Most dental practices believe they're HIPAA compliant.
But with the new HIPAA Security Rule updates expected in 2026, that assumption is about to be tested. These changes represent the most significant update to HIPAA in over a decade, and they shift compliance from a checklist to something much more demanding: proven, measurable cybersecurity.
“Do you have policies in place?”
“Can you prove your systems are secure?”
01Why is HIPAA changing, and why does it matter to dental practices?
Healthcare — including dental practices — has become one of the most targeted industries for:
- Ransomware
- Phishing attacks
- Data breaches
In response, regulators are aligning HIPAA with modern cybersecurity standards, not outdated assumptions.
02What's changing in the new HIPAA Security Rule?
Let's break this down into what actually matters for a dental practice.
- 1“Addressable” safeguards are going awaySecurity measures are no longer optional. The current rule allows flexibility (“addressable” controls); the new rule removes that — if it's required, you must implement it, and documentation alone won't protect you.
- 2Encryption will be mandatoryAll ePHI must be encrypted, both at rest and in transit. For dental practices, this affects email systems, servers, backups, and imaging systems. If your systems aren't encrypted today, you are already behind.
- 3Multi-factor authentication (MFA) will be requiredAccessing patient data will require more than just a password — additional verification is required. This impacts front desk systems, remote logins, and cloud platforms.
- 4Annual risk assessments and auditsThe new rule requires formal annual security audits and ongoing risk analysis and documentation — a major shift from “set it and forget it” to continuous compliance.
- 5Required testing, not just policiesPractices will need vulnerability scans every 6 months and annual penetration testing. You must actively test your security, not just claim it exists.
- 6Asset inventory and network mappingYou'll need to document every system that touches patient data and how data flows through your network. If you can't answer “where is our patient data stored and accessed,” you're already at risk.
- 7Faster incident reportingIf something goes wrong, business associates must report incidents within 24 hours — that includes IT vendors, software providers, and third-party systems.
03What does this mean for dental practices?
Common gaps include:
- No centralized Dental IT strategy
- Outdated systems without encryption
- Weak or no MFA
- No documented risk assessments
- Limited visibility into network activity
04Why is HIPAA shifting from compliance to cybersecurity?
05Why are dental practices especially at risk?
Dental practices often:
- Operate with limited IT resources
- Use multiple disconnected systems
- Rely on reactive IT support
- Store highly sensitive patient data
06How does dental IT impact your readiness?
This is where everything ties together. Your ability to meet the new HIPAA requirements depends on your:
- Dental IT infrastructure
- Dental IT solutions
- Dental IT services
- Overall Dental Information Technology strategy
Without a structured approach, compliance becomes nearly impossible.
07What should dental practices do now?
You don't need to wait for the final rule. In fact, you shouldn't.
- 1Conduct a HIPAA risk assessmentIdentify current gaps, security weaknesses, and compliance exposure.
- 2Upgrade your security stackFocus on encryption, MFA, firewalls, and endpoint protection.
- 3Move to proactive dental IT servicesReactive IT will not meet new requirements. You need monitoring, ongoing maintenance, and continuous risk management.
- 4Standardize your Dental Information TechnologyEnsure systems are consistent, security is enforced across all devices, and data is properly controlled.
Darkhorse Tech is here for you
Your dental technology should support your practice, not slow it down. Darkhorse Tech helps dental offices stay secure, connected, and productive with IT support built specifically for dentistry.
The bottom line
The new HIPAA Security Rule isn't just an update. It's a fundamental shift in how compliance is defined.
- Increased risk
- Higher costs
- Greater exposure to fines and breaches
- Strengthen security
- Reduce downtime
- Stay ahead of compliance requirements
Final thought: under the new HIPAA Security Rule, compliance will have to be proven — not assumed.

