No, as of September 2026, the proposed HIPAA Security Rule overhaul (mandatory encryption, MFA, asset inventories, semiannual vulnerability scans, annual penetration testing, 72-hour restoration, and more) is still not final law. U.S. Department of Health and Human Services (HHS) has pushed its target finalization date multiple times, most recently to around July 2027. And that’s the target to issue a final rule, not a compliance deadline. The proposed rule itself specifies 60 days to an effective date plus a 180-day compliance period after that (240 days total), which points to roughly March 2028 for actual compliance if HHS hits its current target. Separately, the Notice of Privacy Practices (NPP) update for substance use disorder (42 CFR Part 2) records (which applies to every HIPAA-covered dental practice regardless of size) deadline passed on February 16, 2026.
Let’s clear something up, because a lot of what’s floating around the internet right now is going to get your practice pointed in the wrong direction.
If you’ve read a blog post, a webinar invite, or a vendor email talking about “the new HIPAA Security Rule requirements” (mandatory encryption, multi-factor authentication, the whole list) as if they’re already in effect, that’s not accurate. Not yet, anyway. And getting this distinction right matters, because reacting to a rule that hasn’t been finalized can mean spending time and money in the wrong order, or just as bad, assuming you’re covered because you haven’t heard it’s “official,” when the current rules already expect more from you than you might think.
What’s Required by HIPAA Right Now
One HIPAA deadline in 2026 is final and already passed: by February 16, 2026, every HIPAA-covered dental practice was required to update its Notice of Privacy Practices (NPP) to address how PHI from substance use disorder treatment programs gets used and disclosed, under a rule aligning 42 CFR Part 2 with HIPAA [4]. This applies even to practices that don’t specifically treat SUD patients. If your NPP still predates that update, we suggest updating it this week.
Beyond that specific deadline, the existing Security Rule (the one that’s been on the books, not the proposed overhaul) already requires things a lot of practice haven’t fully implemented:
- A genuine, documented risk analysis – an accurate and thorough assessment that gets revisited). We walk through what this looks like, including how it interacts with ransomware-specific breach presumption rules, in our ransomware & HIPAA compliance guide.
- Patient right of access – records provided within 30 days, full stop, regardless of an outstanding balance. Enforcement actions have hit practices for exactly this; see what those consequences look like.
- Appropriate safeguards around who can access PHI, based on role – across every system that touches it, including your practice management software, not just your server.
- Keeping known vulnerabilities patched, including on operating systems (OS). The current rule doesn’t use the words “patch” or “operating systems”, but the Office for Civil Rights (OCR) has directly addressed this in guidance with its June 2018 Cybersecurity Newsletter where it ties unpatched software to the existing, required risk analysis and risk management standards [8], and specifically recommends including “operating systems, applications, device firmware and other software” in a technology inventory so patching gaps can be tracked. Basically, an unsupported OS that no longer receives security patches is exactly the kind of risk this obligation is about. We’ve covered this in detail for two systems on a hard countdown – Windows 10 to 11: What Your Dental Practice Needs to Know and Windows Server 2016 End of Life.
The OCR has said that its enforcement focus has shifted from “do you have a policy?” to “prove this policy is actually working.” That’s happening under the rules that already exist today. And small practices aren’t flying under the radar. OCR has pursued solo practitioners with penalties ranging from a few thousand dollars up into six figures.
What’s Proposed for the HIPAA Security Rule
The big Security Rule overhaul that everyone’s been asking about.
In January 2025, OCR proposed the most significant rewrite of the HIPAA Security Rule since it was first written in 2003. If it goes through as written, it will eliminate the current “required vs. addressable” flexibility and make nearly everything mandatory, including:
- Encryption of ePHI, at rest and in transit
- Multi-factor authentication across systems that touch ePHI
- Network segmentation
- Annual technology asset inventories
- Vulnerability scanning at least every six months, plus penetration testing at least once every twelve months [5]
- A new, explicit patch management standard (proposed 45 CFR 164.308(a)(4)(i)) – 15 days to remediate critical vulnerabilities, 30 days for high-risk ones, once a patch exists [6]*
- 72-hour incident/data restoration capability
- Documented, recurring risk assessments
- Tighter oversight of business associates and vendors
*Note: For the patch management standard specifically, an end-of-life operating system (one that Microsoft has stopped issuing security patches for entirely – such as Server 2016 (expires 1/12/27), can never satisfy a 15-day remediation deadline, because there’s no patch coming, ever. If this proposal finalizes as written, running an unsupported OS would be a standing, unfixable gap against a specific, named standard for as long as that system stayed in use.
We’ve broken down each of these five in more depth (what each one means day-to-day) in Is Your Dental Practice Ready for the 2026 HIPAA Security Rule Overhaul? This piece focuses on the changes to the timeline since the previous article.
As of today, it is still a proposed rule. HHS has pushed the target date for finalizing it back multiple times (most recently to around July 2027 [1][3]) and a coalition of more than 100 hospital and provider groups has asked HHS to withdraw it. The proposed rule’s own text specifies the compliance mechanics: a 60-day gap between publication and the effective date, then a further 180-day compliance period after that [6] equating to 240 days. Applied to the current July 2027 target, that would make compliance closer to March 2028.
An Update to Our Own Coverage
When we covered this topic in May 2026, OCR’s own regulatory agenda listed May 2026 as the finalization target [2], it was an accurate reflection of the agenda at the time. Since then, that date slipped again, to around July 2027 [1][3]. We’re noting this because the target keeps moving, so anything you read – including from us – should be checked against the current date rather than treated as permanently settled.
Why You Might Be Hearing This is “Already Mandatory”
If you’ve received an email or update from a security vendor, compliance platform, or IT provider describing these controls as “100% required” or a “final deadline” coming in 2027, you’re not imagining it. The language is out there, and it’s understandable why. A rule this significant, with deadlines attached to its eventual finalization, creates genuine urgency to communicate, and “prepare now” is good advice regardless of the technical status.
But there’s a difference between “prepare now because this is coming” and “this is already the law.” July 2027 is HHS’s current target to issue a final rule, not a date by which practices must comply. The proposed rule’s own text lays out 60 days to an effective date plus a 180-day compliance period after that (240 days total), which is why March 2028 is a more realistic estimate for actual mandatory compliance, if the rule finalizes on its current timeline at all. HHS’s own website makes the same distinction we’re making here in that the official “Summary of the HIPAA Security Rule” explicitly describes itself as covering “the Security Rule that is currently in effect,” pointing readers elsewhere for the separate, still-proposed changes [7].
There’s also a second, separate reason you may be feeling pressure around these same controls, and this one has nothing to do with HIPAA’s regulatory timeline at all. Cyber liability insurance underwriting has tightened sharply industry wide. Independent of whether HIPAA’s proposed rule ever finalizes, most carriers now require documented, verifiable MFA across every account, encrypted and tested backups, and evidence of a completed risk analysis before they’ll issue or renew a policy for a medical or dental practice. Underwriters aren’t waiting on HHS; they’ve already made these controls a condition of coverage. (We touch on why cyber liability coverage matters for dental practices in our Network Security FAQs.)
For Multi-Location and DSO Practices, One Item Deserves Early Attention
Whatever happens to the finalization timeline, the proposed annual technology asset inventory requirement is something we recommend starting now if you operate more than one location. We’ve noted before that this is one of the most underestimated items in the whole proposal for a practice running multiple locations, using legacy equipment, or working with a patchwork of vendors across sites. Because building an accurate picture of where ePHI lives is a genuinely significant undertaking. Starting that inventory is useful regardless of the rule finalizing, and it’s the kind of project that gets harder to retrofit the more locations you add in the meantime.
What We’d Recommend Doing
Regardless of when – or whether – the Security Rule overhaul finalizes, these are what we recommend doing now, because they’re either already expected or clearly coming:
- Get a real risk analysis done
- Turn on multi-factor authentication everywhere it’s available. It’s one of the cheapest, highest-impact security moves a practice can make. Our MFA quick-reference guide walks through enabling it system by system.
- Confirm your data is encrypted, both sitting on your systems and moving between them.
- Start scheduling vulnerability scans and penetration tests on a roughly six-month and annual cadence, respectively.
- Check your Notice of Privacy Practices against the February 2026 SUD/Part 2 update if you haven’t already.
- Make sure your backup plan is tested. The proposed 72-hour restoration standard is a good stress test for whether your current backup and disaster strategy would hold up today.
Frequently Asked Questions
Is the 2026 HIPAA Security Rule update final yet?
No. As of September 2026, it remains a proposed rule. HHS has pushed the finalization target back multiple times, most recently to around July 2027, and a coalition of over 100 hospital and provider groups has asked HHS to withdraw it entirely.
Are MFA and encryption already mandatory under HIPAA?
Not yet, as specific mandates. The proposed rule would make both mandatory, removing the “addressable” flexibility that currently lets practices document an alternative approach. Under the current, still-active Security Rule, both are strongly expected as part of a reasonable risk analysis, but neither is a standalone mandatory line item until the proposed rule is finalized.
What does “delayed until 2027” mean for HIPAA compliance?
It means HHS’s current target for issuing a final rule is around July 2027, not a compliance deadline. The proposed rule specifies 60 days to an effective date plus a 180-day compliance period after that (240 days total), which points to around March 2028 for actual compliance if HHS hits its current target.
What HIPAA requirements are already mandatory?
A current, accurate risk analysis; patient right of access within 30 days; role-based access safeguards for anyone touching ePHI; and, as of February 16, 2026, an updated Notice of Privacy Practices addressing substance use disorder record disclosures. These apply under the existing Security and Privacy Rules.
Does the proposed HIPAA Security Rule apply to small dental practices?
Yes, HIPAA applies to all covered entities regardless of size, and the proposed overhaul would remove many of the flexibility provisions smaller practices have historically relied on to defer certain safeguards.
How doe this affect multi-location or DSO dental practices differently?
The proposed annual technology asset inventory requirement is significantly more involved across multiple locations, legacy equipment, or a mix of vendors. It’s worth starting that inventory now regardless of finalization status, since it only gets harder to build retroactively as a group adds locations.
What happened to the May 2026 finalization fate some sources mentioned?
That was OCR’s regulatory agenda target at the time, including in our own earlier coverage. It has since been pushed back again, to around July 2027. This is a reminder that this timeline has moved more than once and is worth reconfirming before treating any date as final.
Not Sure Where Your Practice Stands?
Want a real answer instead of a guess? Request a free Practice IT Analysis and we’ll help you identify where your gaps lie today.
Looking for dental-specific HIPAA compliance support directly? Our HIPAA compliance partners page has more on how we approach that.
Disclaimer: This article is for informational and educational purposes only and does not constitute legal advice. For guidance specific to your practice’s compliance obligations, consult a qualified HIPAA compliance professional or legal counsel.
Sources
- HIPAA Journal Editorial Staff. “HIPAA Security Rule Update Postponed.” HIPAA Journal, 2026, https://www.hipaajournal.com/hipaa-security-rule-update-postponed/. Accessed 7 Aug. 2026.
- Everett, Jennifer C., Burnette, Angela T., and Pike, Jennifer. “HIPAA Security Rule: Still on Track for Finalization.” Alston & Bird, 4 Nov. 2025, https://www.alston.com/en/insights/publications/2025/11/hipaa-security-rule-overhaul. Accessed 7 Aug. 2026.
- Butzel Long. “HHS-OCR (Again) Delays Issuance of Final HIPAA Privacy and Security Rules.” Butzel Long, 2026, https://www.butzel.com/alert-hhs-ocr-again-delays-issuance-of-final-hipaa-privacy-and-security-rules. Accessed 7 Aug. 2026.
- Texas Dental Association. “Important Update: New Federal HIPAA Privacy Rules Affect Dental Practices.” Texas Dental Association, 9 Jan. 2026, https://www.tda.org/home/2026/01/09/important-update--new-federal-hipaa-privacy-rules-affect-dental-practices. Accessed 7 Aug. 2026.
- U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information: Fact Sheet.” HHS.gov, 27 Dec. 2024, https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html. Accessed 4 Sept. 2026.
- U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information.” Federal Register, vol. 90, 6 Jan. 2025, pp. 898-1022, https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information. Accessed 4 Sept. 2026.
- U.S. Department of Health and Human Services, Office for Civil Rights. “Summary of the HIPAA Security Rule.” HHS.gov, content last reviewed 7 Aug. 2026, https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html. Accessed 4 Sept. 2026.
- U.S. Department of Health and Human Services, Office for Civil Rights. “June 2018 Cybersecurity Newsletter: Guidance on Software Vulnerabilities and Patching.” HHS.gov, June 2018, https://www.hhs.gov/sites/default/files/june-2018-newsletter-software-patches.pdf. Accessed 4 Sept. 2026.
Dental IT. Remove the Burden. Embrace the Use.
Quality patient care – it's ultimately why you became a dental professional. But, some business operations can get in the way (such as pesky computer issues or lack of IT support). That’s where Pact-One Solutions can help! Our passion lies in supplying reliable, responsive dental IT support and security that practices can count on.
Whether you’re looking for dental IT services for your startup or searching for more responsive dental IT support – our team of dental IT specialists have you covered. With team members throughout the United States, we offer nationwide support to dental practices of all sizes, specialties, and stages of growth. Our wide range of dental IT services ensure your data is secure, accessible, and protected.
Don't let technology challenges hinder your ability to deliver exceptional dental care. Contact us at info@pact-one.com or 866-722-8663 to join over 3,000 dental professionals thriving with the support of a dedicated dental IT team.


