HIPAA's Security Rule hasn't seen a major update since 2013. That's about to change. Regulators have proposed the most significant revision in over a decade, and the shift isn't subtle: safeguards that used to be optional are becoming mandatory, and "we have a policy" is no longer enough on its own.
If your business touches protected health information in any capacity, including as an IT provider or other business associate, this update reaches you directly.
"The updates shift HIPAA compliance from a checklist task to a proactive, measurable process. Written policy without ongoing monitoring is no longer the same thing as compliance."
The Core Shift Worth Understanding
The old Security Rule used a category called "addressable" safeguards, controls organizations could implement, document an alternative for, or skip with justification. That flexibility is going away. The proposed update eliminates the distinction between required and addressable safeguards almost entirely, making nearly all of them mandatory controls.
That single change reshapes how covered entities and their business associates, including IT providers, need to operate. Multi-factor authentication, encryption, and regular technical testing move from "recommended practice" to "required control," with real audit consequences for falling short.
What's Actually Changing
- Is multi-factor authentication enforced on every system touching PHI?
- Is electronic PHI encrypted both at rest and in transit, consistently?
- Do we have a documented, tested process for revoking access quickly?
- When was our last penetration test, and is it on a recurring schedule?
- Can our IT provider demonstrate compliance with these new requirements?
Where Gradius Fits In
We help healthcare-adjacent businesses move from written policy to the measurable, ongoing controls this update actually requires. That means implementing mandatory MFA and encryption, establishing a real testing cadence, and maintaining the documentation that demonstrates compliance during an audit, not just promises it.
This update rewards businesses that treat compliance as an ongoing practice rather than a folder of policy documents. We help build that practice before the deadline arrives.
for the New HIPAA Standard