HIPAA Security Rule Changes: What Medical and Dental Practices Need to Know
For most of its life, the HIPAA Security Rule was deliberately flexible. It told practices to protect electronic health information but left many of the specifics to your judgment, distinguishing between "required" and "addressable" safeguards. That flexibility is ending. The Security Rule is being updated to be stronger and far more prescriptive, and the direction is clear: the controls that used to be optional are becoming mandatory. If you run a medical or dental practice, now is the time to get ahead of it.
What's changing in direction
You don't need to memorize regulatory language to understand where this is headed. The update moves away from vague, addressable safeguards toward specific, verifiable requirements. In practice, that means several controls the security community has recommended for years are becoming expectations you'll be measured against:
- Encryption — encryption of protected health information, both at rest and in transit, is moving from "addressable" to effectively expected. Laptops, servers, backups, and email carrying patient data all fall in scope.
- Multi-factor authentication — MFA on systems that access patient records is becoming a baseline requirement rather than a suggestion.
- Regular risk analysis — a documented, genuine risk assessment of where patient data lives and how it could be exposed, done on a real schedule, not a one-time checkbox.
- Documentation — written policies, evidence that safeguards are actually in place, asset inventories, and records of testing. If you can't show it, regulators treat it as not done.
- Incident response and recovery — a tested plan for detecting, containing, and recovering from a breach, including backups you've proven you can restore.
Why practices are exposed
Healthcare is one of the most targeted industries for ransomware and data theft, because patient records are valuable and many practices run lean on IT. A dental office or small clinic often has the same obligations as a hospital but a fraction of the resources, and the gap tends to show up in the same places: unencrypted laptops, shared logins without MFA, backups nobody has tested, and a risk analysis that was either never done or done once and filed away. Those are exactly the areas the updated rule targets.
What to do now to prepare
The worst time to start is after a breach or an audit letter. A sensible, practical path looks like this:
- Run a real risk analysis. Map where protected health information is created, stored, and sent — including cloud apps, imaging systems, and email — and identify where it's exposed.
- Turn on encryption everywhere it belongs. Full-disk encryption on every device, encrypted backups, and secure email for anything containing patient data.
- Deploy MFA on every system that touches patient records. Practice management software, email, remote access, and cloud services.
- Fix and test your backups. Keep them immutable or offline, and prove you can restore from them.
- Write it down. Policies, procedures, training records, and evidence — documentation is a core part of compliance, not an afterthought.
- Train your staff. Most breaches start with a click; ongoing awareness training is both good security and a compliance expectation.
You don't have to figure this out alone
Compliance and security overlap heavily, and the good news is that doing the security work properly gets you most of the way to compliance. Our cybersecurity services are built for exactly this — encryption, MFA, tested backups, risk analysis, and the documentation to back it all up — so your practice can meet the updated Security Rule with confidence rather than scrambling later.
Equal Tech Solutions supports medical and dental practices across Chattanooga, Cleveland, and the Southeast US with HIPAA-focused IT and cybersecurity. If you want a clear-eyed assessment of where your practice stands against the changes, contact Equal Tech Solutions and we'll help you build a plan.

