these requirements into specific controls.

2026 Proposed Rule: MFA and Encryption Mandates Pending

HHS proposed updates to the Security Rule in December 2024 that would make Multi-Factor Authentication (MFA) mandatory for all ePHI access and convert several addressable encryption specifications into hard requirements. As of September 2026, the proposal remains under regulatory review. OCR already treats MFA as an expected control in its enforcement approach, so practices without it should not wait for final rulemaking to add it. Check HHS's HIPAA Security Rule guidance for the current status before making compliance decisions.

HIPAA Security Rule Compliance Checklist

  • Conduct and document an organization-wide risk analysis under §164.308(a)(1)(ii)(A)
  • Name a security official responsible for Security Rule implementation
  • Assign unique user IDs to everyone who accesses ePHI
  • Turn on multi-factor authentication for every ePHI access point
  • Enable and regularly review audit logs on EHR, billing, and any system storing ePHI
  • Encrypt ePHI in transit using TLS 1.2 or higher
  • Set automatic logoff on clinical workstations
  • Test data backup and disaster recovery procedures on a set schedule
  • Sign a Business Associate Agreement with every vendor that touches ePHI
  • Deliver role-appropriate security awareness training annually
  • Document media disposal procedures for retired devices
  • Retain Security Rule policies and procedures for six years

The rule organizes controls into three categories. Administrative safeguards, under §164.308, are the largest section and cover the security management process, workforce training, the assigned security official, and contingency planning. The risk analysis inside the security management process is the single most scrutinized item in OCR investigations; investigators ask to see it first and question the named security official about it directly.

Physical safeguards, under §164.310, cover facility access controls, workstation security, and device and media controls. These get underestimated in small practices more than any other category. A reception workstation facing the waiting room, an unlocked server closet, or a hard drive discarded instead of wiped or destroyed are recurring findings in OCR breach investigations, and each has triggered six-figure penalties on its own. If you run a smaller practice, our HIPAA compliance guide for chiropractors walks through how these controls apply outside a large clinical setting.

Technical safeguards, under §164.312, are built into the systems themselves: unique user identification, audit controls, integrity controls to detect unauthorized changes to ePHI, transmission security, and person or entity authentication. Encryption for ePHI in transit and at rest is addressable rather than required, but OCR expects it in virtually every circumstance where ePHI leaves a secured network (see our healthcare data encryption overview and our explainer on symmetric versus asymmetric encryption).

A defensible risk analysis covers six elements: where ePHI lives, including cloud platforms and mobile devices; the threats reasonably anticipated against it; weaknesses in current controls; the likelihood and impact of each threat-vulnerability pairing; how well existing safeguards address that risk; and an overall risk rating that feeds a written risk management plan with assigned owners and deadlines under §164.308(a)(1)(ii)(B). A risk analysis that never turns into remediation work satisfies the paperwork requirement but not the intent of the rule, and OCR investigators are practiced at spotting that gap during a post-breach review. If your last risk analysis is more than a year old, or your systems have changed meaningfully since it was written, updating it should be the first item on your list.

The Four Gaps Behind Most OCR Enforcement Actions

OCR's published resolution agreements point to the same four gaps in almost every case: no risk analysis, weak access controls, missing Business Associate Agreements, and audit logs that were never reviewed. Closing those four gaps addresses most of the enforcement risk a typical practice carries.

Every vendor that creates, receives, maintains, or transmits ePHI on your behalf, whether a cloud storage provider, EHR platform, billing service, or IT support company, needs a signed Business Associate Agreement (BAA) before any data sharing starts, under §164.314. A BAA is a contract required under HIPAA that specifies permitted uses of ePHI, requires the vendor to implement its own safeguards, and obligates it to report breaches. Without one, any ePHI access by that vendor is an unauthorized disclosure regardless of whether a breach ever happens. Subcontractors count too: if your billing vendor routes claims through a clearinghouse, that clearinghouse needs its own BAA with the billing vendor.

Penalty tiers under HIPAA range from $100 to $50,000 per violation category, with annual caps around $2 million per category, and willful neglect that isn't corrected carries mandatory minimum penalties. State attorneys general in California, New York, and Texas have also brought independent HIPAA enforcement actions, so exposure isn't limited to federal action alone. In practice, the difference between a corrected finding and a formal penalty usually comes down to documentation: can you show you identified the gap, fixed it, and kept records of the process.

Meeting these requirements is ongoing work, not a one-time project, which is why most practices without dedicated IT security staff pair internal policy work with a managed provider for the technical safeguards. When comparing options, separate software licenses from managed services. A low-cost endpoint tool license is not the same scope as a managed service that includes monitoring, response, and documentation an auditor can review, so confirm what's actually included before comparing price.

Bellator Shield is Bellator Cyber Guard's managed endpoint detection and response (EDR) service, priced at $19 per computer per month, and covers the monitoring and response layer behind the access control and audit logging requirements in §164.312. Bellator Core, at $33 per computer per month, adds remote monitoring and Ransomware Rollback®, which supports the contingency planning and backup testing requirement in §164.308(a)(7). Compare the two on our protection plans comparison page, or see the Bellator Shield and Bellator Core product pages for what's included at each tier. Neither guarantees a breach won't happen, but both reduce the specific gaps OCR cites most often.

What to Ask a HIPAA Security Vendor

  • Will you sign a Business Associate Agreement before handling any ePHI?
  • Can you provide documentation OCR would accept during an investigation?
  • Do you support audit logging across our EHR, billing, and email systems?
  • How do you test and verify backup and disaster recovery procedures?
  • Is this a managed service or a software license only, and what's included at each tier?
  • How do you handle incident response and breach notification timelines?

Talk with a cybersecurity expert

Get a practical read on where your HIPAA technical safeguards stand and what it would take to close the gaps.

Frequently Asked Questions

Not yet as a hard requirement. Person or entity authentication is required under §164.312(d), but MFA specifically is only proposed as mandatory in HHS's pending rule change from December 2024, still under review as of September 2026. OCR already expects MFA as a baseline control in practice, so waiting for the final rule is not a low-risk option.

Required specifications must be implemented exactly as written. Addressable specifications must be implemented, or replaced with a documented, equivalent alternative appropriate to the organization's size and risk profile. Addressable does not mean optional.

Yes. Business associates, and their subcontractors, are directly subject to the Security Rule's administrative, physical, and technical safeguard requirements, not just to the terms of their Business Associate Agreement.

Penalty tiers range from $100 to $50,000 per violation category, with annual caps around $2 million per category, according to HHS. Willful neglect that goes uncorrected carries mandatory minimum penalties, and the average healthcare breach overall costs $9.77 million once incident response, notification, and lost business are included, according to IBM's Cost of a Data Breach Report 2024.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn HIPAA requirements into safeguards that fit patient care

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring HIPAA security

Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.