Health care practices already carry some of the strictest cybersecurity obligations of any industry. HHS’s proposed update to the HIPAA Security Rule is about to make them stricter still — removing the long-standing distinction between “required” and “addressable” safeguards that let some practices treat controls like encryption as optional.
What the Security Rule Requires Today
The HIPAA Security Rule requires covered entities — health care providers, health plans, health care clearinghouses — and their business associates to implement administrative, physical, and technical safeguards protecting electronic protected health information (ePHI). It applies to every practice that creates, receives, maintains, or transmits ePHI, regardless of size. A two-provider practice carries the same underlying obligations as a large hospital system, just scaled to its own risk and resources.
What’s Changing
HHS’s Office for Civil Rights published the first proposed Security Rule update since 2013 in December 2024. It removes the “addressable” category entirely — every implementation specification becomes required, with only narrow, documented exceptions — and proposes mandatory encryption of ePHI at rest and in transit, mandatory MFA, an annually updated technology asset inventory and network map, and network segmentation. The rule is expected to be finalized with a compliance window measured in months, not years, once finalized.
The Most Commonly Cited Violation
A HIPAA risk analysis is required, not a best practice, and it’s the single most commonly cited violation in HHS enforcement actions — more than half of recent enforcement actions involved an inadequate or missing one. A proper risk analysis identifies where ePHI actually lives across your systems, what could go wrong, how likely each threat is, and what safeguards close the gap. It has to be a real, documented process tied to your actual technology inventory, not a generic checklist filled out once and forgotten in a drawer.
Breach Notification Timelines
Breaches affecting 500 or more individuals must currently be reported to HHS OCR, affected individuals, and in most cases the media, without unreasonable delay and no later than 60 days after discovery. The proposed update tightens this further: practices would need to restore certain systems within 72 hours, and business associates would need to notify covered entities within 24 hours of activating a contingency plan — a much faster clock than most practices are used to today.
The Vendor Question: Business Associate Agreements
Any vendor that creates, receives, maintains, or transmits ePHI on your behalf — your managed IT provider, cloud backup vendor, email hosting provider — needs a signed Business Associate Agreement (BAA) obligating them to the same safeguard and breach-notification standards you’re held to. An IT provider unwilling to sign a BAA should not be touching any system with patient data on it, full stop.
What Non-Compliance Actually Costs
Penalties are tiered by culpability, from a few hundred dollars per violation for unknowing violations up to over $2 million per violation category per year for willful neglect that isn’t corrected. Beyond the fine itself, non-compliant practices found after a breach face corrective action plans, mandatory audits, and reputational damage that often costs more than the penalty — patients do switch providers over data breaches.
How CelereTech Helps
CelereTech handles the technical half of HIPAA compliance: conducting and documenting the risk analysis, deploying encryption and MFA across every device and system, maintaining the technology asset inventory the proposed rule will require, and monitoring for and responding to incidents within the tightening notification windows — all backed by a signed BAA. We work alongside your practice’s own HIPAA privacy policies to cover the technical safeguards specifically, so a two- or five-provider practice doesn’t need a full-time security engineer on staff to stay compliant.
Get a HIPAA security assessment for your practice before the updated rule takes effect.