HIPAA Security Rule: The 5 Controls Most Medical Practices Are Missing in 2026

• BizVuln Staff

Discover the 5 HIPAA Security Rule controls that medical practices overlook in 2026, including continuous risk analysis, IoT device management, and MFA. Expert compliance guide.

HIPAA Security Rule: The 5 Controls Most Medical Practices Are Missing in 2026

The stakes have never been higher. In 2025, healthcare data breaches cost the industry an average of $10.93 million per incident—the highest of any sector. The Office for Civil Rights (OCR) has signaled a sharp increase in enforcement actions, with penalties reaching $2 million per violation for willful neglect. Yet despite these risks, the vast majority of medical practices—from small clinics to multi-location groups—continue to operate with critical gaps in their HIPAA Security Rule compliance.

The problem is not a lack of intention. It’s a lack of awareness about which controls are truly being missed. Many practices believe that having a signed BA agreement, a basic risk assessment, and a password policy is enough. In 2026, with ransomware targeting healthcare every 11 seconds and telehealth platforms multiplying attack surfaces, those baseline measures are no longer sufficient.

This deep dive identifies the five Security Rule controls that most medical practices are missing—and offers a clear, actionable path to closing those gaps before the next OCR audit or ransomware attack.

---

Control #1: Continuous Risk Management (Not an Annual Checklist)

The Requirement

The HIPAA Security Rule (45 CFR § 164.308(a)(1)) requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). The word “continuous” does not appear in the regulation, but the expectation has evolved dramatically.

What Most Practices Are Doing

A 2025 survey by the American Medical Association found that 62% of small practices still treat risk analysis as a one-time compliance checkbox. They hire a consultant, produce a 50-page PDF, and file it away until the next OCR audit or certification requirement. The risk analysis is performed in a vacuum, often without integration into daily operations.

What They Are Missing

In 2026, threats evolve faster than annual cycles. Zero-day vulnerabilities, credential stuffing attacks, and supply chain compromises emerge weekly. A static risk assessment is obsolete the moment it is signed. The missing control is continuous risk management—a living process that includes:

How to Implement

---

Control #2: Complete Asset Inventory and Management (Including IoT and Telehealth)

The Requirement

Addressable implementation specifications under the Security Rule include “facility security plan” and “device and media controls” (45 CFR § 164.310). To protect ePHI, you must know where it lives. That means knowing every device, application, and service that stores, processes, or transmits ePHI.

What Most Practices Are Missing

Medical practices often maintain a list of workstations, servers, and practice management software. But they routinely overlook:

Why This Matters in 2026

The FDA has reported a 300% increase in vulnerabilities in connected medical devices since 2022. Ransomware groups now specifically target IoT devices because they are often unpatched and invisible to traditional asset inventories. If you don’t know a device exists, you cannot protect it.

How to Implement

---

Control #3: Multi-Factor Authentication (MFA) for All ePHI Access

The Requirement

The Security Rule’s “authentication” standard (45 CFR § 164.312(d)) requires procedures to verify that a person or entity seeking access to ePHI is the one claimed. While the rule does not explicitly mandate MFA, OCR guidance and enforcement actions since 2020 have made it clear that single-factor authentication (username + password) is insufficient for any system containing ePHI.

The Gap

Despite widespread awareness, many medical practices still do not enforce MFA universally. Common excuses include:

In 2026, these excuses are no longer acceptable. The OCR’s 2024 settlement with a New Jersey dental practice ($150,000 fine) explicitly cited lack of MFA as a contributing factor to a breach that exposed 10,000 patient records.

What Most Practices Are Missing

How to Implement

---

Control #4: Encryption at Rest and in Transit – Including Backups

The Requirement

The Security Rule’s “transmission security” (45 CFR § 164.312(e)(1)) and “integrity controls” (45 CFR § 164.312(c)(1)) address encryption. While encryption is addressable, OCR has repeatedly stated that it is “the most effective method” for protecting ePHI. In practice, failure to encrypt is almost always cited in enforcement actions when a breach occurs.

What Most Practices Are Missing

The 2026 Reality

Ransomware attackers now exfiltrate data before encrypting it. If your data is not encrypted at rest, the stolen records are immediately usable. Encrypted data, even if exfiltrated, is far less valuable to attackers and may not trigger a breach notification if the encryption is strong and the key is not compromised.

How to Implement

---

Control #5: A Living Incident Response Plan (With Tabletop Exercises)

The Requirement

The Security Rule mandates that covered entities have “policies and procedures addressing security incidents” (45 CFR § 164.308(a)(6)(i)) and a “process for responding to a security incident” (45 CFR § 164.308(a)(6)(ii)). This includes detection, containment, eradication, and recovery.

The Common Deficiency

Most medical practices have an incident response (IR) plan—often a 10-page document created by a consultant and stored in a binder. But when a real incident occurs, the plan is rarely followed. Staff don’t know who to call, how to isolate affected systems, or when to notify patients and OCR.

The Missing Control: Operational Readiness

What is missing is not the document—it is the culture and practice of incident response. In 2026, the average time to identify and contain a healthcare breach is 236 days. Practices that conduct regular tabletop exercises reduce that time by 54%.

What Most Practices Are Not Doing

How to Implement

---

Actionable Checklist for Closing the Gaps

Use this checklist to assess your practice’s current posture against the five missing controls. Each item should be completed within 90 days.

Continuous Risk Management

Asset Inventory and Management

Multi-Factor Authentication

Encryption at Rest and in Transit

Incident Response Readiness

---

Frequently Asked Questions (FAQ)

1. Does HIPAA actually require MFA for all ePHI access?

While the Security Rule does not explicitly name “multi-factor authentication,” OCR guidance and enforcement actions since 2020 have consistently treated single-factor authentication as inadequate. In the 2024 OCR settlement with a New Jersey dental practice, the lack of MFA was cited as a direct cause of the breach. To be compliant in 2026, you should assume MFA is required for any system that can access ePHI.

2. Our practice is small—only three doctors and a receptionist. Do we really need continuous risk monitoring?

Yes. Small practices are the most targeted by ransomware because they often have weaker defenses. A single successful phishing attack can encrypt your entire EHR and force you to pay a ransom or shut down for weeks. Continuous monitoring tools are now affordable (many start under $100/month) and can be managed by a virtual CISO or managed security service provider.

3. What if our EHR vendor doesn’t support MFA?

This is a red flag. If your EHR vendor does not offer MFA, you should either (a) implement a third-party identity provider (e.g., Azure AD, Okta) in front of the EHR, or (b) begin planning a migration to a HIPAA-compliant EHR that supports modern authentication. In the meantime, document the risk and implement compensating controls such as IP whitelisting and session timeouts.

4. How often should we update our risk analysis?

The Security Rule does not specify a frequency, but OCR expects a “continuous” process. At minimum, conduct a formal reassessment annually and whenever there is a significant change (e.g., new EHR, new telehealth platform, merger, or after a security incident). Automated scanning should occur monthly.

5. We have cyber insurance. Doesn’t that cover us if we get breached?

Cyber insurance is a financial safety net, not a compliance control. Insurers now require proof of MFA, encryption, and incident response plans before issuing policies. Furthermore, a breach can still result in OCR fines, lawsuits, and reputational damage that insurance may not fully cover. Compliance is the first line of defense.

6. Is encryption required for data at rest on internal servers?

Yes, if you want to avoid a breach notification. Under the HIPAA Breach Notification Rule, if encrypted data is stolen and the encryption key is not compromised, the breach is presumed not to have occurred. Without encryption, any unauthorized access to a server is a reportable breach. Encryption at rest is the single most effective way to reduce breach risk.

7. Our practice uses a managed IT provider. Are they responsible for these controls?

Your managed IT provider (MSP) can help implement technical controls, but the final responsibility for HIPAA compliance rests with your practice as the covered entity. You must ensure that your MSP has signed a Business Associate Agreement and that they are following the same security standards. Many MSPs claim HIPAA compliance but lack continuous monitoring or incident response testing. Audit your MSP annually.

---

Conclusion: Closing the Gaps Before the Next Breach

The five controls outlined above are not theoretical. They are the concrete, actionable measures that separate compliant, resilient medical practices from those that become the next OCR case study or ransomware headline. In 2026