<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HIPAA Secure Now!</title>
	<atom:link href="http://www.hipaasecurenow.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.hipaasecurenow.com/</link>
	<description>HIPAA Compliance Made Human</description>
	<lastBuildDate>Tue, 11 Aug 2026 09:04:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.hipaasecurenow.com/wp-content/uploads/2019/05/cropped-HSN-Favicon-512px-32x32.png</url>
	<title>HIPAA Secure Now!</title>
	<link>https://www.hipaasecurenow.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>HIPAA Patch Management: What to Prepare For</title>
		<link>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/</link>
					<comments>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/#respond</comments>
		
		<dc:creator><![CDATA[Paige Merrill]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 04:00:31 +0000</pubDate>
				<category><![CDATA[Backup & Disaster Recovery]]></category>
		<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=20415</guid>

					<description><![CDATA[<p>Patch management plays an important role in protecting ePHI and reducing cybersecurity risk. Learn how the proposed HIPAA Security Rule could introduce more formal patching timelines, documentation, and annual testing requirements for covered entities and business associates.</p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/">HIPAA Patch Management: What to Prepare For</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-20416 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for.webp" alt="HIPAA Patch Mgmt" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/hipaa-patch-management-what-to-prepare-for-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">Patch management is the process of identifying, prioritizing, acquiring, installing, evaluating, and verifying software and system updates. It helps correct security weaknesses while reducing the risk that an update will disrupt operations or affect electronic protected health information (ePHI).</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">How do covered entities and business associates know what needs patching? Common sources include:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Vendor notifications and security advisories </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Automated vulnerability scans </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Penetration-testing results </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Government resources, such as CISA’s Known Exploited Vulnerabilities Catalog </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">IT or managed service provider reports </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Internal risk analyses and system reviews </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">The U.S. Department of Health and Human Services (HHS) proposed significant HIPAA Security Rule changes in December 2024. As of today, the proposal has not been finalized. The federal regulatory agenda identifies July 2027 as an estimated final-action date, but that date is not binding and may change.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">If finalized as proposed, covered entities and business associates would need written procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying patches, updates, and upgrades across relevant electronic information systems. These procedures would need to be reviewed and tested at least annually.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Critical risks generally would need remediation within 15 calendar days after the need is identified when a patch, update, or upgrade is available. High risks generally would need remediation within 30 calendar days. If remediation is unavailable, the applicable period would begin when it becomes available. Organizations would set and document timelines for other risks.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Limited exceptions would apply when remediation is unavailable or would adversely affect the confidentiality, integrity, or availability of ePHI. The organization would have to document the exception in real time and implement appropriate compensating controls.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Organizations should not wait. The HHS Office for Civil Rights has confirmed that the current HIPAA risk-analysis requirement includes risks and vulnerabilities to ePHI from unpatched software.</span><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/">HIPAA Patch Management: What to Prepare For</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/hipaa-patch-management-what-to-prepare-for/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why MFA Is Essential for Healthcare Organizations</title>
		<link>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/</link>
					<comments>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/#respond</comments>
		
		<dc:creator><![CDATA[Trent Bolish]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 04:00:09 +0000</pubDate>
				<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Remote Workforce]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=20410</guid>

					<description><![CDATA[<p>Passwords alone are no longer enough to protect healthcare systems and patient data. Learn how multi-factor authentication can reduce unauthorized access, strengthen operational resilience, and help healthcare organizations prepare for changing HIPAA expectations.</p>
<p>The post <a href="https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/">Why MFA Is Essential for Healthcare Organizations</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="aligncenter wp-image-20411 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations.webp" alt="MFA for Healthcare" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/08/why-mfa-is-essential-for-healthcare-organizations-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">For healthcare leaders, multi-factor authentication, or MFA, is more than an IT decision. It is a business decision that directly affects patient trust, operational resilience, regulatory risk, and the organization’s reputation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Healthcare organizations rely on digital systems for patient records, billing, scheduling, communication, and clinical workflows. When access to those systems is compromised, the impact can extend far beyond a single account. A breach can expose electronic protected health information (ePHI), interrupt patient care, create costly recovery work, and damage the trust an organization has worked hard to build.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Passwords Alone Are No Longer Enough</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Passwords remain one of the most common entry points for attackers. They can be stolen through phishing emails, exposed in data breaches, reused across multiple accounts, or purchased on the dark web.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Even a strong password cannot provide complete protection if it falls into the wrong hands.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">MFA adds another layer of verification before access is granted. In addition to entering a password, the user must confirm their identity through another method, such as an authentication application, security key, or unique code.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">That additional step makes it much more difficult for an attacker to enter a system using stolen credentials alone.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Why MFA Matters in Healthcare</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Healthcare organizations and their business associates manage highly sensitive information across a wide range of systems, users, and locations. Employees may access ePHI from clinical workstations, laptops, mobile devices, cloud platforms, or remote environments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">A single compromised account could provide an attacker with access to patient data, email, shared files, administrative systems, or connected applications. Privileged accounts, remote access tools, and systems containing ePHI should be especially important priorities when implementing MFA.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">HIPAA Expectations Are Changing</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">MFA is also becoming a more urgent HIPAA consideration.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Under the current HIPAA Security Rule, some access-control safeguards are considered addressable, allowing organizations to evaluate how they apply based on their circumstances. The proposed HIPAA Security Rule updates would establish stronger and more consistent expectations for MFA.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Although the proposed rule has not been finalized and its requirements may change, the direction is clear: healthcare organizations should prepare for stronger access controls.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">A Practical Step You Can Take Now</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Implementing MFA now can reduce the likelihood of unauthorized access while supporting several broader organizational goals. It can strengthen cyber insurance readiness, support Security Risk Assessment findings, protect remote and privileged accounts, and demonstrate due diligence to patients, partners, and regulators.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">There may be brief adjustments as employees become familiar with a new login process, but that inconvenience is small compared with the disruption that can follow a compromised account.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The question is no longer whether MFA adds another step. The real question is whether your organization can afford to rely on passwords alone.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">MFA is one of the most practical and effective steps healthcare leaders can take today to reduce risk, protect ePHI, and prepare for where HIPAA expectations are heading.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/">Why MFA Is Essential for Healthcare Organizations</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/why-mfa-is-essential-for-healthcare-organizations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Encryption and the Proposed HIPAA Security Rule Changes</title>
		<link>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/</link>
					<comments>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 04:00:59 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=20405</guid>

					<description><![CDATA[<p>The proposed HIPAA Security Rule places greater emphasis on encryption as a core safeguard for protecting ePHI. Learn what the proposed rule changes could mean and the practical steps healthcare organizations can take today to strengthen security and prepare for future compliance requirements.</p>
<p>The post <a href="https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/">Encryption and the Proposed HIPAA Security Rule Changes</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="aligncenter wp-image-20406 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes.webp" alt="" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/encryption-and-the-proposed-hipaa-security-rule-changes-768x432.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">As healthcare organizations prepare for the proposed updates to the HIPAA Security Rule, one area receiving significant attention is encryption.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">While the rule has not yet been finalized and may change before publication, the proposal makes the overall direction clear: encryption is expected to become a foundational safeguard for protecting electronic protected health information (ePHI), rather than an addressable implementation specification.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">For many healthcare organizations, this is an opportunity to evaluate whether their current security practices align with where HIPAA expectations are heading.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Protecting ePHI at Rest and in Transit</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">If the proposed rule is finalized as written, organizations should expect encryption to be applied much more broadly to ePHI at rest, meaning data stored on devices or systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">This includes:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Laptops, desktops, tablets, and smartphones that store or access ePHI</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Servers and databases containing ePHI</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Backup media, including external hard drives and cloud backups</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Portable storage devices such as USB drives</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">The proposal also reinforces the importance of protecting ePHI while it is in transit, or moving between locations or systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Examples include:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Encrypted email solutions</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Secure web connections</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Virtual Private Networks (VPNs) for remote access</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Encrypted communications between healthcare applications and cloud services</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">These safeguards help reduce the risk of unauthorized access while sensitive patient information is being stored, shared, or transmitted.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Start Preparing Now</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Healthcare organizations do not need to wait for the final rule before evaluating their encryption posture.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">A practical first step is creating or updating a technology asset inventory to identify every device, application, and system that creates, receives, maintains, or transmits ePHI. From there, organizations can confirm encryption is enabled where appropriate, document current encryption standards, and identify any legacy systems that may not support modern encryption practices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Taking these steps now can help reduce future implementation costs while strengthening your organization&#8217;s overall cybersecurity posture.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">HIPAA Secure Now Is Here to Help</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Although the final rule may differ from the current proposal, the direction is becoming increasingly clear. Strong encryption is quickly becoming an expected safeguard for protecting patient data.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">HIPAA Secure Now is here to help healthcare organizations understand what may be changing, evaluate their current security posture, and prepare before the compliance clock starts. If you have questions about encryption, asset inventories, or your organization&#8217;s HIPAA readiness, our compliance team is ready to help.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/">Encryption and the Proposed HIPAA Security Rule Changes</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/encryption-and-the-proposed-hipaa-security-rule-changes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</title>
		<link>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/</link>
					<comments>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/#respond</comments>
		
		<dc:creator><![CDATA[Paige Merrill]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 04:00:29 +0000</pubDate>
				<category><![CDATA[Client News]]></category>
		<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20394</guid>

					<description><![CDATA[<p>The proposed HIPAA Privacy Rule update could reshape patient access, care coordination, and privacy requirements for covered entities and business associates. Learn what the proposed changes include, when a final rule may be published, and the practical steps your organization can take to prepare now.</p>
<p>The post <a href="https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/">A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20401 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know.webp" alt=" A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know Featured Image " width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">In January 2021, the U.S. Department of Health and Human Services (HHS) published a </span><a href="https://www.federalregister.gov/documents/2021/01/21/2020-27157/proposed-modifications-to-the-hipaa-privacy-rule-to-support-and-remove-barriers-to" target="_blank" rel="noopener"><span data-contrast="none">Notice of Proposed Rulemaking (NPRM)</span></a><span data-contrast="auto"> proposing updates to the HIPAA Privacy Rule. The proposal was intended to remove barriers to coordinated care, improve individuals&#8217; access to their health information, reduce unnecessary administrative burden, and strengthen certain patient rights while continuing to protect the privacy of protected health information (PHI).</span></p>
<p><span data-contrast="auto">The proposal has remained under federal review for several years. If a final rule is published, it may adopt some, all, or none of the originally proposed changes.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">When Could This Happen?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">While HHS has not announced an official publication date, the final rule is widely expected to be published as early as August 2026 based on the federal regulatory agenda.</span></p>
<p><span data-contrast="auto">If finalized, organizations will not be expected to comply immediately. Historically, HIPAA rules have become effective 60 days after publication, with compliance required approximately 180 days later. The final rule will establish the official effective and compliance dates.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Was Included in the Proposal?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The proposed rule included several notable changes, including but not limited to:</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">Patient Access and Individual Rights</span></b><span data-ccp-props="{}"> </span></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Proposing to reduce the time to respond to an individual&#8217;s request for access to PHI from 30 calendar days to 15 calendar days </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing to strengthen an individual&#8217;s right to inspect PHI in person, including the ability to take notes and photographs </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Proposing changes to certain fees for copies of PHI, including additional transparency through website fee schedules, individualized fee estimates, and itemized bills </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Creating a pathway for individuals to direct electronic PHI maintained in an electronic health record (EHR) to another covered healthcare provider or health plan </span><span data-ccp-props="{}"> </span></li>
</ul>
<h2><b><span data-contrast="auto">Care Coordination and Permitted Disclosures</span></b><span data-ccp-props="{}"> </span></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Expanding and clarifying certain permitted uses and disclosures of PHI to improve care coordination and case management </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing changes affecting disclosures to social service agencies and community-based organizations involved in an individual&#8217;s care </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Proposing updates to certain standards governing disclosures to family members and caregivers in specific situations </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Proposing to replace the current &#8220;serious and imminent threat&#8221; standard with a &#8220;serious and reasonably foreseeable threat&#8221; standard for certain disclosures made to prevent or lessen a threat to health or safety.</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Clarifying the application of the minimum necessary standard for certain disclosures and requests for PHI to reduce unnecessary barriers to care while maintaining privacy protections </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Notice of Privacy Practices (NPP)</span></b><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Proposing revisions to the Notice of Privacy Practices (NPP), including eliminating the requirement to obtain a patient&#8217;s written acknowledgment of receipt while retaining the requirement to provide the notice </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proposing changes to the required content and format of the NPP to better inform individuals of their privacy rights </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Administrative and Operational Changes</span></b><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="18" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Clarifying several administrative provisions intended to reduce unnecessary regulatory burden while maintaining privacy protections</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">While the proposal covers many topics, its primary focus is improving patient access, supporting care coordination, reducing administrative burden, and updating the Notice of Privacy Practices. These changes remain proposals until a final rule is published.</span><br />
<span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">What Could This Mean for Covered Entities and Business Associates and What Should They Do Now?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:200,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">Covered entities are expected to be most directly affected by many of the proposed operational changes. Business associates should also review the final rule to determine whether any contractual, operational, or policy updates may be necessary.</span></p>
<p><span data-contrast="auto">Depending on the final rule, organizations may need to evaluate:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">HIPAA policies and procedures</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Patient access request workflows</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Notice of Privacy Practices</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Workforce training</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Forms and documentation</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Business associate agreements and operational processes that support HIPAA compliance</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">The final requirements, effective date, and compliance deadlines will not be known until HHS publishes the final rule.</span></p>
<p><span data-contrast="auto">Now is a good time to:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Stay informed about the publication of the final rule</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Begin identifying policies and workflows that could be affected if the proposed changes are adopted</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:360,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;singleLevel&quot;}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Plan time and resources to review and implement any new requirements once the final rule is published</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/">A HIPAA Privacy Rule Update Could Arrive as Early as August 2026. Here’s What Covered Entities and Business Associates Should Know</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/a-hipaa-privacy-rule-update-could-arrive-as-early-as-august-2026-heres-what-covered-entities-and-business-associates-should-know/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Preparing Your 2027 Budget for the Proposed HIPAA Security Rule</title>
		<link>https://www.hipaasecurenow.com/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule/</link>
					<comments>https://www.hipaasecurenow.com/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 04:00:32 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20384</guid>

					<description><![CDATA[<p>If the proposed HIPAA Security Rule is finalized, healthcare organizations may have just 180 days to demonstrate compliance. Learn how budgeting for cybersecurity and compliance improvements now can help your organization avoid rushed decisions and strengthen security long before the deadline.</p>
<p>The post <a href="https://www.hipaasecurenow.com/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule/">Preparing Your 2027 Budget for the Proposed HIPAA Security Rule</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20392 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule.webp" alt="Preparing Your 2027 Budget for the Proposed HIPAA Security Rule" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">The proposed updates to the HIPAA Security Rule are expected to move forward in 2027, and if the rule is finalized as proposed, healthcare organizations could have as little as 180 days to demonstrate compliance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">While six months may sound like plenty of time, the reality is different for many healthcare practices. Budget planning often happens only once a year, and significant security improvements can take time to evaluate, purchase, implement, and document.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">That is why now is the right time to start the conversation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Budgeting Today Can Prevent Scrambling Tomorrow</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Preparing for the proposed rule does not mean you need to invest in every security solution immediately. Instead, think of this year&#8217;s budgeting process as an opportunity to identify potential gaps, prioritize future investments, and create a roadmap that aligns with your organization&#8217;s needs.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Many of the safeguards highlighted in the proposed rule are already considered cybersecurity best practices and can strengthen your organization&#8217;s security regardless of when the final rule is published.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">As you build your 2027 budget, consider planning for investments such as:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Multi-factor authentication (MFA)</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Encryption</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Technology asset inventories</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Vulnerability scanning and remediation</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Backup and disaster recovery testing</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Security Risk Assessments and ongoing risk management</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">HIPAA and cybersecurity awareness training</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Updated policies and procedures</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Business associate and vendor risk management</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<h2 aria-level="2"></h2>
<h2 aria-level="2"><b><span data-contrast="none">Work with Your Trusted Advisors</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">You do not have to figure out every requirement on your own.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Now is an excellent time to meet with your IT provider, managed service provider (MSP), or compliance partner to review your current security posture, discuss where improvements may be needed, and estimate future costs. Having those conversations before budgets are finalized gives your organization greater flexibility and helps avoid unexpected expenses later.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Prepare with Confidence</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Organizations that budget and plan ahead are far less likely to face rushed purchasing decisions, implementation delays, or last-minute compliance challenges if the final rule moves forward.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">More importantly, many of these investments provide immediate value by reducing cybersecurity risk, strengthening the protection of electronic protected health information (ePHI), and improving your overall security posture.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">HIPAA Secure Now is here to help healthcare organizations prepare before the clock starts. By taking practical steps today, you can make the 180-day compliance window far more manageable while building a stronger, more resilient organization for the future.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule/">Preparing Your 2027 Budget for the Proposed HIPAA Security Rule</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/preparing-your-2027-budget-for-the-proposed-hipaa-security-rule/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The SRA: Your Roadmap to Stronger HIPAA Compliance</title>
		<link>https://www.hipaasecurenow.com/the-sra-your-roadmap-to-stronger-hipaa-compliance/</link>
					<comments>https://www.hipaasecurenow.com/the-sra-your-roadmap-to-stronger-hipaa-compliance/#respond</comments>
		
		<dc:creator><![CDATA[Trent Bolish]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 04:00:50 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=20372</guid>

					<description><![CDATA[<p>A Security Risk Assessment is more than a HIPAA requirement. It helps healthcare organizations understand risk, protect ePHI, strengthen documentation, and prepare for changing cybersecurity expectations.</p>
<p>The post <a href="https://www.hipaasecurenow.com/the-sra-your-roadmap-to-stronger-hipaa-compliance/">The SRA: Your Roadmap to Stronger HIPAA Compliance</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20377 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/the-sra-your-roadmap-to-stronger-hipaa-compliance.webp" alt="The SRA: Your Roadmap to Stronger HIPAA Compliance Featured Image" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/07/the-sra-your-roadmap-to-stronger-hipaa-compliance.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/the-sra-your-roadmap-to-stronger-hipaa-compliance-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/the-sra-your-roadmap-to-stronger-hipaa-compliance-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/07/the-sra-your-roadmap-to-stronger-hipaa-compliance-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p><span data-contrast="auto">For healthcare executives and practice owners, <a href="https://breachsecurenow.com/healthcare-clients-and-cybersecurity/" target="_blank" rel="noopener">cybersecurity is no longer just an IT responsibility</a>. It is a business risk, a patient trust issue, and a core part of HIPAA compliance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">As cyberattacks against healthcare organizations continue to rise, conducting a thorough Security Risk Assessment, or SRA, is one of the most important steps your organization can take to protect electronic protected health information, also known as ePHI.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>Read more: <a href="https://breachsecurenow.com/opportunities-for-msps-in-healthcare/" target="_blank" rel="noopener">Opportunities for MSPs in Healthcare</a></p>
<h2 aria-level="2"><b><span data-contrast="none">More Than a Compliance Requirement</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">The HIPAA Security Rule requires covered entities and business associates to regularly evaluate risks to ePHI. But a strong SRA should be more than a compliance exercise.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">It should help your organization understand where sensitive data lives, how it moves, who can access it, and where vulnerabilities may exist across systems, vendors, devices, and workflows.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>Read more: <a href="https://breachsecurenow.com/why-continuous-training-beats-one-and-done-cyber-awareness/" target="_blank" rel="noopener">Why Continuous Training Beats One-and-Done Cyber Awareness</a></p>
<h2 aria-level="2"><b><span data-contrast="none">Visibility Is the First Step Toward Protection</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">Without clear visibility, healthcare organizations may overlook gaps that could lead to unauthorized access, data exposure, operational disruption, or regulatory scrutiny.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">A well-executed SRA gives leaders a practical roadmap. It helps identify weaknesses, prioritize security investments, strengthen policies and procedures, and document the steps your organization is taking to reduce risk.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">For small and mid-sized healthcare practices that may not have a dedicated compliance officer, this kind of guidance can make HIPAA readiness feel more manageable.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>Read More: <a href="https://breachsecurenow.com/safeguarding-your-business-the-proactive-path-to-strong-cybersecurity/" target="_blank" rel="noopener">Proactive Cybersecurity Strategies to Protect Your Business</a></p>
<h2 aria-level="2"><b><span data-contrast="none">Proposed Rule Changes Raise the Stakes</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">The proposed updates to the HIPAA Security Rule reinforce the importance of moving beyond a “check-the-box” approach.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">If finalized as proposed, the changes could require more detailed documentation, regular reassessments, technology asset inventories, ePHI mapping, and ongoing risk management.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">In other words, risk analysis is not something to complete once and file away. It is an ongoing process that should evolve as your technology, workforce, vendors, and threat landscape change.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">OCR Is Paying Attention</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">The U.S. Department of Health and Human Services Office for Civil Rights has also emphasized risk analysis through its enforcement activity. Inadequate or missing SRAs continue to appear in investigations, often leading to penalties and corrective action plans.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><b><span data-contrast="none">Build Confidence Before Pressure Builds</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h2>
<p><span data-contrast="auto">A Security Risk Assessment does more than support HIPAA compliance. It helps healthcare leaders make informed decisions, protect patient data, strengthen trust, and build a more resilient organization.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">HIPAA Secure Now is here to help healthcare organizations take that next step with confidence.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/the-sra-your-roadmap-to-stronger-hipaa-compliance/">The SRA: Your Roadmap to Stronger HIPAA Compliance</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/the-sra-your-roadmap-to-stronger-hipaa-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Don&#8217;t Wait for the Final HIPAA Rule: Start with Your Asset Inventory</title>
		<link>https://www.hipaasecurenow.com/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory/</link>
					<comments>https://www.hipaasecurenow.com/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory/#respond</comments>
		
		<dc:creator><![CDATA[Kim Berardi]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 04:00:46 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://hsnstg.wpengine.com/?p=19557</guid>

					<description><![CDATA[<p>While the HIPAA Security Rule update is not final yet, small healthcare practices can start preparing now by building or updating an asset inventory. This simple step can improve visibility, strengthen risk analysis, and support stronger ePHI protection.</p>
<p>The post <a href="https://www.hipaasecurenow.com/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory/">Don&#8217;t Wait for the Final HIPAA Rule: Start with Your Asset Inventory</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="wp-image-20345 size-full aligncenter" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/06/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory.webp" alt="HIPAA Inventory" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/06/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p>&nbsp;</p>
<p><span data-contrast="auto">The proposed HIPAA Security Rule update has not been finalized yet, but small healthcare practices should not wait until the deadline is set to start preparing.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">One practical step your organization can take now is to begin building, reviewing, or updating your asset inventory.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">An asset inventory is a documented list of the systems, devices, software, vendors, and access points that may create, receive, maintain, or transmit electronic protected health information, also known as ePHI. While asset inventories have not historically been listed as a specific HIPAA Security Rule requirement, the proposed updates could make them a much more formal expectation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">More importantly, an asset inventory is a smart foundation for your overall security and compliance program.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Why does it matter?</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Because you cannot protect what you do not know exists. If your practice does not have a clear picture of where ePHI lives, how it moves, and who can access it, your risk analysis may miss important gaps. That can make it harder to identify vulnerabilities, update policies, manage vendor risk, and show that your organization is taking reasonable steps to protect patient data.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>&nbsp;</p>
<h2><span data-contrast="auto">A strong asset inventory should include:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Hardware, such as computers, laptops, mobile devices, servers, medical devices, and equipment that touches ePHI</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Software and applications, including EHR/EMR systems, billing platforms, cloud tools, and other SaaS applications</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Data flows that show where ePHI is stored, transmitted, and accessed</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Vendors and business associates that interact with your systems or patient data</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Network components, such as routers, firewalls, remote access tools, and other connection points</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">User access, including who has access to what and at what permission level</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">The goal is not perfection on day one. The goal is visibility.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Starting now gives your practice time to identify what you use, where patient data may be exposed, and which areas may need stronger safeguards. It can also make future compliance work easier if the proposed rule is finalized and organizations have a shorter window to act.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto"><strong>HIPAA Secure Now</strong> is here to help healthcare organizations take practical steps before the clock starts. For more information, or to request a sample Asset Inventory, please reach out to our compliance team.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.hipaasecurenow.com/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory/">Don&#8217;t Wait for the Final HIPAA Rule: Start with Your Asset Inventory</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/dont-wait-for-the-final-hipaa-rule-start-with-your-asset-inventory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What the Proposed HIPAA Security Rule Changes Could Mean for Your Organization</title>
		<link>https://www.hipaasecurenow.com/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization/</link>
					<comments>https://www.hipaasecurenow.com/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization/#respond</comments>
		
		<dc:creator><![CDATA[Zach Morrison]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 04:00:44 +0000</pubDate>
				<category><![CDATA[Download]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Audits]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[HSN News]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Reminders]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[featured]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=19550</guid>

					<description><![CDATA[<p>&#160; HIPAA compliance has always required ongoing attention. But with proposed changes to the HIPAA Security Rule now on the table, healthcare organizations may need to prepare for a higher standard of cybersecurity, documentation, and ePHI protection.  In January 2025, the U.S. Department of Health and Human Services Office for Civil Rights proposed major updates to the [&#8230;]</p>
<p>The post <a href="https://www.hipaasecurenow.com/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization/">What the Proposed HIPAA Security Rule Changes Could Mean for Your Organization</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-19551 size-full" src="https://www.hipaasecurenow.com/wp-content/uploads/2026/06/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization.webp" alt="HIPAA Changes" width="1200" height="675" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2026/06/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization.webp 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization-300x169.webp 300w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization-1024x576.webp 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2026/06/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization-768x432.webp 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p>&nbsp;</p>
<p><span data-contrast="none">HIPAA compliance has always required ongoing attention. But with proposed changes to the HIPAA Security Rule now on the table, healthcare organizations may need to prepare for a higher standard of cybersecurity, documentation, and ePHI protection.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none">In January 2025, the U.S. Department of Health and Human Services Office for Civil Rights proposed major updates to the HIPAA Security Rule. If finalized as proposed, the updates could raise expectations around cybersecurity, documentation, workforce training, and how electronic protected health information, or ePHI, is protected.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">For small and mid-sized healthcare organizations, that can feel like a lot to take on. You may already be balancing patient care, staffing, billing, vendor relationships, insurance requirements, and daily operations. Adding new compliance expectations to the list can feel like one more thing you don’t have time to manage.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">That is exactly why preparation matters. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2><b>What Could Change?</b></h2>
<p><span data-contrast="none">The proposed updates focus on safeguards healthcare organizations should already be evaluating, including:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Technology asset inventories</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Risk analysis</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Multifactor authentication</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Encryption</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="none">Vulnerability management</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="none">Contingency planning</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="none">Documented policies and procedures</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="none">Stronger incident response planning</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="none">Business associate oversight</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="none">Workforce training</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="none">Some of these areas may already be part of your compliance program. Others may need more documentation, stronger processes, or closer review if the rule is finalized as proposed.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">The proposed updates point to a clear theme: healthcare organizations may need to show that safeguards are not only in place, but also documented, reviewed, and maintained over time.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<h2><b>Why This Matters Now</b></h2>
<p><span data-contrast="none">The response across the healthcare industry has been mixed. Many healthcare organizations have raised concerns about cost, timing, operational burden, and the potential impact on smaller or rural providers. At the same time, federal lawmakers continue to discuss stronger cybersecurity expectations across healthcare, including legislation aimed at improving cybersecurity resilience throughout the industry.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none">Those developments may seem to pull in different directions, but they point to the same reality: healthcare organizations should be paying close attention to cybersecurity and HIPAA compliance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none">The timeline is what makes this especially important. If the proposed rule is finalized as written, covered entities and business associates may have as little as 180 days to demonstrate compliance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none">That is a short runway for organizations that may need to:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Identify compliance and security gaps</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Update policies and procedures</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Implement or strengthen security controls</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Train employees</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="none">Review vendor and business associate relationships</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="none">Document compliance efforts</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="none">For organizations without a dedicated compliance officer or internal HIPAA expert, waiting could make the process more stressful than it needs to be.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2><b>Preparation Doesn&#8217;t Have to Happen All at Once</b></h2>
<p><span data-contrast="none">The good news is that preparing for what may be coming doesn’t mean everything overnight.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none"> It starts with understanding what has been proposed, reviewing where your compliance program stands today, and taking practical steps to strengthen the safeguards that protect patient data.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="none">That may include reviewing your Security Risk Assessment, confirming policies and procedures are current, checking how your organization manages employee training, and looking more closely at areas like MFA, encryption, vendor oversight, and incident response.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">It also means helping employees understand their role in protecting patient data, especially as cyber threats, AI tools, and Microsoft 365 usage continue to shape daily healthcare operations.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<h2><b><span data-contrast="none">HIPAA Secure Now Can Help</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></h2>
<p><span data-contrast="none">Since 2010, HIPAA Secure Now has helped more than 5,000 healthcare organizations strengthen HIPAA compliance, protect patient data, and reduce cyber risk.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">We provide HIPAA training, Security Risk Assessments, policies and procedures, phishing awareness, vulnerability tools, AI training, Microsoft 365 productivity training, and compliance support designed specifically for healthcare organizations.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">Our connected compliance and training platform helps make HIPAA easier to understand, document, and maintain over time, so your organization can take practical steps before the deadline is set.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">Protecting patient data is about more than meeting a requirement. It’s about knowing you can answer with confidence when someone asks, “Can you show me your HIPAA compliance program?”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="none">The proposed rule is not final yet. The time to prepare is before the deadline is set.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:160}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"><a class="blog-cta-button" href="https://hubs.ly/Q04mvz-Y0" target="_blank" rel="noopener"><strong>Download the Industry Brief</strong></a></span></p>
<p><span class="TextRun SCXW63559522 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW63559522 BCX0">Learn what may be changing, why it matters, and how HIPAA Secure Now can help your organization prepare.</span></span></p>
<p>The post <a href="https://www.hipaasecurenow.com/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization/">What the Proposed HIPAA Security Rule Changes Could Mean for Your Organization</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/what-the-proposed-hipaa-security-rule-changes-could-mean-for-your-organization/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Is Acceptable Use in a Medical Office?</title>
		<link>https://www.hipaasecurenow.com/what-is-acceptable-use-in-a-medical-office/</link>
					<comments>https://www.hipaasecurenow.com/what-is-acceptable-use-in-a-medical-office/#respond</comments>
		
		<dc:creator><![CDATA[Art Gross]]></dc:creator>
		<pubDate>Mon, 28 Jul 2025 21:08:40 +0000</pubDate>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Policies and Procedures]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=19538</guid>

					<description><![CDATA[<p>Walk into any medical office today, and you’ll probably hear the soft ping of an email, maybe a Teams message popping up on someone’s screen. Chances are someone else is copying patient instructions into a word processor or using a chatbot to summarize notes. It all blends in with the workday. The tools feel familiar. [&#8230;]</p>
<p>The post <a href="https://www.hipaasecurenow.com/what-is-acceptable-use-in-a-medical-office/">What Is Acceptable Use in a Medical Office?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="642" data-end="936"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-19539" src="https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-38.png" alt="" width="1200" height="400" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-38.png 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-38-300x100.png 300w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-38-1024x341.png 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-38-768x256.png 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p data-start="642" data-end="936">Walk into any medical office today, and you’ll probably hear the soft ping of an email, maybe a Teams message popping up on someone’s screen. Chances are someone else is copying patient instructions into a word processor or using a chatbot to summarize notes. It all blends in with the workday.</p>
<p data-start="938" data-end="982">The tools feel familiar. That’s the problem.</p>
<p data-start="984" data-end="1282">When something feels routine, it’s easy to forget how much risk it carries. Especially when the systems involved are handling patient data. Most teams aren’t doing anything malicious—they’re just moving fast, solving problems, and trying to get through the day. That’s exactly when mistakes happen.</p>
<p data-start="1284" data-end="1447">An acceptable use policy helps with that. Not by scaring people, but by drawing clear lines around what’s appropriate, what’s not, and what should trigger a pause.</p>
<h2 data-start="1454" data-end="1490">Where Most People Slip Up: Email</h2>
<p data-start="1492" data-end="1685">Email feels harmless. It’s the go-to for appointment reminders, referral requests, lab results, and staff communication. But it’s also one of the easiest places for <a href="https://www.hhs.gov/hipaa/for-professionals/privacy/index.html" target="_blank" rel="noopener">patient information to leak</a>.</p>
<p data-start="1687" data-end="1701">Some examples:</p>
<ul data-start="1702" data-end="1876">
<li data-start="1702" data-end="1752">
<p data-start="1704" data-end="1752">Sending the wrong attachment to the right person</p>
</li>
<li data-start="1753" data-end="1791">
<p data-start="1755" data-end="1791">Forgetting to BCC on a group message</p>
</li>
<li data-start="1792" data-end="1876">
<p data-start="1794" data-end="1876">Forwarding a sensitive message to a personal inbox so it’s easier to print at home</p>
</li>
</ul>
<p data-start="1878" data-end="1957">None of these actions start with bad intentions. But they create real exposure.</p>
<p data-start="1959" data-end="2228">A policy needs to call that out, plainly. Staff should know when it’s okay to send PHI over email, and when it’s not. If encryption isn’t automatic, that needs to be clear too. Some offices go further and restrict emailing PHI altogether unless a secure system is used.</p>
<p data-start="2230" data-end="2309">Make sure people understand the rules before a mistake forces the conversation.</p>
<h2 data-start="2316" data-end="2342">AI Use Is Growing Fast</h2>
<p data-start="2344" data-end="2521">There’s no shortage of tools that promise to speed things up. From grammar checkers built into browsers to full-blown AI assistants, people are using them. Often without asking.</p>
<p data-start="2523" data-end="2677">And here’s the thing: many of these platforms collect and store the input they’re given. That includes copy-pasted notes, emails, and yes—patient details.</p>
<p data-start="2679" data-end="2872">If an employee pastes a progress note into an AI tool to rewrite it “more clearly,” that data leaves your system. You don’t get it back. There’s no agreement in place, no guarantee of security.</p>
<p data-start="2874" data-end="3147">This isn’t about banning technology altogether. Some AI tools are safe to use for general writing help. But the line needs to be clear: don’t feed these systems sensitive information, ever. The policy should say so in plain terms. No fine print, no room for interpretation.</p>
<h2 data-start="3154" data-end="3203">Personal Devices and Apps: Another Blind Spot</h2>
<p data-start="3205" data-end="3487">Most people don’t think twice about checking work email on their phone. Or jotting a reminder in their Notes app. Maybe they message a coworker a patient name to coordinate care. All of it seems efficient—until something gets lost, copied, or accidentally sent to the wrong contact.</p>
<p data-start="3489" data-end="3722">If personal devices are allowed, <a href="https://www.hipaasecurenow.com/byod-policy/" target="_blank" rel="noopener">that has to come with conditions</a>. Require passcodes. Disable app syncing for certain platforms. Clarify which apps are approved and which aren’t. And make sure everyone knows where the boundaries are.</p>
<p data-start="3724" data-end="3818">Without a shared understanding, people fill in the blanks themselves. That’s where risk lives.</p>
<h2 data-start="3825" data-end="3874">The Policy Only Works If People Understand It</h2>
<p data-start="3876" data-end="4019">A 12-page acceptable use document full of legalese won’t help your team avoid trouble. Nobody reads it. And if they do, they won’t remember it.</p>
<p data-start="4021" data-end="4270">Keep it short. Use plain language. Give real examples of what’s allowed and what’s not. Review it regularly, not just during onboarding. Post the top five takeaways where people will actually see them—break rooms, log-in screens, onboarding packets.</p>
<p data-start="4272" data-end="4387">Training helps too. Not a video once a year, but small, repeatable reminders tied to the tools people actually use.</p>
<h2 data-start="4394" data-end="4427">Before You Rework Your Policy</h2>
<p data-start="4429" data-end="4577">If any of this feels familiar, that’s probably a good thing. It means you’re noticing where gaps exist—and that’s the first step toward fixing them.</p>
<p data-start="4579" data-end="4811">HIPAA Secure Now offers real-world training and policy templates that make acceptable use more than just a document. We help healthcare teams apply these rules to the tools they use every day, like email, Microsoft 365, and even AI.</p>
<p data-start="4813" data-end="4907">Want to build a policy that actually sticks? <a class="" href="http://hipaasecurenow.com/sales-support/" target="_blank" rel="noopener" data-start="4858" data-end="4872">Reach out</a>. We’ll help you get it done right.</p>
<p>The post <a href="https://www.hipaasecurenow.com/what-is-acceptable-use-in-a-medical-office/">What Is Acceptable Use in a Medical Office?</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/what-is-acceptable-use-in-a-medical-office/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Most Healthcare Leaders See the Promise of GenAI—Only 36% Feel Ready</title>
		<link>https://www.hipaasecurenow.com/gen-ai-2025-survey/</link>
					<comments>https://www.hipaasecurenow.com/gen-ai-2025-survey/#respond</comments>
		
		<dc:creator><![CDATA[Art Gross]]></dc:creator>
		<pubDate>Mon, 07 Jul 2025 16:02:26 +0000</pubDate>
				<category><![CDATA[Healthcare Industry]]></category>
		<category><![CDATA[Security Training]]></category>
		<guid isPermaLink="false">https://www.hipaasecurenow.com/?p=19533</guid>

					<description><![CDATA[<p>If you run or support a small healthcare organization, you’re probably used to doing more with less. You manage compliance, care, billing, and tech—often without a big team or deep pockets. So when you hear terms like “Generative AI training,” it might feel out of reach. But the 2025 Wolters Kluwer Future Ready Healthcare Survey [&#8230;]</p>
<p>The post <a href="https://www.hipaasecurenow.com/gen-ai-2025-survey/">Most Healthcare Leaders See the Promise of GenAI—Only 36% Feel Ready</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="552" data-end="814"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-19535" src="https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-37.png" alt="" width="1200" height="400" srcset="https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-37.png 1200w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-37-300x100.png 300w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-37-1024x341.png 1024w, https://www.hipaasecurenow.com/wp-content/uploads/2025/07/HSN-Blog-Covers-37-768x256.png 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p data-start="552" data-end="814">If you run or support a small healthcare organization, you’re probably used to doing more with less. You manage compliance, care, billing, and tech—often without a big team or deep pockets. So when you hear terms like “Generative AI training,” it might feel out of reach.</p>
<p data-start="816" data-end="890">But the<a href="https://www.wolterskluwer.com/en/know/future-ready-healthcare" target="_blank" rel="noopener"> 2025 Wolters Kluwer Future Ready Healthcare Survey</a> says otherwise.</p>
<p data-start="892" data-end="1004">Most healthcare leaders aren’t ahead of the curve—they’re still trying to figure it out. According to the study:</p>
<ul data-start="1006" data-end="1239">
<li data-start="1006" data-end="1060">
<p data-start="1008" data-end="1060"><strong data-start="1008" data-end="1015">80%</strong> say optimizing workflows is a top priority</p>
</li>
<li data-start="1061" data-end="1105">
<p data-start="1063" data-end="1105"><strong data-start="1063" data-end="1070">76%</strong> want to reduce clinician burnout</p>
</li>
<li data-start="1106" data-end="1179">
<p data-start="1108" data-end="1179">Only <strong data-start="1113" data-end="1120">36%</strong> feel truly prepared to use GenAI to solve those problems</p>
</li>
<li data-start="1180" data-end="1239">
<p data-start="1182" data-end="1239">And just <strong data-start="1191" data-end="1198">18%</strong> have policies in place to guide AI use</p>
</li>
</ul>
<p data-start="1241" data-end="1337">That gap between goals and action? It’s where risk lives and opportunity begins.</p>
<h2 data-start="1344" data-end="1391">When GenAI Shows Up Quietly, So Do the Risks</h2>
<p data-start="1393" data-end="1650">Here’s what’s happening in most healthcare environments right now: someone on the team uses ChatGPT to rewrite patient instructions. A front desk staffer asks it to draft a policy update. A manager tries out an AI-based transcription tool for meeting notes.</p>
<p data-start="1652" data-end="1779">They’re not doing anything wrong—they’re just trying to move faster. But without training or guardrails, things get risky fast:</p>
<ul data-start="1781" data-end="1942">
<li data-start="1781" data-end="1813">
<p data-start="1783" data-end="1813"><strong data-start="1783" data-end="1811">PHI slips into a chatbot</strong></p>
</li>
<li data-start="1814" data-end="1871">
<p data-start="1816" data-end="1871"><strong data-start="1816" data-end="1869">Sensitive notes end up stored on external servers</strong></p>
</li>
<li data-start="1872" data-end="1942">
<p data-start="1874" data-end="1942"><strong data-start="1874" data-end="1942">AI-generated content gets mistaken for accurate medical guidance</strong></p>
</li>
</ul>
<p data-start="1944" data-end="2068">These aren’t theoretical risks. They’re happening now. And in healthcare, even small mistakes can have serious consequences.</p>
<h2 data-start="2075" data-end="2139">The Survey’s Real Takeaway? No One Has This Fully Figured Out</h2>
<p data-start="2141" data-end="2377">The most surprising part of the Wolters Kluwer survey isn’t that AI is rising. It’s that even major health systems aren’t fully prepared. Less than 1 in 5 organizations have formal GenAI policies. Fewer than 1 in 4 offer staff training.</p>
<p data-start="2379" data-end="2514">That means smaller practices and business associates have a real chance to lead—not by doing more, but by doing the right things first.</p>
<h2 data-start="2521" data-end="2557">What That Could Look Like for You</h2>
<p data-start="2559" data-end="2636">Let’s keep it simple. Here’s what “taking the lead” might mean for your team:</p>
<ul data-start="2638" data-end="3040">
<li data-start="2638" data-end="2746">
<p data-start="2640" data-end="2746">Start by <strong data-start="2649" data-end="2692">talking about where AI already shows up</strong>—in Microsoft 365, in browser tools, in EHR plug-ins</p>
</li>
<li data-start="2747" data-end="2852">
<p data-start="2749" data-end="2852">Create a basic <strong data-start="2764" data-end="2789">acceptable use policy</strong> to help staff understand what’s safe to share and what’s not</p>
</li>
<li data-start="2853" data-end="2936">
<p data-start="2855" data-end="2936">Offer short, <strong data-start="2868" data-end="2896">practical GenAI training</strong> that explains risks in plain language</p>
</li>
<li data-start="2937" data-end="3040">
<p data-start="2939" data-end="3040">Review tools you’re already using to see if any of them now include AI features you didn’t plan for</p>
</li>
</ul>
<p data-start="3042" data-end="3161">You don’t need a full-time AI officer. You need awareness, clarity, and some shared language to keep your team aligned.</p>
<h2 data-start="3168" data-end="3216">Moving Slowly Isn’t the Same as Moving Safely</h2>
<p data-start="3218" data-end="3381">A lot of healthcare leaders are taking the “wait and see” approach. That’s understandable. But it won’t stop your staff—or your vendors—from adopting GenAI anyway.</p>
<p data-start="3383" data-end="3630">The Wolters Kluwer survey makes this clear: the pressure to adopt AI is already here. But most organizations aren’t matching that pressure with preparation. That’s where risk starts to grow—quietly, in day-to-day tools, far from the IT department.</p>
<p data-start="3632" data-end="3730">The solution isn’t to rush. It’s to educate. A little clarity now can prevent a lot of mess later.</p>
<h2 data-start="2516" data-end="2553">Want a Simple Way to Move Forward?</h2>
<p data-start="2555" data-end="2725">At HIPAA Secure Now, we’ve helped healthcare organizations build strong foundations around security, compliance, and training for years. Now we’re doing the same with AI.</p>
<p data-start="2727" data-end="2836">Our <strong data-start="2731" data-end="2757">Generative AI Training</strong> is built specifically for covered entities and business associates. It covers:</p>
<ul data-start="2838" data-end="3054">
<li data-start="2838" data-end="2875">
<p data-start="2840" data-end="2875">What GenAI is (and what it’s not)</p>
</li>
<li data-start="2876" data-end="2933">
<p data-start="2878" data-end="2933">How to use it safely in a HIPAA-regulated environment</p>
</li>
<li data-start="2934" data-end="2991">
<p data-start="2936" data-end="2991">The right way to talk about it with staff and vendors</p>
</li>
<li data-start="2992" data-end="3054">
<p data-start="2994" data-end="3054">And how to introduce it without overcomplicating the process</p>
</li>
</ul>
<p data-start="3056" data-end="3159">It’s short, practical, and designed to help you stay in control of where GenAI shows up next.</p>
<p data-start="3161" data-end="3240"><strong data-start="3161" data-end="3240">→ Want to start the conversation inside your organization? <a class="" href="https://www.hipaasecurenow.com/sales-support/" target="_blank" rel="noopener" data-start="3222" data-end="3238">Let’s talk.</a></strong></p>
<p>The post <a href="https://www.hipaasecurenow.com/gen-ai-2025-survey/">Most Healthcare Leaders See the Promise of GenAI—Only 36% Feel Ready</a> appeared first on <a href="https://www.hipaasecurenow.com">HIPAA Secure Now!</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.hipaasecurenow.com/gen-ai-2025-survey/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
