What Does HIPAA IT Compliance Require in 2026?
HIPAA IT compliance in 2026 requires a small medical practice to follow the Privacy Rule, Security Rule, and Breach Notification Rule; identify every location containing electronic protected health information (ePHI); and document administrative, physical, and technical safeguards. The first three actions should be conducting a risk assessment, assigning responsible compliance officers, and correcting access, encryption, backup, and vendor-management gaps.
This HIPAA compliance checklist is designed for U.S. medical practices with 1–20 physicians. The January 2025 HIPAA Security Rule Notice of Proposed Rulemaking, or NPRM, remains proposed rather than final as of July 2026, but it signals stricter future requirements for multifactor authentication, encryption, asset inventories, annual compliance audits, network maps, and tested incident response plans.
Who Must Comply: Covered Entities vs. Business Associates
HIPAA applies to covered entities and business associates that create, receive, maintain, or transmit protected health information. A medical practice is generally a covered entity when it conducts HIPAA-covered transactions electronically, while an MSP becomes a business associate when its staff or systems can access the practice’s ePHI.
| Party | Typical examples | Main HIPAA responsibility |
|---|---|---|
Covered entity | Medical practice, health plan, healthcare clearinghouse | Control PHI use and disclosure, honor patient rights, implement safeguards, and manage breaches |
Business associate | EHR host, billing company, cloud provider, MSP, shredding vendor | Protect PHI, report incidents, restrict subcontractors, and comply with the BAA |
Ordinary vendor | Electrician, delivery company, or utility provider with only incidental access | Usually does not require a BAA if PHI access is incidental and not part of the service |
An MSP that administers Microsoft 365, servers, backups, firewalls, endpoints, remote-support tools, or security logs should sign a business associate agreement before access begins. HHS specifically identifies cloud, server, IT support, billing, and secure-document-disposal providers as common business associates.

Step 1: Conduct a Security Risk Assessment
A HIPAA risk assessment must identify risks and vulnerabilities affecting the confidentiality, integrity, and availability of all ePHI. The current Security Rule does not literally specify an annual assessment, but completing one at least annually—and after an EHR migration, office move, acquisition, ransomware incident, new cloud platform, or major network redesign—is a defensible operational minimum.
Use the free HHS Security Risk Assessment Tool to document systems, threats, vulnerabilities, existing controls, likelihood, impact, and required remediation. Each finding should have an owner, completion deadline, supporting evidence, and documented residual-risk decision.
Retain risk assessments, policies and procedures, training records, sanctions, incident records, and other required HIPAA compliance documentation for at least six years. The six-year rule applies to HIPAA documentation; medical-record retention periods may be longer under state law.
Request a free network security audit to identify unsupported systems, missing MFA, unencrypted devices, exposed remote access, and backup weaknesses.
What Counts as ePHI in a Small Practice?
ePHI is individually identifiable health information created, received, maintained, or transmitted electronically by a covered entity or business associate. The commonly cited “18 HIPAA identifiers” are the identifiers that must be removed under the Safe Harbor de-identification method; they are not a separate legal definition of ePHI.
A small practice should inspect EHRs, practice-management platforms, billing systems, email, patient portals, telehealth applications, imaging systems, voicemail, copier hard drives, backups, USB devices, personal phones, screenshots, spreadsheets, and exported reports. A patient name connected to an appointment, diagnosis, prescription, balance, insurance number, photograph, biometric record, IP address, or device identifier can constitute PHI.
Step 2: Administrative Safeguards Checklist
HIPAA administrative safeguards require named responsibility, documented decisions, workforce controls, security training, sanctions, information-system activity review, and contingency planning. A small practice should designate a HIPAA security officer and a privacy or HIPAA compliance officer, although one qualified employee may perform both functions in a smaller organization.
| Control | Small-practice implementation standard | HIPAA reference |
|---|---|---|
Risk management | Maintain an annual remediation cycle and update it after material changes | 45 CFR §164.308(a)(1) |
Sanction policy | Apply written and consistent sanctions for workforce violations | §164.308(a)(1)(ii)(C) |
Activity review | Use automated alerts and complete a documented management review at least monthly | §164.308(a)(1)(ii)(D) |
Workforce access | Approve access according to job duties and document every change | §164.308(a)(3)–(4) |
HIPAA training | Train during onboarding, after policy changes, and at least annually as a practice standard | §164.308(a)(5) |
Contingency planning | Maintain backups, disaster recovery, emergency operations, and test records | §164.308(a)(7) |
Collect dated training attestations and policy acknowledgments instead of relying on attendance lists alone. The current rule requires termination procedures but does not set an exact deadline, so the practice’s policy should disable a departing worker’s EHR, email, VPN, cloud, remote-support, and physical access immediately—preferably within one hour and never later than 24 hours.
Step 3: Technical Safeguards Checklist
HIPAA technical safeguards require controlled access, unique user identification, emergency-access procedures, audit controls, data-integrity protection, authentication, and transmission security. Encryption and automatic logoff remain “addressable,” which means the practice must implement them when reasonable and appropriate or document why an equivalent alternative control adequately reduces the risk.
☐ Create a unique account for every workforce member and prohibit shared logins.
☐ Apply role-based access control and the principle of least privilege.
☐ Review active accounts and permissions at least quarterly.
☐ Require MFA for EHR, email, VPN, remote support, cloud applications, and administrator accounts.
☐ Configure automatic workstation locking and application timeouts.
☐ Use AES-256 encryption at rest and TLS 1.2 or later in transit as technical baselines; HIPAA does not mandate a specific algorithm.
☐ Centralize audit logs and alert on mass downloads, new administrators, impossible travel, and disabled security tools.
☐ Deploy endpoint detection and response on supported desktops, laptops, and servers.
☐ Scan for vulnerabilities and define patch deadlines based on severity.
☐ Sanitize or physically destroy storage media before disposal or reassignment.
The proposed Security Rule changes would make stronger MFA, encryption, asset inventory, network mapping, annual auditing, vulnerability scanning, and plan testing explicit requirements in more situations. Until HHS publishes a final rule and effective date, the NPRM should be treated as a readiness roadmap rather than current law.
Email, Texting, and Telehealth: Common ePHI Leak Points
Standard SMS is not automatically HIPAA compliant because consumer texting may lack reliable authentication, audit trails, retention controls, remote wipe, verified delivery, and a signed BAA. Practices should use a secure patient portal or contracted messaging platform that supports access controls, encryption, logging, and administrative management.
HHS permits electronic communication when reasonable safeguards are used. A patient may also request unencrypted email after being warned about the risks and accepting that communication method, but the practice should document the request and avoid placing unnecessary clinical details in the message subject line.
Telehealth vendors that create, receive, maintain, or transmit ePHI should support HIPAA safeguards and sign a BAA.
Read our article about HIPAA compliance requirements for remote teams.
Step 4: Physical Safeguards Checklist
HIPAA physical safeguards protect facilities, workstations, devices, and electronic media from unauthorized access, theft, tampering, and improper disposal. Small practices should control visitor access, keys, badges, server rooms, records areas, network cabinets, and after-hours entry.
☐ Position screens so patients and waiting-room visitors cannot view ePHI.
☐ Use privacy filters where workstation placement cannot be changed.
☐ Lock unattended rooms, laptops, backup drives, and network equipment.
☐ Track each device’s user, serial number, location, encryption status, and disposal date.
☐ Prohibit unapproved USB storage and unnecessary local ePHI downloads.
☐ Record equipment transfers between offices, employees, and vendors.
☐ Retain certificates confirming secure wiping or physical destruction.
Physical safeguards also apply to home offices and mobile devices used by clinicians. A written clean-desk, screen-lock, device-transport, and lost-device reporting policy should cover every location where workforce members access ePHI.
Step 5: Business Associate Agreements
A valid BAA is required before a vendor performs a service involving PHI for a covered medical practice. Review EHR, billing, transcription, MSP/IT, cloud hosting, email, backup, telehealth, analytics, legal, consulting, answering-service, and document-destruction vendors, including subcontractors that handle the same data.
A business associate agreement should define:
- Permitted and prohibited PHI uses
- Required administrative, physical, and technical safeguards
- Security-incident and breach-reporting obligations
- Subcontractor requirements
- Support for patient access, amendment, and accounting requests
- Access by the Department of Health and Human Services (HHS)
- PHI return or destruction after termination
- Termination rights following a material violation
Raleigh Orthopaedic Clinic paid $750,000 after disclosing PHI connected to approximately 17,300 patients to a vendor without a BAA. Advanced Care Hospitalists settled for $500,000 after using a medical billing provider without first executing the required agreement.
Step 6: Breach Notification and Incident Response
HIPAA breach response requires a documented four-factor risk assessment unless the practice decides to proceed directly with notification. The assessment considers the type and amount of PHI involved, the unauthorized person who received it, whether the information was actually acquired or viewed, and the extent to which the risk was mitigated.
Use a defined process:
Detect → contain → preserve evidence → assess → notify → document → correct
Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Notify HHS within 60 days when a breach is affecting 500 or more individuals; breaches involving fewer than 500 people may be recorded in an annual log and reported within 60 days after the end of the calendar year.
Media notification is required when a breach affects more than 500 residents of one state or jurisdiction. Business associates must notify the covered entity according to the BAA and the Breach Notification Rule.
HIPAA Violation Penalties in 2026?

HIPAA violation penalties are adjusted for inflation and depend on the organization’s level of knowledge, culpability, corrective action, duration of noncompliance, financial condition, and resulting harm. Effective January 28, 2026, HHS increased the published civil monetary penalty amounts.
| Tier | Level of culpability | Penalty per violation | Published annual cap per identical requirement* |
|---|---|---|---|
Tier 1 | Organization did not know and could not reasonably have known | $145–$73,011 | $2,190,294 |
Tier 2 | Reasonable cause, but not willful neglect | $1,461–$73,011 | $2,190,294 |
Tier 3 | Willful neglect corrected within the required period | $14,602–$73,011 | $2,190,294 |
Tier 4 | Willful neglect not corrected within the required period | $73,011–$2,190,294 | $2,190,294 |
*OCR’s indefinitely effective 2019 enforcement-discretion notice announced lower tier-specific annual limits for Tiers 1–3. Legal counsel should therefore confirm the cap OCR would apply to the facts and enforcement date of an active case.
Criminal violations involving false pretenses, personal gain, commercial advantage, or malicious harm can result in fines of up to $250,000 and imprisonment for up to 10 years.
IBM reported that the average healthcare data breach cost reached approximately $9.77 million in 2024—the highest average among the industries studied. IBM’s 2025 report placed the healthcare average at $7.42 million, showing improvement but still demonstrating that one breach can cost far more than a structured prevention and compliance program.
Free HIPAA IT Compliance Checklist (Printable Summary)
This printable hipaa compliance checklist gives a practice with 1–20 physicians a minimum 2026 control set. Mark an item complete only when the practice has dated evidence showing who implemented the control, when it was reviewed, and how it was tested.
☐ Identify the covered entity and every business associate.
☐ Assign privacy/compliance and security responsibility.
☐ Complete and date a comprehensive HIPAA risk assessment.
☐ Repeat the assessment annually and after material changes.
☐ Inventory systems, applications, users, devices, and ePHI locations.
☐ Maintain an ePHI data-flow diagram and current network map.☐ Retain required HIPAA documentation for at least six years.
☐ Document onboarding and annual HIPAA training.
☐ Obtain signed policy acknowledgments and training attestations.
☐ Apply a written workforce sanction policy.
☐ Eliminate shared user accounts.
☐ Enforce least privilege and quarterly access reviews.
☐ Enable MFA for critical, administrative, cloud, and remote access.
☐ Encrypt ePHI at rest and in transit.
☐ Configure automatic workstation locking and application logoff.
☐ Centralize audit logs and investigate security alerts.
☐ Deploy EDR and patch systems according to defined deadlines.
☐ Maintain encrypted, offline, or immutable backups.
☐ Test data restoration and emergency-mode procedures.
☐ Terminate departing-worker access immediately.
☐ Secure facilities, workstations, mobile devices, and media.
☐ Sanitize or destroy storage media before disposal or reuse.
☐ Execute and review BAAs before vendors receive access.
☐ Use secure email, texting, and telehealth workflows.
☐ Maintain and test a written incident and breach-response plan.
☐ Document incidents, assessments, notifications, and corrective actions.
The checklist can also be offered as a downloadable PDF with columns for the control owner, due date, evidence location, remediation status, and next review date.
How an IT Provider Helps a Small Practice Stay HIPAA Compliant?
A HIPAA-focused MSP converts regulatory requirements into configured, monitored, tested, and documented IT controls. The provider can support the SRA, asset inventory, MFA, encryption, EDR, vulnerability management, patching, audit-log review, backup testing, vendor due diligence, and incident response, while the covered entity retains responsibility for its overall HIPAA program.
RIT Company provides HIPAA-compliant IT services, network security, backup, and Managed IT Services from Addison for medical and professional organizations throughout Chicagoland. A free Network Security Audit can provide a practical starting point for identifying exposed ePHI, unsupported operating systems, weak access controls, missing MFA, unreliable backups, and unmanaged vendor access.
Check this out:
Request a free network security audit to identify the highest-risk compliance and cybersecurity gaps before they result in downtime, reportable exposure, or an OCR investigation.
FAQ
These answers distinguish current HIPAA requirements from recommended annual operating standards and proposed Security Rule changes. Small medical practices remain subject to the same core HIPAA rules as larger covered entities, although safeguards may be selected and implemented according to the organization’s size, complexity, capabilities, technical infrastructure, costs, and identified risks.
Frequently Asked Questions
- What are the HIPAA 3 rules?
The three primary HIPAA rules are the Privacy Rule, Security Rule, and Breach Notification Rule. The Privacy Rule governs the use and disclosure of PHI, the Security Rule protects ePHI, and the Breach Notification Rule establishes notification duties following a breach of unsecured PHI.
- What are the 5 main HIPAA rules?
There is no official regulation titled “the five main HIPAA rules.” Compliance summaries commonly use the phrase to describe the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and the modifications introduced by the 2013 Omnibus Rule.
- What are HIPAA compliance requirements?
Four recurring violation categories are impermissible PHI disclosure, failure to conduct an adequate risk analysis, inadequate access controls, and missing business associate agreements. OCR enforcement also frequently addresses incomplete risk management, insufficient audit controls, and delayed breach notification.
- What are the four most common HIPAA violations?
Four recurring violation categories are impermissible PHI disclosure, failure to conduct an adequate risk analysis, inadequate access controls, and missing business associate agreements. OCR enforcement also frequently addresses incomplete risk management, insufficient audit controls, and delayed breach notification.
- What are the top 10 HIPAA violations?
Ten frequent compliance failures are unauthorized disclosure, employee snooping, missing risk analysis, inadequate risk management, missing BAAs, excessive user privileges, unencrypted lost devices, insufficient audit-log review, improper media disposal, and missing training or incident-response procedures. The exact ranking varies by enforcement period, but these categories repeatedly appear in OCR investigations and settlements.
- How often is a risk assessment required?
The current HIPAA Security Rule requires an accurate and thorough risk analysis and periodic technical and nontechnical evaluation, but it does not specify the word “annually.” A small practice should perform a complete assessment at least annually and whenever a significant system, vendor, location, operational process, or threat environment changes.
- Does a small practice need a compliance officer?
Yes. HIPAA requires designated privacy and security responsibility, although one qualified person may perform both roles in a small practice. The practice should document the appointment, authority, duties, training, reporting path, and backup contact for that person.
Contact Us Today To Schedule Your Discovery Call
15min discovery call Schedule 15min discovery callOr submit a message
Thank you for contacting us!
We respond within 24 hours