<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HIPAA Secure Now!</title>
	<atom:link href="http://www.hipaasecurenow.com/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>HIPAA Compliance Made Human</description>
	<lastBuildDate>Tue, 22 Sep 2026 03:10:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.5</generator>

<image>
	<url>https://www.hipaasecurenow.com/wp-content/uploads/2019/05/cropped-HSN-Favicon-512px-32x32.png</url>
	<title>HIPAA Secure Now!</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>HIPAA Workforce Security: What Could Change?</title>
		<link>https://www.hipaasecurenow.com/hipaa-workforce-security-what-could-change/</link>
					<comments>https://www.hipaasecurenow.com/hipaa-workforce-security-what-could-change/#respond</comments>
		
		<dc:creator><![CDATA[Zach Morrison]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 04:00:05 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=20475</guid>

					<description><![CDATA[<p>Workforce security goes beyond annual HIPAA training. Learn how proposed HIPAA Security Rule changes could introduce more specific expectations for employee training, security reminders, documentation, and timely removal of access to ePHI. </p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-workforce-security-what-could-change/">HIPAA Workforce Security: What Could Change?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-20476 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/hipaa-workforce-security-what-could-change.webp" alt="HIPAA Workforce" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/hipaa-workforce-security-what-could-change.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/hipaa-workforce-security-what-could-change-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/hipaa-workforce-security-what-could-change-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/hipaa-workforce-security-what-could-change-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Your workforce is an important part of protecting electronic protected health information (ePHI). HIPAA already requires covered entities and business associates to train their workforce, maintain security policies, and control access to ePHI. A proposed update to the HIPAA Security Rule would make many of these requirements more specific.</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">What Does HIPAA Require Today?</span></b><span data-ccp-props="{}"> </span></h2>
<p><span data-contrast="auto">The current Security Rule requires a security awareness and training program for all workforce members, including management. It also includes addressable provisions covering security updates, protection from malicious software, login monitoring, and password management.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Organizations must maintain written Security Rule policies and procedures, update them when needed, and have procedures for ending access when a workforce member leaves. However, the current Security Rule does not set a specific annual training schedule, a deadline for training new workforce members, or a timeframe for removing access.</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">What Would the Proposed Rule Change?</span></b><span data-ccp-props="{}"> </span></h2>
<p><span data-contrast="auto">If finalized as written, the proposed rule would establish clearer training content and deadlines. Covered entities and business associates would need to:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Provide role-based security training at least once every 12 months</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Train new workforce members no later than 30 days after they first receive system access</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Provide updated training within 30 days of a material policy or procedure change affecting someone’s role</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Provide ongoing reminders/continuous trainings about security responsibilities and emerging threats</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Document that training and reminders were provided</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">The proposal would also require workforce security policies and procedures to be reviewed and tested annually.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Training is only one part of workforce security. Under the proposal, system and facility access would need to be terminated as soon as possible, but no later than one hour after a workforce member’s employment or other arrangement ends. When that person had authorized access to systems maintained by another covered entity or business associate, that organization would generally need to be notified within 24 hours.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">These changes are not final, but organizations can begin preparing by reviewing their training, policies, documentation, and access-removal processes.</span><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-workforce-security-what-could-change/">HIPAA Workforce Security: What Could Change?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/hipaa-workforce-security-what-could-change/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Business Associate and Vendor Management: A New Approach is Needed</title>
		<link>https://www.hipaasecurenow.com/business-associate-and-vendor-management-a-new-approach-is-needed/</link>
					<comments>https://www.hipaasecurenow.com/business-associate-and-vendor-management-a-new-approach-is-needed/#respond</comments>
		
		<dc:creator><![CDATA[Trent Bolish]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 04:00:12 +0000</pubDate>
				<category><![CDATA[Business Associates]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Press Release]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20466</guid>

					<description><![CDATA[<p>Signing a Business Associate Agreement is an essential part of HIPAA compliance, but effective vendor management does not stop there. Learn how healthcare organizations can identify, assess, monitor, and securely offboard vendors to better protect PHI and reduce third-party risk.</p>
<p>The post <a href="https://www.hipaasecurenow.com/business-associate-and-vendor-management-a-new-approach-is-needed/">Business Associate and Vendor Management: A New Approach is Needed</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="aligncenter wp-image-20472 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/business-associate-and-vendor-management-a-new-approach-is-needed.webp" alt="HSN Vendor Management" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/business-associate-and-vendor-management-a-new-approach-is-needed.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/business-associate-and-vendor-management-a-new-approach-is-needed-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/business-associate-and-vendor-management-a-new-approach-is-needed-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/business-associate-and-vendor-management-a-new-approach-is-needed-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Healthcare organizations depend on outside vendors for billing, cloud storage, IT support, legal services, and everyday operations. When a vendor accesses, processes, receives, maintains, or transmits protected health information (PHI) on your behalf, it generally is a business associate under HIPAA.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">That relationship creates responsibilities for both parties—and signing a Business Associate Agreement (BAA) is only the beginning.</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">A BAA Is Essential, but It Is Not Vendor Management</span></b><span data-ccp-props="{}"> </span></h2>
<p><span data-contrast="auto">A BAA defines how a business associate may use and disclose PHI, requires appropriate safeguards, and addresses incident reporting and subcontractor responsibilities. However, a signed agreement does not prove that a vendor has effective security controls.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Healthcare organizations need a repeatable process for managing vendors throughout the relationship:</span><span data-ccp-props="{}"> </span></p>
<ol>
<li><b><span data-contrast="auto">Identify and classify.</span></b><span data-contrast="auto"> Maintain an inventory of vendors, the services they provide, the PHI they handle, and any subcontractors they use.</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Evaluate risk.</span></b><span data-contrast="auto"> Review safeguards such as access controls, multifactor authentication, encryption, workforce training, incident response, backups, and vulnerability management before access begins.</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Set clear expectations.</span></b><span data-contrast="auto"> Ensure the BAA and service agreement address responsibilities, notification procedures, data return or destruction, and other requirements appropriate to the risk.</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Monitor the relationship.</span></b><span data-contrast="auto"> Reassess higher-risk vendors on a defined schedule and whenever services, ownership, access, or subcontractors change.</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Offboard securely.</span></b><span data-contrast="auto"> Remove accounts and integrations, recover assets, and confirm that PHI is returned or destroyed when required and feasible.</span><span data-ccp-props="{}"> </span></li>
</ol>
<p><span data-contrast="auto">Business associates must apply the same discipline to subcontractors that handle PHI on their behalf. Each additional party extends the chain of responsibility—and can increase exposure if oversight is weak.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Effective vendor management is not paperwork for its own sake. It helps your organization know who has access to PHI, understand the risk, respond faster to incidents, and prevent former vendors from retaining unnecessary access or data.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">HIPAA Secure Now helps healthcare organizations assess risk, maintain policies and documentation, train employees, and keep compliance work moving throughout the year.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">Schedule a HIPAA compliance review to identify vendor-management gaps and prioritize your next steps.</span></b><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/business-associate-and-vendor-management-a-new-approach-is-needed/">Business Associate and Vendor Management: A New Approach is Needed</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/business-associate-and-vendor-management-a-new-approach-is-needed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Could the End of &#8220;Addressable&#8221; HIPAA Safeguards Mean for Healthcare Organizations?</title>
		<link>https://www.hipaasecurenow.com/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations/</link>
					<comments>https://www.hipaasecurenow.com/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 04:00:14 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20458</guid>

					<description><![CDATA[<p>“Addressable” has never meant optional under the HIPAA Security Rule. But proposed changes could eliminate much of the flexibility associated with addressable safeguards. Learn what that could mean for healthcare organizations and why now is a good time to review your current security practices.</p>
<p>The post <a href="https://www.hipaasecurenow.com/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations/">What Could the End of &#8220;Addressable&#8221; HIPAA Safeguards Mean for Healthcare Organizations?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="aligncenter wp-image-20463 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations-1.webp" alt="Addressable Safeguards" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/09/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations-1.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations-1-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations-1-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/09/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations-1-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">One common misconception about the HIPAA Security Rule is that an “addressable” safeguard is optional. That is not the case.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Under the current Security Rule, when an implementation specification is designated as addressable, an organization must determine whether that safeguard is reasonable and appropriate for its environment. If it is not, the organization must document why and, when reasonable and appropriate, implement an equivalent alternative measure.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The proposed HIPAA Security Rule changes could significantly reduce that flexibility. HHS has proposed eliminating the distinction between “required” and “addressable” implementation specifications, making the specifications required with limited exceptions.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Why Is HHS Proposing This Change?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">During the recent NIST/HHS </span><i><span data-contrast="auto">Safeguarding Health Information: Building Assurance Through HIPAA Security</span></i><span data-contrast="auto"> conference, one of the points discussed was that the Security Rule was originally designed with flexibility so organizations could adapt as technology evolved.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Technology has certainly evolved. Many safeguards that may have once been difficult, costly, or impractical to implement are now considered fundamental security practices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Encryption is a good example.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Years ago, encryption could be expensive or difficult to implement, particularly for a small healthcare organization. Depending on the organization&#8217;s circumstances, there may have been other reasonable and appropriate ways to protect electronic protected health information (ePHI).</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Today, encryption is widely available and often built directly into the technology healthcare organizations already use. What may have once required additional technology and resources has increasingly become a baseline safeguard for protecting sensitive information.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The same evolution is happening across other areas of cybersecurity. As technology becomes more accessible and threats become more sophisticated, expectations for protecting ePHI are changing with them.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Does This Mean for Your Organization?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">The proposed HIPAA Security Rule has not been finalized, so the current Security Rule requirements remain in effect.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">However, healthcare organizations do not have to wait for a final rule to start preparing.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Now is a good time to review the safeguards your organization currently treats as addressable. Understand which safeguards have been implemented, where alternative measures are being used, and whether those decisions still make sense based on today&#8217;s technology and cybersecurity risks.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">This review can also help identify areas that may require additional planning, budgeting, or support from your IT team or managed service provider.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Even if the final rule differs from the current proposal, evaluating these safeguards today can help strengthen the protection of ePHI and put your organization in a better position to adapt as HIPAA requirements evolve.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Preparing now means having more time to make thoughtful decisions instead of waiting until a compliance deadline is approaching.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations/">What Could the End of &#8220;Addressable&#8221; HIPAA Safeguards Mean for Healthcare Organizations?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/what-could-the-end-of-addressable-hipaa-safeguards-mean-for-healthcare-organizations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Beyond the Checkbox: Mastering Vulnerability Scans and Penetration Testing for the 2027 Proposed HIPAA Rules</title>
		<link>https://www.hipaasecurenow.com/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules/</link>
					<comments>https://www.hipaasecurenow.com/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules/#respond</comments>
		
		<dc:creator><![CDATA[Paige Merrill]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 04:00:15 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Business Associates]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20450</guid>

					<description><![CDATA[<p>Proposed HIPAA Security Rule updates could introduce more structured vulnerability scanning and penetration testing requirements for covered entities and business associates. Learn how the two forms of testing differ, what the proposal may require, and how healthcare organizations can start preparing now.</p>
<p>The post <a href="https://www.hipaasecurenow.com/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules/">Beyond the Checkbox: Mastering Vulnerability Scans and Penetration Testing for the 2027 Proposed HIPAA Rules</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20455 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules.webp" alt="HSN Mastering Vulnerability Scans" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Healthcare cyberattacks continue to evolve, and federal regulators are responding with stronger proposed cybersecurity expectations.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The U.S. Department of Health and Human Services (HHS) has proposed major updates to the HIPAA Security Rule, with July 2027 currently listed as an estimated final-action date on the federal regulatory agenda. That date is not guaranteed and may change, but the proposal gives healthcare organizations a clear signal about where cybersecurity expectations are heading.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">One area receiving greater attention is vulnerability management, including both automated vulnerability scanning and penetration testing.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Vulnerability Scans vs. Penetration Tests</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">While the two are related, they serve different purposes.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Vulnerability scans</span></b><span data-contrast="auto"> use automated tools to identify known technical weaknesses, outdated software, missing patches, and configuration issues across systems and devices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Penetration tests</span></b><span data-contrast="auto"> go a step further. Qualified security professionals simulate real-world attacks to determine whether identified weaknesses can actually be exploited and how far an attacker could potentially move through the environment.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Think of a vulnerability scan as finding unlocked doors. A penetration test evaluates what could happen if someone actually tried to walk through them.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Could Change Under the Proposed Rule?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">The current HIPAA Security Rule requires organizations to identify risks to electronic protected health information (ePHI) and implement reasonable safeguards, but it does not prescribe a specific vulnerability-scanning or penetration-testing schedule.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">If finalized as proposed, that would change.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Covered entities and business associates could be required to:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Conduct automated vulnerability scans at least once every six months, or more frequently based on their risk analysis</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Perform penetration testing on relevant electronic information systems at least once every 12 months, or more frequently when warranted</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Use qualified individuals to perform penetration testing</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Continuously monitor authoritative sources for newly identified vulnerabilities</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Address identified vulnerabilities through established patch-management and risk-management processes</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<h2 aria-level="2"><b><span data-contrast="none">How Healthcare Organizations Can Prepare Now</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Organizations do not need to wait for a final rule to strengthen these practices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Start by reviewing which systems contain or interact with ePHI and determining whether they are currently included in regular vulnerability scanning. From there, work with your internal IT team or managed service provider (MSP) to establish testing schedules, assign responsibility for remediation, document findings, and verify that identified weaknesses are actually corrected.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Penetration testing may also require outside expertise, particularly for smaller organizations without dedicated security personnel.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The goal is not simply to complete another compliance task. These activities help healthcare organizations understand where weaknesses exist before an attacker finds them.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Building these processes now can strengthen patient data protection today while making future compliance requirements easier to manage if the proposed rule is finalized.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules/">Beyond the Checkbox: Mastering Vulnerability Scans and Penetration Testing for the 2027 Proposed HIPAA Rules</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/beyond-the-checkbox-mastering-vulnerability-scans-and-penetration-testing-for-the-2027-proposed-hipaa-rules/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Mapping ePHI: Why Network Visibility Is Essential for HIPAA Compliance</title>
		<link>https://www.hipaasecurenow.com/mapping-ephi-why-network-visibility-is-essential-for-hipaa-compliance/</link>
					<comments>https://www.hipaasecurenow.com/mapping-ephi-why-network-visibility-is-essential-for-hipaa-compliance/#respond</comments>
		
		<dc:creator><![CDATA[Trent Bolish]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 04:00:37 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20442</guid>

					<description><![CDATA[<p>Knowing where ePHI is stored is only part of the picture. Healthcare organizations also need visibility into how sensitive information moves between systems, applications, vendors, and business associates. Learn why network mapping can strengthen risk analysis and help organizations prepare for proposed HIPAA Security Rule requirements.</p>
<p>The post <a href="https://www.hipaasecurenow.com/mapping-ephi-why-network-visibility-is-essential-for-hipaa-compliance/">Mapping ePHI: Why Network Visibility Is Essential for HIPAA Compliance</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20448 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/image-18.webp" alt="HSN Network Mapping" width="1536" height="1024" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/image-18.webp 1536w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/image-18-300x200.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/image-18-1024x683.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/image-18-768x512.webp 768w" sizes="auto, (max-width: 1536px) 100vw, 1536px" /></p>
<p><span data-contrast="auto">Healthcare organizations rely on an increasingly complex web of EHR platforms, cloud services, medical devices, applications, vendors, and business associates. But when it comes to HIPAA compliance, knowing where electronic protected health information (ePHI) is stored isn’t enough, you also need to understand how it moves.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">A comprehensive network map should document the systems and technology assets that interact with ePHI, while clearly illustrating how that information flows into, through, and out of the organization. This visibility is fundamental to an effective security risk analysis. After all, it is difficult to identify risks to ePHI when you don’t have a complete picture of the systems, connections, and third parties that may affect it.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">This is becoming even more important under HHS’s </span><b><span data-contrast="auto">proposed updates to the HIPAA Security Rule</span></b><span data-contrast="auto">. The proposed rule would explicitly require regulated entities to maintain a technology asset inventory and a network map illustrating the movement of ePHI, updating them at least annually and when environmental or operational changes may affect ePHI.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">For healthcare organizations, that means documenting more than servers and workstations. Cloud-hosted EHRs, backup providers, connected systems, remote environments, and relevant business associates may all need to be considered when mapping the ePHI ecosystem.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Importantly, these Security Rule changes </span><b><span data-contrast="auto">remain proposed, not final</span></b><span data-contrast="auto">, and the current HIPAA Security Rule remains in effect. But organizations shouldn’t wait for a compliance deadline to gain visibility into their environments.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">A complete network and ePHI data-flow map isn’t just documentation, it’s the foundation for understanding risk and protecting patient information.</span></b><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/mapping-ephi-why-network-visibility-is-essential-for-hipaa-compliance/">Mapping ePHI: Why Network Visibility Is Essential for HIPAA Compliance</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/mapping-ephi-why-network-visibility-is-essential-for-hipaa-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Network Segementation &#038; The Proposed HIPAA Security Rule</title>
		<link>https://www.hipaasecurenow.com/network-segementation-the-proposed-hipaa-security-rule/</link>
					<comments>https://www.hipaasecurenow.com/network-segementation-the-proposed-hipaa-security-rule/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 04:00:29 +0000</pubDate>
				<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20433</guid>

					<description><![CDATA[<p>Network segmentation can help healthcare organizations limit how far an attacker can move after gaining access to a system. Learn why identifying where ePHI lives is an important first step and how the proposed HIPAA Security Rule could strengthen expectations around protecting critical systems.</p>
<p>The post <a href="https://www.hipaasecurenow.com/network-segementation-the-proposed-hipaa-security-rule/">Network Segementation &#038; The Proposed HIPAA Security Rule</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignnone wp-image-20438 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/network-segementation-the-proposed-hipaa-security-rule.webp" alt="HSN Network Segmentation" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/network-segementation-the-proposed-hipaa-security-rule.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/network-segementation-the-proposed-hipaa-security-rule-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/network-segementation-the-proposed-hipaa-security-rule-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/network-segementation-the-proposed-hipaa-security-rule-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Another proposed change to the HIPAA Security Rule involves network segmentation. While the term may sound technical, the concept is fairly straightforward.</span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">What is Network Segmentation?</span></b><span data-contrast="auto"> </span></h2>
<p><span data-contrast="auto">It is a security control that divides your network into separate areas. The goal is to limit how far an unauthorized user can go if they gain access to your organization’s systems. If someone gets through one door, you do not want them to suddenly have keys to every room in the building. If an attacker compromises one computer, account, or system, network segmentation can help prevent them from automatically reaching other systems that contain sensitive information, including electronic protected health information (ePHI).</span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">Where Do You Start?</span></b><span data-contrast="auto"> </span></h2>
<p><span data-contrast="auto">Before you can segment your network, you first need to understand where your PHI lives.</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Is ePHI stored on your servers?</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Is ePHI being sent or stored in email?</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Is ePHI contained within your EMR or EHR? Do you have any legacy systems?</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Is there any medical equipment that contain hard drives with ePHI?</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Are employees storing PHI on workstations, laptops, smartphones, or shared drives?</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Are there other applications or cloud systems that contain PHI?</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">Once you understand where PHI is located, your IT team or managed service provider (MSP) can determine how those systems should be separated from other parts of your network.</span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">Why Does This Matter?  </span></b></h2>
<p><span data-contrast="auto">Strong cybersecurity includes limiting the damage when something does happen.</span><b><span data-contrast="auto"> </span></b><span data-contrast="auto">Without segmentation, an attacker who gains access to one part of your environment may be able to move through the network and access additional systems. With segmentation, you can create barriers that make that movement more difficult. An unauthorized user gaining access to one system should not automatically mean they have access to everything. Start by identifying where your PHI lives, then work with your IT provider to determine whether appropriate barriers exist between critical systems and the rest of your network.</span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/network-segementation-the-proposed-hipaa-security-rule/">Network Segementation &#038; The Proposed HIPAA Security Rule</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/network-segementation-the-proposed-hipaa-security-rule/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>HIPAA Patch Management: What to Prepare For</title>
		<link>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/</link>
					<comments>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/#respond</comments>
		
		<dc:creator><![CDATA[Paige Merrill]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 04:00:29 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20423</guid>

					<description><![CDATA[<p>Patch management plays an important role in protecting ePHI and reducing cybersecurity risk. Learn how the proposed HIPAA Security Rule could introduce more formal patching timelines, documentation, and annual testing requirements for covered entities and business associates.</p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/">HIPAA Patch Management: What to Prepare For</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20428 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for.webp" alt="HIPAA Patch Mgmt" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Patch management is the process of identifying, prioritizing, acquiring, installing, evaluating, and verifying software and system updates. It helps correct security weaknesses while reducing the risk that an update will disrupt operations or affect electronic protected health information (ePHI).</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">How do covered entities and business associates know what needs patching? Common sources include:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Vendor notifications and security advisories </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Automated vulnerability scans </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Penetration-testing results </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Government resources, such as CISA’s Known Exploited Vulnerabilities Catalog </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">IT or managed service provider reports </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Internal risk analyses and system reviews </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">The U.S. Department of Health and Human Services (HHS) proposed significant HIPAA Security Rule changes in December 2024. As of today, the proposal has not been finalized. The federal regulatory agenda identifies July 2027 as an estimated final-action date, but that date is not binding and may change.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">If finalized as proposed, covered entities and business associates would need written procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying patches, updates, and upgrades across relevant electronic information systems. These procedures would need to be reviewed and tested at least annually.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Critical risks generally would need remediation within 15 calendar days after the need is identified when a patch, update, or upgrade is available. High risks generally would need remediation within 30 calendar days. If remediation is unavailable, the applicable period would begin when it becomes available. Organizations would set and document timelines for other risks.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Limited exceptions would apply when remediation is unavailable or would adversely affect the confidentiality, integrity, or availability of ePHI. The organization would have to document the exception in real time and implement appropriate compensating controls.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Organizations should not wait. The HHS Office for Civil Rights has confirmed that the current HIPAA risk-analysis requirement includes risks and vulnerabilities to ePHI from unpatched software.</span><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/">HIPAA Patch Management: What to Prepare For</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why MFA Is Essential for Healthcare Organizations</title>
		<link>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/</link>
					<comments>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/#respond</comments>
		
		<dc:creator><![CDATA[Trent Bolish]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 04:00:57 +0000</pubDate>
				<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Remote Workforce]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20414</guid>

					<description><![CDATA[<p>Passwords alone are no longer enough to protect healthcare systems and patient data. Learn how multi-factor authentication can reduce unauthorized access, strengthen operational resilience, and help healthcare organizations prepare for changing HIPAA expectations.</p>
<p>The post <a href="https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/">Why MFA Is Essential for Healthcare Organizations</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20420 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations.webp" alt="MFA for Healthcare" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">For healthcare leaders, multi-factor authentication, or MFA, is more than an IT decision. It is a business decision that directly affects patient trust, operational resilience, regulatory risk, and the organization’s reputation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Healthcare organizations rely on digital systems for patient records, billing, scheduling, communication, and clinical workflows. When access to those systems is compromised, the impact can extend far beyond a single account. A breach can expose electronic protected health information (ePHI), interrupt patient care, create costly recovery work, and damage the trust an organization has worked hard to build.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Passwords Alone Are No Longer Enough</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Passwords remain one of the most common entry points for attackers. They can be stolen through phishing emails, exposed in data breaches, reused across multiple accounts, or purchased on the dark web.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Even a strong password cannot provide complete protection if it falls into the wrong hands.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">MFA adds another layer of verification before access is granted. In addition to entering a password, the user must confirm their identity through another method, such as an authentication application, security key, or unique code.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">That additional step makes it much more difficult for an attacker to enter a system using stolen credentials alone.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Why MFA Matters in Healthcare</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Healthcare organizations and their business associates manage highly sensitive information across a wide range of systems, users, and locations. Employees may access ePHI from clinical workstations, laptops, mobile devices, cloud platforms, or remote environments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">A single compromised account could provide an attacker with access to patient data, email, shared files, administrative systems, or connected applications. Privileged accounts, remote access tools, and systems containing ePHI should be especially important priorities when implementing MFA.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">HIPAA Expectations Are Changing</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">MFA is also becoming a more urgent HIPAA consideration.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Under the current HIPAA Security Rule, some access-control safeguards are considered addressable, allowing organizations to evaluate how they apply based on their circumstances. The proposed HIPAA Security Rule updates would establish stronger and more consistent expectations for MFA.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Although the proposed rule has not been finalized and its requirements may change, the direction is clear: healthcare organizations should prepare for stronger access controls.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">A Practical Step You Can Take Now</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Implementing MFA now can reduce the likelihood of unauthorized access while supporting several broader organizational goals. It can strengthen cyber insurance readiness, support Security Risk Assessment findings, protect remote and privileged accounts, and demonstrate due diligence to patients, partners, and regulators.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">There may be brief adjustments as employees become familiar with a new login process, but that inconvenience is small compared with the disruption that can follow a compromised account.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The question is no longer whether MFA adds another step. The real question is whether your organization can afford to rely on passwords alone.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">MFA is one of the most practical and effective steps healthcare leaders can take today to reduce risk, protect ePHI, and prepare for where HIPAA expectations are heading.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/">Why MFA Is Essential for Healthcare Organizations</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Encryption and the Proposed HIPAA Security Rule Changes</title>
		<link>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/</link>
					<comments>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 04:00:21 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20405</guid>

					<description><![CDATA[<p>The proposed HIPAA Security Rule places greater emphasis on encryption as a core safeguard for protecting ePHI. Learn what the proposed rule changes could mean and the practical steps healthcare organizations can take today to strengthen security and prepare for future compliance requirements.</p>
<p>The post <a href="https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/">Encryption and the Proposed HIPAA Security Rule Changes</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20411 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes.webp" alt="encryption-and-the-proposed-hipaa-security-rule-changes" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">As healthcare organizations prepare for the proposed updates to the HIPAA Security Rule, one area receiving significant attention is encryption.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">While the rule has not yet been finalized and may change before publication, the proposal makes the overall direction clear: encryption is expected to become a foundational safeguard for protecting electronic protected health information (ePHI), rather than an addressable implementation specification.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">For many healthcare organizations, this is an opportunity to evaluate whether their current security practices align with where HIPAA expectations are heading.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Protecting ePHI at Rest and in Transit</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">If the proposed rule is finalized as written, organizations should expect encryption to be applied much more broadly to ePHI at rest, meaning data stored on devices or systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">This includes:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Laptops, desktops, tablets, and smartphones that store or access ePHI</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Servers and databases containing ePHI</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Backup media, including external hard drives and cloud backups</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Portable storage devices such as USB drives</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">The proposal also reinforces the importance of protecting ePHI while it is in transit, or moving between locations or systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Examples include:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Encrypted email solutions</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Secure web connections</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Virtual Private Networks (VPNs) for remote access</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Encrypted communications between healthcare applications and cloud services</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">These safeguards help reduce the risk of unauthorized access while sensitive patient information is being stored, shared, or transmitted.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Start Preparing Now</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Healthcare organizations do not need to wait for the final rule before evaluating their encryption posture.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">A practical first step is creating or updating a technology asset inventory to identify every device, application, and system that creates, receives, maintains, or transmits ePHI. From there, organizations can confirm encryption is enabled where appropriate, document current encryption standards, and identify any legacy systems that may not support modern encryption practices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Taking these steps now can help reduce future implementation costs while strengthening your organization&#8217;s overall cybersecurity posture.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">HIPAA Secure Now Is Here to Help</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Although the final rule may differ from the current proposal, the direction is becoming increasingly clear. Strong encryption is quickly becoming an expected safeguard for protecting patient data.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">HIPAA Secure Now is here to help healthcare organizations understand what may be changing, evaluate their current security posture, and prepare before the compliance clock starts. If you have questions about encryption, asset inventories, or your organization&#8217;s HIPAA readiness, our compliance team is ready to help.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/">Encryption and the Proposed HIPAA Security Rule Changes</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</title>
		<link>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/</link>
					<comments>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/#respond</comments>
		
		<dc:creator><![CDATA[Paige Merrill]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 04:00:29 +0000</pubDate>
				<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20394</guid>

					<description><![CDATA[<p>The proposed HIPAA Privacy Rule update could reshape patient access, care coordination, and privacy requirements for covered entities and business associates. Learn what the proposed changes include, when a final rule may be published, and the practical steps your organization can take to prepare now.</p>
<p>The post <a href="https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/">A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20401 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know.webp" alt=" A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know Featured Image " width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">In January 2021, the U.S. Department of Health and Human Services (HHS) published a </span><a href="https://www.federalregister.gov/documents/2021/01/21/2020-27157/proposed-modifications-to-the-hipaa-privacy-rule-to-support-and-remove-barriers-to" target="_blank" rel="noopener"><span data-contrast="none">Notice of Proposed Rulemaking (NPRM)</span></a><span data-contrast="auto"> proposing updates to the HIPAA Privacy Rule. The proposal was intended to remove barriers to coordinated care, improve individuals&#8217; access to their health information, reduce unnecessary administrative burden, and strengthen certain patient rights while continuing to protect the privacy of protected health information (PHI).</span></p>
<p><span data-contrast="auto">The proposal has remained under federal review for several years. If a final rule is published, it may adopt some, all, or none of the originally proposed changes.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">When Could This Happen?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">While HHS has not announced an official publication date, the final rule is widely expected to be published as early as August 2026 based on the federal regulatory agenda.</span></p>
<p><span data-contrast="auto">If finalized, organizations will not be expected to comply immediately. Historically, HIPAA rules have become effective 60 days after publication, with compliance required approximately 180 days later. The final rule will establish the official effective and compliance dates.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Was Included in the Proposal?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The proposed rule included several notable changes, including but not limited to:</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">Patient Access and Individual Rights</span></b><span data-ccp-props="{}"> </span></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Proposing to reduce the time to respond to an individual&#8217;s request for access to PHI from 30 calendar days to 15 calendar days </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing to strengthen an individual&#8217;s right to inspect PHI in person, including the ability to take notes and photographs </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Proposing changes to certain fees for copies of PHI, including additional transparency through website fee schedules, individualized fee estimates, and itemized bills </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Creating a pathway for individuals to direct electronic PHI maintained in an electronic health record (EHR) to another covered healthcare provider or health plan </span><span data-ccp-props="{}"> </span></li>
</ul>
<h2><b><span data-contrast="auto">Care Coordination and Permitted Disclosures</span></b><span data-ccp-props="{}"> </span></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Expanding and clarifying certain permitted uses and disclosures of PHI to improve care coordination and case management </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing changes affecting disclosures to social service agencies and community-based organizations involved in an individual&#8217;s care </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Proposing updates to certain standards governing disclosures to family members and caregivers in specific situations </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Proposing to replace the current &#8220;serious and imminent threat&#8221; standard with a &#8220;serious and reasonably foreseeable threat&#8221; standard for certain disclosures made to prevent or lessen a threat to health or safety.</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Clarifying the application of the minimum necessary standard for certain disclosures and requests for PHI to reduce unnecessary barriers to care while maintaining privacy protections </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Notice of Privacy Practices (NPP)</span></b><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Proposing revisions to the Notice of Privacy Practices (NPP), including eliminating the requirement to obtain a patient&#8217;s written acknowledgment of receipt while retaining the requirement to provide the notice </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing changes to the required content and format of the NPP to better inform individuals of their privacy rights </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Administrative and Operational Changes</span></b><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="18" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Clarifying several administrative provisions intended to reduce unnecessary regulatory burden while maintaining privacy protections</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">While the proposal covers many topics, its primary focus is improving patient access, supporting care coordination, reducing administrative burden, and updating the Notice of Privacy Practices. These changes remain proposals until a final rule is published.</span><br />
<span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Could This Mean for Covered Entities and Business Associates and What Should They Do Now?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">Covered entities are expected to be most directly affected by many of the proposed operational changes. Business associates should also review the final rule to determine whether any contractual, operational, or policy updates may be necessary.</span></p>
<p><span data-contrast="auto">Depending on the final rule, organizations may need to evaluate:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">HIPAA policies and procedures</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Patient access request workflows</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Notice of Privacy Practices</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Workforce training</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Forms and documentation</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Business associate agreements and operational processes that support HIPAA compliance</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">The final requirements, effective date, and compliance deadlines will not be known until HHS publishes the final rule.</span></p>
<p><span data-contrast="auto">Now is a good time to:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Stay informed about the publication of the final rule</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Begin identifying policies and workflows that could be affected if the proposed changes are adopted</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Plan time and resources to review and implement any new requirements once the final rule is published</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/">A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
