Short answer: The proposed HIPAA Security Rule update — still not final, with HHS now targeting mid-2027 for any final action — would specifically remove the "addressable" flexibility small practices currently use to scale safeguards to their size. The five changes that would matter most to a small practice are: mandatory encryption, mandatory multi-factor authentication, a 72-hour incident recovery timeline, annual penetration testing, and stricter business associate oversight. None of these are currently required. All five are worth preparing for anyway, because they reflect where reasonable security expectations are already heading.
Why "addressable" mattered to small practices specifically
Under the current rule, a number of safeguards are labeled "addressable" rather than "required" — meaning a practice can implement an alternative measure if the standard approach isn't reasonable given its size, resources, and risk profile. This flexibility has been particularly useful for small practices without dedicated IT security staff. The proposed rule would eliminate this distinction for most implementation specifications, converting them to flat requirements regardless of practice size. That single change is why the proposal has drawn so much pushback from smaller and rural providers specifically.
1. Mandatory encryption of ePHI
What it would require: Encryption of electronic PHI both at rest and in transit, without the case-by-case flexibility current rule allows.
What to do now: Confirm whether your EHR, billing system, and any cloud storage actually encrypt data both when stored and when transmitted — not just claim to. This is worth verifying now rather than assuming, since it's already a reasonable security expectation even under current requirements.
2. Mandatory multi-factor authentication
What it would require: MFA on any system accessing ePHI, made a flat requirement rather than an addressable one.
What to do now: If MFA isn't currently enforced on your EHR, billing platform, and shared email, that's worth fixing under current requirements already — this is one of the most commonly missing controls at small practices, and it's inexpensive to implement relative to its impact.
3. A 72-hour incident recovery timeline
What it would require: Meaningfully faster system and data restoration following a security incident than most current practices are built around.
What to do now: Review your incident response plan and honestly assess whether your practice could realistically restore critical systems within 72 hours of an incident today. If the honest answer is no, that's worth addressing regardless of whether this specific proposal is ever finalized.
4. Annual penetration testing and network mapping
What it would require: Regular penetration testing and maintained, current network maps and asset inventories — a more rigorous technical standard than many small practices currently maintain.
What to do now: This is the item most likely to require outside expertise or a budget commitment for a small practice, since penetration testing generally isn't something office staff can perform themselves. Worth researching cost and vendor options now rather than scrambling later.
5. Enhanced business associate oversight
What it would require: Stricter verification and ongoing oversight of business associates' security practices, beyond simply having a signed BAA on file.
What to do now: This aligns closely with vendor vetting practices worth having regardless — confirming a vendor's actual security posture, not just getting a signature, is good practice under the current rule too.
The bigger picture
Given the genuine uncertainty around whether, when, and in what final form this rule takes effect, the more useful frame isn't "wait and see" — it's recognizing that most of these five items represent reasonable security practice today, independent of this specific rulemaking process. A small practice that's already moving toward these standards is better positioned regardless of how the proposal's timeline or scope eventually shakes out.