HIPAA Security Rule Changes Are Coming: What Dental Practices Should Start Preparing For Now

HIPAA Security Rule Changes Are Coming: What Dental Practices Should Start Preparing For Now | Darkhorse Tech
HIPAA & Compliance

HIPAA Security Rule changes are coming: what dental practices should start preparing for now

A proposed update to the HIPAA Security Rule — the biggest in more than a decade — is expected to become final around May 2026. Here's what's changing and why dental practices shouldn't wait for the final rule to start preparing.

8 MIN READ HIPAA & COMPLIANCE DENTAL IT
TL;DR

A proposed modification to the HIPAA Security Rule, released December 27, 2024, is expected to become final around May 2026 with a 240-day compliance window after that. It would remove the "required vs. addressable" distinction, making most safeguards mandatory rather than optional and documented. For dental practices, that means a technology asset inventory and network map, annual risk analysis, mandatory MFA, encryption of ePHI in transit and at rest, recurring vulnerability scans and annual penetration testing, a 72-hour restoration expectation after an incident, one-hour access termination after an employee leaves, and much closer scrutiny of vendors and business associates. The details may still shift before finalization, but the direction is clear enough that practices should start preparing now.

The HIPAA Security Rule may be getting its biggest update in more than a decade — and dental practices should be paying attention.

A proposed modification to the HIPAA Security Rule was released on December 27, 2024, and according to RubinBrown, it includes some of the most sweeping proposed updates since 2013. The rule is expected to become final around May 2026, with a proposed 240-day compliance window after finalization.

That may sound like plenty of time. It is not.

If your dental practice relies on cloud systems, remote access, digital imaging, practice management software, email, online forms, or third-party vendors, these changes could significantly raise the bar for how you secure electronic protected health information (ePHI).

And here's the biggest takeaway: HIPAA cybersecurity requirements are moving from “flexible and documented” toward “mandatory and provable.” That is a major shift for healthcare organizations — including dental practices and DSOs.

Expected final rule May 2026 With a proposed 240-day compliance window after finalization

01Why is HIPAA changing now?

Direct answer Healthcare continues to be one of the most targeted industries for cyberattacks, and dental practices are no exception. One of the largest proposed changes is the removal of the distinction between “required” and “addressable” safeguards, meaning many controls that were previously flexible may soon become mandatory.

Cybercriminals know dental offices rely on uninterrupted access to:

  • Patient records
  • Digital imaging
  • Scheduling systems
  • Insurance and billing platforms
  • Clinical software
  • Cloud applications

When those systems go down, production stops quickly.

In plain English: today, some HIPAA safeguards allow practices to decide whether a control is “reasonable and appropriate” and document why they implemented — or skipped — it. Under the proposed changes, many of those controls would simply be expected. That means dental practices need to start thinking less like “Do we have a reason not to do this?” and more like “Can we prove this is already in place?”

AreaToday's ruleProposed rule
Safeguard statusMany controls are "addressable" — flexible, with documented rationaleDistinction removed — most controls simply expected
MFARecommended in many casesMandatory for systems with ePHI, limited exceptions
EncryptionAddressable, often skipped with documentationRequired in transit and at rest, limited exceptions
TestingNot explicitly mandatedVulnerability scans every 6 months, annual penetration testing
Incident recoveryNo fixed restoration timeline72-hour restoration expectation
Access terminationNo fixed timeframeProposed one-hour termination after separation

02Required technology asset inventory and network mapping

Direct answer One major proposed requirement is maintaining and annually updating a complete technology asset inventory and network map showing systems and ePHI data flows. You cannot secure what you cannot see.
Illustration of a dental practice technology asset inventory and network map showing connected systems, devices, cloud platforms, and ePHI data flow.

For dental practices, this could include:

  • Servers
  • Workstations
  • Imaging computers
  • Firewalls
  • Wireless access points
  • Practice management software
  • Imaging systems
  • Cloud platforms
  • Backup systems
  • Email systems
  • Remote access tools
  • Third-party integrations

If your practice does not have a current inventory of every device and system touching patient data, now is the time to fix that.

03Annual risk analysis and risk management plans

Direct answer HIPAA has long required risk analysis, but the proposed changes push for more detailed, recurring, and documented assessments tied directly to your asset inventory and network map. The key word is documented — if it isn't written down, it's very difficult to prove compliance during an audit or investigation.

A proper dental IT risk analysis should answer questions like:

  • Where does ePHI live?
  • Who has access to it?
  • How is access controlled?
  • Which systems are mission-critical?
  • What vulnerabilities exist?
  • What happens during downtime?
  • How are backups protected?
  • Which vendors can access patient data?
  • What gaps still need remediation?

04Mandatory multi-factor authentication (MFA)

Direct answer The proposed rule includes MFA requirements for systems containing ePHI, with limited exceptions. Passwords alone are no longer enough.
Cybersecurity illustration showing multi-factor authentication, encryption, and secure patient data protection for a dental practice.

For dental practices, MFA should already be standard for:

  • Email accounts
  • Remote access tools
  • Cloud applications
  • Admin accounts
  • Backup portals
  • Vendor access
  • Firewall management

If your office still relies on shared logins, weak passwords, or remote access without MFA, those are high-risk gaps that need attention now.

05Encryption requirements for ePHI

Direct answer RubinBrown notes the proposed rule would require encryption of ePHI both in transit and at rest, with limited documented exceptions. Encryption dramatically reduces the damage if a device is lost, stolen, or compromised.

For dental practices, this could affect:

  • Email transmission
  • Cloud storage
  • Backup systems
  • Laptops
  • Servers
  • External drives
  • Imaging data
  • Remote access systems

A stolen laptop is bad. A stolen laptop full of unencrypted patient data is the kind of bad that involves attorneys, regulators, breach notifications, and several sleepless nights.

06Vulnerability scanning and penetration testing

Direct answer The proposed rule includes vulnerability scans at least every six months and annual penetration testing — a significant operational shift for many smaller healthcare organizations.

Dental practices should expect formal testing of:

  • Firewalls
  • Remote access systems
  • Servers
  • Workstations
  • Cloud services
  • Misconfigurations
  • Unsupported software
  • Weak authentication
  • Unpatched vulnerabilities

This is not just about checking a compliance box. Vulnerability management is one of the most effective ways to identify security problems before attackers do — which is generally preferable, since attackers are notoriously bad at submitting polite support tickets.

07Incident response and 72-hour restoration expectations

Direct answer RubinBrown highlights a proposed requirement for documented incident response plans and restoration of affected systems and ePHI within 72 hours. That raises the importance of backup and disaster recovery planning dramatically.

Practices should be asking:

  • Do we have current backups?
  • Are backups isolated from ransomware?
  • Are backups encrypted?
  • Have we tested restoration recently?
  • How long would it take to restore Open Dental and imaging systems?
  • Who handles vendors during an outage?
  • Who communicates with staff?
  • Who handles legal and compliance notifications?

Having backups is good. Having tested backups is better. Having a written recovery process your team actually understands is where the real protection happens.

08Faster employee access termination

Direct answer The proposed rule includes workforce access requirements, including termination of access within a specific timeframe after employee separation. RubinBrown's comparison notes a proposed one-hour access termination expectation.

When someone leaves, access should immediately be removed from:

  • Email
  • Practice management systems
  • Imaging software
  • Remote access tools
  • Cloud storage
  • Password managers
  • Vendor portals
  • Shared accounts
  • Phone systems
  • Billing platforms

This becomes even more important with remote workers, consultants, temporary staff, and vendors.

09Increased vendor and business associate oversight

Direct answer The proposed updates create stronger expectations around business associates and subcontractors, including annual verification of safeguards and contingency planning requirements. Your practice's security is only as strong as the weakest company with access to your patient data.

Dental practices should expect increased focus on vendor documentation, including:

  • Business Associate Agreements (BAAs)
  • Security questionnaires
  • Written verification of safeguards
  • Backup and recovery expectations
  • Incident response responsibilities
  • Access controls
  • Data handling practices

Even if your internal systems are secure, your vendors can still create serious cybersecurity risk.

10What should dental practices do now?

These rules are not final yet, and details may still change — RubinBrown notes that provisions could be delayed or modified by the Department of Health and Human Services before finalization. But the direction is very clear: healthcare cybersecurity expectations are increasing, and dental practices should not wait for the final rule before preparing.

Illustration of dental practice backup, disaster recovery, and incident response systems supporting HIPAA cybersecurity readiness.
  1. 1
    Build or update your technology inventoryThis becomes the foundation for everything else. Start documenting:
    • Every workstation
    • Every server
    • Every firewall
    • Every wireless access point
    • Every cloud platform
    • Every backup system
    • Every vendor with access
    • Every system touching ePHI
  2. 2
    Review MFA coverageIdentify where MFA is enabled — and where it is missing. Prioritize:
    • Email
    • Remote access
    • Admin accounts
    • Cloud systems
    • Backup platforms
    • Vendor portals
    If MFA is not enabled everywhere it reasonably can be, start closing those gaps now.
  3. 3
    Confirm backup and recovery readinessAsk your IT provider: are backups monitored, encrypted, and protected from ransomware? Have they been tested recently? How quickly can you restore systems, and which systems recover first? The proposed 72-hour restoration expectation means “we think backups exist somewhere” is no longer a recovery strategy.
  4. 4
    Schedule vulnerability scanningIf your practice is not already performing recurring vulnerability scans, now is the time to begin. At minimum, you should understand which systems are externally exposed, which patches are missing, which devices are unsupported, which configurations are risky, and which remediation projects are needed.
  5. 5
    Tighten employee onboarding and offboardingDocument exactly how access is granted, changed, and removed. Your process should include:
    • New hire approvals
    • Role-based permissions
    • MFA setup
    • Password policies
    • Termination checklists
    • Vendor access removal
    • Shared account elimination
    This is not glamorous work. But neither is explaining to OCR why a former employee still had access six months later.
  6. 6
    Review vendor documentationCreate a list of every vendor touching patient data, then confirm: do you have a signed BAA? Do they use MFA and encrypt data? Do they have incident response procedures and backup and recovery plans? Can they provide written security documentation? Vendor risk management is becoming much harder to ignore.

Not sure where your practice stands?

Darkhorse Tech can help evaluate your current IT and cybersecurity posture, identify security gaps, and build a roadmap toward stronger HIPAA readiness — before the final rule forces the conversation.

The bottom line

The proposed HIPAA Security Rule changes are a warning shot for healthcare organizations — including dental practices and DSOs. The future of HIPAA compliance is likely to be more technical, more documented, more prescriptive, more cybersecurity-focused, and more demanding of vendors and business associates.

For dental practices, the smartest move is to start preparing now — not in panic mode, and not in "buy every shiny cybersecurity product" mode, but in a practical, methodical way: know what you have, protect what matters, document what you do, and test whether it works. That is the playbook. Because when HIPAA expectations rise, your technology foundation needs to rise with them.

Darkhorse Tech is here for you.

Your dental technology should support your practice, not slow it down. Darkhorse Tech helps dental offices stay secure, connected, and productive with IT support built specifically for dentistry.

Schedule a Consultation Today

Back to Education

Looking to get dental IT support for the first time?

You’re in the right place.

Don’t hesitate to drop us a line, we look forward to connecting with you soon.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Want To Chat?

You can schedule an intro meeting online! Find a time on our calendar that works for you.

schedule today!