← All insights

Compliance and professional-office resource

HIPAA Security Rule in 2026: What Central Florida Medical Offices Should Document Now

The current HIPAA Security Rule remains in effect while a proposed update is pending; medical offices should strengthen evidence without treating a proposal as final law.

U.S. medical-practice administrator reviewing HIPAA security documentation with a clinician

Separate the current rule from the proposal

The U.S. Department of Health and Human Services states that the HIPAA Security Rule currently in effect establishes administrative, physical, and technical safeguards for electronic protected health information. HHS also maintains a proposed rule issued in late 2024 that would strengthen cybersecurity requirements. As of HHS’s August 2026 summary, the proposal should not be described as the final rule currently governing regulated entities.

That distinction matters. A Central Florida medical practice should comply with current requirements, monitor official HHS updates, and improve reasonable safeguards without representing proposed provisions as binding law.

Confirm the security official and governance record

HHS says a regulated entity must designate a security official responsible for required policies and procedures. Record the person’s role, authority, reporting path, and backup contact. Security may be supported by an IT provider, but the practice still needs internal ownership of risk decisions.

Maintain a decision record for risk acceptance, corrective actions, vendor changes, significant incidents, and policy exceptions. Avoid relying solely on informal conversations with a technology vendor.

Keep the risk analysis current

Identify where ePHI is created, received, maintained, or transmitted. Include electronic health record systems, imaging, email, patient portals, billing, cloud storage, remote access, mobile devices, connected clinical equipment, backups, and business associates.

Assess threats, vulnerabilities, existing safeguards, likelihood, and potential impact. Revisit the analysis after major system, facility, vendor, or workflow changes. HHS and the Office of the National Coordinator provide a Security Risk Assessment Tool intended to assist small and medium-sized healthcare practices; using a tool does not itself guarantee compliance.

Turn safeguards into evidence

For each important control, retain evidence that a reviewer can understand:

  • Access lists and periodic access-review results.
  • Multifactor-authentication and administrator-account settings.
  • Workforce onboarding and termination records.
  • Security-awareness and incident-reporting training.
  • Patch, endpoint protection, logging, and alert-handling records.
  • Backup configuration and restoration-test results.
  • Facility and device controls.
  • Incident-response exercises and corrective actions.
  • Business-associate agreements and vendor security reviews.

Evidence should be accurate, dated, protected, and connected to an accountable owner. A screenshot without context or an undated policy copied from a template may not demonstrate operation.

Review business associates

HHS’s current summary addresses obligations involving business associates and subcontractors that handle ePHI. Inventory those relationships and confirm that written agreements and actual data flows match. Review remote-support access, cloud applications, billing services, transcription, managed IT, backup providers, and disposal vendors.

Ask how access is approved and removed, how incidents are reported, which subcontractors are involved, how data is returned or destroyed, and what evidence the practice can obtain. Contract language should be reviewed by qualified counsel.

Prepare for Florida operations

Storms and office closures can change where staff work and which devices they use. Document secure remote access, downtime procedures, alternate communications, backup power dependencies, emergency contacts, and restoration priorities. Test access to essential patient and scheduling information without weakening authentication or privacy safeguards.

Observe documentation retention

HHS states that required policies, procedures, and documentation of required actions, activities, or assessments must generally be retained for six years after the later of creation or last effective date. Confirm the applicable requirement with qualified compliance or legal advisers and make sure the retention location remains accessible after personnel or vendor changes.

Monitor the proposal responsibly

Assign someone to monitor HHS and Federal Register updates. Keep a list of proposed changes that may require budget, technology, workflow, or contract decisions, but label that list as planning—not current-law compliance. Avoid purchasing a product solely because a sales claim says the proposed rule already mandates it.

A useful management review

Quarterly, review the risk register, access changes, incidents and near misses, restoration evidence, vendor changes, overdue corrective actions, and official regulatory updates. Record decisions and dates.

The strongest compliance program is not a binder assembled before an audit. It is a repeatable process that shows how the practice identifies risk, selects safeguards, verifies operation, corrects gaps, and updates documentation as conditions change.

Human-reviewed draft. This article is general educational information and not legal, regulatory, privacy, or compliance advice.

Sources