HIPAA Security Rule: The 5 Controls Most Medical Practices Are Missing in 2026
• BizVuln Staff
Discover the 5 HIPAA Security Rule controls that medical practices overlook in 2026, including continuous risk analysis, IoT device management, and MFA. Expert compliance guide.
HIPAA Security Rule: The 5 Controls Most Medical Practices Are Missing in 2026
The stakes have never been higher. In 2025, healthcare data breaches cost the industry an average of $10.93 million per incident—the highest of any sector. The Office for Civil Rights (OCR) has signaled a sharp increase in enforcement actions, with penalties reaching $2 million per violation for willful neglect. Yet despite these risks, the vast majority of medical practices—from small clinics to multi-location groups—continue to operate with critical gaps in their HIPAA Security Rule compliance.
The problem is not a lack of intention. It’s a lack of awareness about which controls are truly being missed. Many practices believe that having a signed BA agreement, a basic risk assessment, and a password policy is enough. In 2026, with ransomware targeting healthcare every 11 seconds and telehealth platforms multiplying attack surfaces, those baseline measures are no longer sufficient.
This deep dive identifies the five Security Rule controls that most medical practices are missing—and offers a clear, actionable path to closing those gaps before the next OCR audit or ransomware attack.
---
Control #1: Continuous Risk Management (Not an Annual Checklist)
The Requirement
The HIPAA Security Rule (45 CFR § 164.308(a)(1)) requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). The word “continuous” does not appear in the regulation, but the expectation has evolved dramatically.
What Most Practices Are Doing
A 2025 survey by the American Medical Association found that 62% of small practices still treat risk analysis as a one-time compliance checkbox. They hire a consultant, produce a 50-page PDF, and file it away until the next OCR audit or certification requirement. The risk analysis is performed in a vacuum, often without integration into daily operations.
What They Are Missing
In 2026, threats evolve faster than annual cycles. Zero-day vulnerabilities, credential stuffing attacks, and supply chain compromises emerge weekly. A static risk assessment is obsolete the moment it is signed. The missing control is continuous risk management—a living process that includes:
- **Automated vulnerability scanning** of all network-connected devices, including IoT medical devices.
- **Threat intelligence feeds** tailored to healthcare (e.g., Health-ISAC alerts).
- **Quarterly risk score updates** tied to asset inventory changes.
- **Integration with incident response** so that every security event triggers a risk reassessment.
How to Implement
- Deploy a continuous monitoring platform (e.g., Qualys, Tenable, or a managed detection and response service).
- Schedule monthly automated scans and quarterly manual reviews.
- Assign a risk owner (not just the IT vendor) who reports to the Privacy Officer.
- Document risk acceptance decisions with clear justification and timelines for remediation.
---
Control #2: Complete Asset Inventory and Management (Including IoT and Telehealth)
The Requirement
Addressable implementation specifications under the Security Rule include “facility security plan” and “device and media controls” (45 CFR § 164.310). To protect ePHI, you must know where it lives. That means knowing every device, application, and service that stores, processes, or transmits ePHI.
What Most Practices Are Missing
Medical practices often maintain a list of workstations, servers, and practice management software. But they routinely overlook:
- **Internet-connected medical devices** (blood pressure cuffs, infusion pumps, glucometers) that transmit data to EHRs.
- **Personal devices used by clinicians** (smartphones, tablets, laptops) that access ePHI via remote desktop or telehealth apps.
- **Cloud-based telehealth platforms** (Zoom for Healthcare, Doxy.me, Updox) that may store recordings or chat logs.
- **Managed service provider (MSP) environments** where ePHI may be stored on shared infrastructure.
Why This Matters in 2026
The FDA has reported a 300% increase in vulnerabilities in connected medical devices since 2022. Ransomware groups now specifically target IoT devices because they are often unpatched and invisible to traditional asset inventories. If you don’t know a device exists, you cannot protect it.
How to Implement
- Use network discovery tools (e.g., Lansweeper, Nmap, or a healthcare-focused asset management platform) to identify all IP-connected devices.
- Create a formal asset register that includes device type, location, owner, data classification, and patch status.
- Implement a policy requiring pre-approval for any new device or application that handles ePHI.
- Conduct quarterly physical walkthroughs to identify unauthorized devices (e.g., a physician’s personal tablet connected to the clinic Wi-Fi).
---
Control #3: Multi-Factor Authentication (MFA) for All ePHI Access
The Requirement
The Security Rule’s “authentication” standard (45 CFR § 164.312(d)) requires procedures to verify that a person or entity seeking access to ePHI is the one claimed. While the rule does not explicitly mandate MFA, OCR guidance and enforcement actions since 2020 have made it clear that single-factor authentication (username + password) is insufficient for any system containing ePHI.
The Gap
Despite widespread awareness, many medical practices still do not enforce MFA universally. Common excuses include:
- “Our EHR vendor doesn’t support MFA on the legacy interface.”
- “Doctors complain it slows them down.”
- “We only use MFA for remote access, not inside the office.”
In 2026, these excuses are no longer acceptable. The OCR’s 2024 settlement with a New Jersey dental practice ($150,000 fine) explicitly cited lack of MFA as a contributing factor to a breach that exposed 10,000 patient records.
What Most Practices Are Missing
- **MFA on internal network access** – Not just VPN or remote desktop. Any workstation that accesses the EHR should require MFA at login.
- **MFA for administrative accounts** – Practice managers, IT administrators, and billing staff should use phishing-resistant MFA (e.g., FIDO2 security keys or biometrics).
- **MFA for third-party applications** – Patient portals, telehealth platforms, and cloud-based billing systems must all enforce MFA.
- **MFA for email and messaging** – Many breaches start with a compromised email account used to reset EHR passwords.
How to Implement
- Start with a risk-based approach: enable MFA on all systems that contain ePHI, prioritizing remote access and administrative accounts.
- Choose MFA methods that minimize friction: push notifications, biometrics, or hardware tokens.
- Train staff on why MFA is critical—use real breach examples.
- Monitor MFA adoption rates and enforce via conditional access policies (e.g., block logins without MFA after a 30-day grace period).
---
Control #4: Encryption at Rest and in Transit – Including Backups
The Requirement
The Security Rule’s “transmission security” (45 CFR § 164.312(e)(1)) and “integrity controls” (45 CFR § 164.312(c)(1)) address encryption. While encryption is addressable, OCR has repeatedly stated that it is “the most effective method” for protecting ePHI. In practice, failure to encrypt is almost always cited in enforcement actions when a breach occurs.
What Most Practices Are Missing
- **Encryption of data at rest on servers and workstations** – Many clinics still rely on full-disk encryption only on laptops, while leaving server databases unencrypted.
- **Encryption of backups** – A 2025 study found that 40% of healthcare organizations do not encrypt their backup media. If a backup tape or cloud storage bucket is stolen, the breach is reportable.
- **Encryption of internal network traffic** – While HTTPS is standard for external communications, internal traffic between EHR servers and workstations is often transmitted in plaintext over a local network.
- **Encryption of mobile devices and removable media** – USB drives, external hard drives, and even printed QR codes used for patient data transfer are common weak points.
The 2026 Reality
Ransomware attackers now exfiltrate data before encrypting it. If your data is not encrypted at rest, the stolen records are immediately usable. Encrypted data, even if exfiltrated, is far less valuable to attackers and may not trigger a breach notification if the encryption is strong and the key is not compromised.
How to Implement
- Enable BitLocker or FileVault on all endpoints; use LUKS on Linux servers.
- For databases, enable Transparent Data Encryption (TDE) or column-level encryption for sensitive fields (e.g., SSN, medical record numbers).
- Require TLS 1.2 or higher for all internal and external communications.
- Encrypt all backup data—both in transit (via SFTP, HTTPS, or VPN) and at rest (AES-256).
- Establish a key management policy: store encryption keys separately from the data (e.g., in a hardware security module or cloud KMS).
---
Control #5: A Living Incident Response Plan (With Tabletop Exercises)
The Requirement
The Security Rule mandates that covered entities have “policies and procedures addressing security incidents” (45 CFR § 164.308(a)(6)(i)) and a “process for responding to a security incident” (45 CFR § 164.308(a)(6)(ii)). This includes detection, containment, eradication, and recovery.
The Common Deficiency
Most medical practices have an incident response (IR) plan—often a 10-page document created by a consultant and stored in a binder. But when a real incident occurs, the plan is rarely followed. Staff don’t know who to call, how to isolate affected systems, or when to notify patients and OCR.
The Missing Control: Operational Readiness
What is missing is not the document—it is the culture and practice of incident response. In 2026, the average time to identify and contain a healthcare breach is 236 days. Practices that conduct regular tabletop exercises reduce that time by 54%.
What Most Practices Are Not Doing
- **Assigning specific roles** (Incident Commander, Communications Lead, Technical Lead, Legal Liaison) with named backups.
- **Establishing a clear communication tree** that includes the practice’s IT vendor, legal counsel, cyber insurance carrier, and public relations support.
- **Testing the plan at least twice a year** with realistic scenarios (e.g., ransomware encrypting the EHR, phishing-based credential theft, insider data exfiltration).
- **Integrating with business associates** – Many incidents originate at the BA level. Your IR plan must include coordination with your EHR vendor, billing company, and cloud provider.
How to Implement
- Schedule a 90-minute tabletop exercise every six months. Use a facilitator (internal or external) who is not part of the response team.
- Document lessons learned and update the plan within 30 days.
- Ensure that every staff member knows the first step: “If you suspect a breach, report it immediately to [designated contact]—do not try to fix it yourself.”
- Include a post-incident review process that feeds back into risk management.
---
Actionable Checklist for Closing the Gaps
Use this checklist to assess your practice’s current posture against the five missing controls. Each item should be completed within 90 days.
Continuous Risk Management
- [ ] Deploy automated vulnerability scanning (monthly or continuous).
- [ ] Subscribe to a healthcare threat intelligence feed (e.g., Health-ISAC).
- [ ] Conduct a quarterly risk review with documented risk acceptance.
- [ ] Integrate risk findings into your patch management schedule.
Asset Inventory and Management
- [ ] Run a network discovery tool to identify all connected devices.
- [ ] Create a living asset register with data classification for each device.
- [ ] Implement a device approval policy for new hardware/software.
- [ ] Schedule quarterly physical audits for unauthorized devices.
Multi-Factor Authentication
- [ ] Enable MFA on all systems containing ePHI (EHR, email, patient portal, VPN).
- [ ] Use phishing-resistant MFA for administrative accounts.
- [ ] Require MFA for all remote and in-office access.
- [ ] Monitor MFA adoption and enforce with conditional access policies.
Encryption at Rest and in Transit
- [ ] Enable full-disk encryption on all endpoints and servers.
- [ ] Encrypt all databases (TDE or column-level) containing ePHI.
- [ ] Enforce TLS 1.2+ for all internal and external communications.
- [ ] Encrypt all backups (at rest and in transit) with AES-256.
- [ ] Establish a key management policy.
Incident Response Readiness
- [ ] Update your IR plan with named roles and communication tree.
- [ ] Schedule a tabletop exercise within the next 30 days.
- [ ] Include business associates in your IR coordination.
- [ ] Conduct a post-exercise review and update the plan.
- [ ] Train all staff on the first step of incident reporting.
---
Frequently Asked Questions (FAQ)
1. Does HIPAA actually require MFA for all ePHI access?
While the Security Rule does not explicitly name “multi-factor authentication,” OCR guidance and enforcement actions since 2020 have consistently treated single-factor authentication as inadequate. In the 2024 OCR settlement with a New Jersey dental practice, the lack of MFA was cited as a direct cause of the breach. To be compliant in 2026, you should assume MFA is required for any system that can access ePHI.
2. Our practice is small—only three doctors and a receptionist. Do we really need continuous risk monitoring?
Yes. Small practices are the most targeted by ransomware because they often have weaker defenses. A single successful phishing attack can encrypt your entire EHR and force you to pay a ransom or shut down for weeks. Continuous monitoring tools are now affordable (many start under $100/month) and can be managed by a virtual CISO or managed security service provider.
3. What if our EHR vendor doesn’t support MFA?
This is a red flag. If your EHR vendor does not offer MFA, you should either (a) implement a third-party identity provider (e.g., Azure AD, Okta) in front of the EHR, or (b) begin planning a migration to a HIPAA-compliant EHR that supports modern authentication. In the meantime, document the risk and implement compensating controls such as IP whitelisting and session timeouts.
4. How often should we update our risk analysis?
The Security Rule does not specify a frequency, but OCR expects a “continuous” process. At minimum, conduct a formal reassessment annually and whenever there is a significant change (e.g., new EHR, new telehealth platform, merger, or after a security incident). Automated scanning should occur monthly.
5. We have cyber insurance. Doesn’t that cover us if we get breached?
Cyber insurance is a financial safety net, not a compliance control. Insurers now require proof of MFA, encryption, and incident response plans before issuing policies. Furthermore, a breach can still result in OCR fines, lawsuits, and reputational damage that insurance may not fully cover. Compliance is the first line of defense.
6. Is encryption required for data at rest on internal servers?
Yes, if you want to avoid a breach notification. Under the HIPAA Breach Notification Rule, if encrypted data is stolen and the encryption key is not compromised, the breach is presumed not to have occurred. Without encryption, any unauthorized access to a server is a reportable breach. Encryption at rest is the single most effective way to reduce breach risk.
7. Our practice uses a managed IT provider. Are they responsible for these controls?
Your managed IT provider (MSP) can help implement technical controls, but the final responsibility for HIPAA compliance rests with your practice as the covered entity. You must ensure that your MSP has signed a Business Associate Agreement and that they are following the same security standards. Many MSPs claim HIPAA compliance but lack continuous monitoring or incident response testing. Audit your MSP annually.
---
Conclusion: Closing the Gaps Before the Next Breach
The five controls outlined above are not theoretical. They are the concrete, actionable measures that separate compliant, resilient medical practices from those that become the next OCR case study or ransomware headline. In 2026