A four-physician practice we spoke with last week has a firewall, an EHR in the cloud, and a shared password for the front-desk workstation that has not changed since 2021. The practice is not unusual. It is the kind of practice the proposed HIPAA Security Rule is written for.

On January 6, 2025, the HHS Office for Civil Rights (OCR) published a notice of proposed rulemaking in the Federal Register that would rewrite the Security Rule for the first time since 2013. Comments are due March 7, 2025. Nothing is final. The incoming administration takes office next week and may change course, and the health care industry will argue hard about cost. But the proposal tells you what OCR thinks the baseline should be, and most of it is what a competent IT vendor would recommend anyway.

We read the proposal from the point of view of a practice manager who has a billing office, an EHR, three vendors and no security staff. What follows is what it would require, what would change day to day, and what we think is worth doing before anyone tells you to.

Key takeaways

  • The proposal removes the "addressable" category. Multifactor authentication, encryption at rest and in transit, and a written asset inventory would all be required, with narrow exceptions.
  • Specific intervals appear for the first time: vulnerability scans at least every six months, penetration tests at least annually, critical systems restored within 72 hours.
  • Business associates would have to verify their safeguards to you in writing every year. Your vendor list is the starting point.
  • If finalized as proposed, a practice would have about 180 days after the rule's effective date to comply, so the work should start now.
  • OCR already asks for most of these controls after a breach under the current rule. The proposal changes the wording, not the expectation.

What OCR is proposing

The current Security Rule divides its implementation specifications into "required" and "addressable". Practices have treated "addressable" as optional for twenty years, and OCR's breach investigations say so. The proposal removes that distinction: with limited exceptions, everything becomes required, and where an exception applies the practice has to document why. The items that matter most for a physician practice are in the table.

ControlTodayAs proposed
Multifactor authenticationNot named; passwords alone are commonRequired for access to systems holding electronic protected health information, with limited exceptions
EncryptionAddressableRequired at rest and in transit, with limited exceptions
Technology asset inventory and network mapImplied by the risk analysisWritten, showing where ePHI moves, reviewed at least once a year and after any major change
Vulnerability scanning and penetration testingNot specifiedScans at least every six months; penetration test at least every twelve months
PatchingNot specifiedCritical vulnerabilities patched within 15 days of identification, high-severity within 30, with documented exceptions
Backup and restorationContingency plan required, no time targetCritical systems and data restored within 72 hours; backups tested
Network segmentationNot specifiedRequired, so a compromised device or guest network cannot reach clinical or billing systems
Compliance auditPeriodic evaluationDocumented audit against the Security Rule at least every twelve months
Business associatesSigned agreementWritten verification of safeguards from each business associate at least every twelve months, and 24-hour notice if the associate activates its contingency plan
Workforce accessTermination proceduresAccess removed within one hour of a departure, and other affected regulated entities notified within 24 hours

The proposal also spells out expectations that were implied before: anti-malware on every device, removing software that is not needed, disabling unused network ports, and a risk analysis with a defined content list rather than the one-page checklist many practices file and forget. The risk analysis would have to be based on the asset inventory, which is the reason the inventory comes first.

Who this affects

Every covered entity and every business associate. That includes the practice, its billing company, its clearinghouse, its EHR vendor, the IT firm that manages the workstations, and the transcription service. The proposed rule would also require the practice to obtain written assurance from each of them, every year, that the safeguards are in place. If you do not currently have a list of your business associates with a signed agreement for each, start there. An asset inventory that omits the vendors who hold your data is not an inventory.

Small practices are not exempt. The current rule's "flexibility of approach" language, which lets a practice consider its size and resources, survives in the proposal, but the specific controls above are proposed as requirements for everyone. In our reading, the flexibility would apply to how a practice implements MFA or segmentation, not to whether it does.

What this changes in a practice's workflow

We think most practices should treat the proposal as a to-do list now rather than wait for a final rule, for a simple reason: OCR already expects most of these controls under the existing rule's risk analysis requirement, and breach investigations already ask for them. The proposal makes the expectation explicit. The work breaks into three groups, and most of it is configuration and paperwork rather than purchases.

GroupWhat to doWho usually does it
AccessTurn on MFA for the EHR, practice management system, email, remote access and the clearinghouse portal. Remove shared logins. Remove access the same day someone leaves.Practice manager with the IT vendor
DataConfirm encryption on laptops, workstations, phones and backups. Confirm the EHR and billing vendors encrypt in transit and at rest and get it in writing.IT vendor; vendor contracts
DocumentationWrite the asset inventory and network map. Update the risk analysis. Collect business associate agreements and security attestations. Test a restore from backup and record the result and the time it took.Practice manager, with counsel if needed

A worked example of the third group. A three-location practice with 22 workstations, four servers or cloud services, 30 user accounts, and six vendors that touch patient data can complete a first inventory in about two working days: one to list the devices and accounts with the IT vendor, one to list the vendors, what data each holds, and whether a signed agreement is on file. The restore test is an afternoon: pick one system, restore it to a test location, time it, and write the result down. If the restore takes four days, you have learned the most important thing in this article before a ransomware group teaches it to you.

Timeline, cost and the comment period

The proposal says a final rule would take effect 60 days after publication and that regulated entities would have to comply 180 days after that, with a further year to update business associate agreements. Whether a final rule comes at all, and in this form, is not known. Plan for the controls, not the date.

Small practices have argued, correctly, that some of this costs money, and HHS's own estimate puts first-year costs for the industry in the billions. MFA and encryption are mostly configuration and are often already included in the software you pay for. Penetration testing, segmentation and a proper network map usually mean a fee to an IT firm. If your practice has a view on the burden, the comment period is the moment to say so, and the specialty societies are collecting input. Comments are due March 7, 2025. We think the intervals (six-month scans, annual tests, 72-hour restores) are the pieces most likely to move in a final rule, and the MFA and encryption requirements are the least likely to.

Where the billing office fits

Billing systems hold everything a criminal wants: names, dates of birth, member IDs, diagnosis codes and, often, card numbers. In our experience the billing office is the least protected part of a practice because it is the least clinical. Nobody audits who can log in to the clearinghouse portal. Remittance files sit in a shared folder for years. The biller who left in August still has a working login in January.

Three questions to ask your billing team or vendor this month: Does every user have a unique login with MFA? Are remittance files and patient statements stored encrypted? When a biller leaves, how long until their access is removed? The answers should be yes, yes and the same day. If the billing is outsourced, ask the vendor for its most recent risk analysis date and its written security attestation, because under the proposal you will need both on file. Revelrex operates as HIPAA compliant and SOC 2 compliant, and we expect the same of the clearinghouses and tools we connect to.

Questions we hear

Is this final?

No. It is a proposed rule published January 6, 2025, with comments due March 7, 2025. A final rule, if one comes, would be published later with its own compliance date, proposed at 180 days after the effective date. The controls it describes are already good practice and already what OCR asks about after a breach.

We are a small practice. Does the rule scale down for us?

The current rule allows flexibility based on size and resources, and the proposal keeps some of that language. But the specific items above (MFA, encryption, inventory, backups, scans) are proposed as requirements for everyone. Do not count on a small-practice exemption. Count on being able to meet the requirements with the tools you already pay for plus some hours from your IT vendor.

What should we do first?

Turn on MFA everywhere it is available, then write down what systems you have and who has access to them. Those two steps take a week and cover the most common findings in OCR investigations. Talk to counsel about the risk analysis and business associate agreements if you have not updated them in the last two years. Our training courses include a practice security module built for office managers, and you can book a call to talk through your setup.

What to do this month

  1. Turn on multifactor authentication for the EHR, practice management system, email, remote access and every payer or clearinghouse portal, and remove shared logins.
  2. List every device, account and cloud service that touches patient data, and every vendor that holds it, with the date of its signed business associate agreement.
  3. Ask each vendor, in writing, whether it encrypts your data at rest and in transit, and file the answer.
  4. Run one restore from backup, time it, and record the result.
  5. Check that the departed-staff list from 2024 matches the active user list in every system.
  6. Decide whether the practice or its specialty society will comment by March 7, 2025, and if so, note the cost items that would hit a practice your size.