HIPAA
The 2025 HIPAA Security Rule update, decoded
The proposed update turns 'addressable' into 'required' — mandatory MFA, encryption, and annual testing. What's changing, and what it will cost a small practice.
For two decades, the HIPAA Security Rule let covered entities treat many safeguards as "addressable" — implement, or document why not. The proposed 2025 update closes that door. Several controls that were optional-with-justification become required, and the bar rises meaningfully for small practices that have leaned on that flexibility.
What's proposed to become mandatory
- Multi-factor authentication for access to systems holding ePHI.
- Encryption of ePHI at rest and in transit.
- Annual technical testing — vulnerability scanning and penetration testing on a defined cadence.
- An up-to-date asset inventory and network map — you can't protect what you haven't catalogued.
Why it matters for a small practice
A clinic administrator isn't a security engineer, and the business-associate chain multiplies the risk: every vendor that touches ePHI inherits the obligation. The practices that struggle are the ones treating HIPAA as paperwork rather than as an operating posture. The ones that do well have a partner who owns the technical controls and the evidence.
The cost frame
The honest answer is that the new floor costs more than the old one — but far less than a breach and the OCR process that follows. Market the outcome, not the fear: a practice that can demonstrate MFA, encryption, tested backups, and an incident-response plan is both compliant and genuinely harder to hit. Keep this strictly business-to-business — HIPAA marketing never touches patient data.
Before your renewal
Run the 3-minute insurability self-check
See where you’d pass or fail your carrier’s questionnaire, with a control-by-control gap list.
Start the self-check