unsplash-image-j4uuKnN43_M.jpg

IT News from SNH

Weekly Tech Updates

Navigating the complexities of today's IT landscape can be daunting. Whether you're a small business owner grappling with data security, a medium-sized company aiming to streamline its IT infrastructure, or a large corporation looking for custom solutions, we've got you covered. Our team of highly skilled, Santa Rosa Beach-based IT professionals are always on hand to offer the best-in-class IT services that your business deserves.

You can learn more about managing IT services with regular industry updates, best practices, cybersecurity tips, and much more. The goal is to help you make informed decisions about your technology investments. In addition, we highlight how our services can specifically help businesses in Walton County stay competitive and secure.

As your local IT company, we're not just technology experts; we’re experts in understanding the unique IT needs of local businesses like yours. Our knowledge is informed by the area business climate and specific needs of companies on 30A-Santa Rosa Beach-Panama City Beach. Here you’ll find tailored solutions to help you maximize productivity, efficiency, and security, ensuring your technology infrastructure grows with your business.

Be sure to subscribe for regular updates on all things IT. We're excited to be your go-to resource for managed IT services in Santa Rosa Beach. With a wealth of local experience and expertise, you can trust us to keep your business at the cutting edge of technology. As a local company, we're proud to be part of the 30A-Santa Rosa Beach community and are dedicated to helping area businesses like yours thrive in the modern digital world.

At SNH Technologies, we're more than just an IT company - we're your local IT partner. Remember, when it comes to IT consulting in Santa Rosa Beach and the Florida panhandle, think local, think SNH Technologies.

HIPAA Cybersecurity Rules Are Changing: What Medical Practices Should Be Doing Now

For years, many medical practices have treated HIPAA cybersecurity as a relatively flexible standard.

Perform a risk assessment. Put reasonable safeguards in place. Document your policies. Train employees. Protect patient information.

That framework is changing.

The U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), has proposed the most significant update to the HIPAA Security Rule in more than a decade, with much more specific cybersecurity requirements for healthcare organizations and their business associates.

The proposal includes requirements for multi-factor authentication, encryption, vulnerability scanning, network mapping, annual compliance audits, penetration testing, backup and recovery testing, incident response planning and network segmentation.

But there's an important distinction:

The New HIPAA Cybersecurity Rule Is Not Final Yet

As of August 2026, the proposed changes have not become a final rule.

The current HIPAA Security Rule remains in effect.

That means a medical practice should not be told that HIPAA suddenly requires annual penetration testing or vulnerability scans every six months today simply because those requirements appear in the proposed rule.

However, that doesn't mean practices should ignore what's coming.

The proposal shows quite clearly where HHS believes healthcare cybersecurity needs to go.

More importantly, many of the underlying responsibilities already exist.

The current Security Rule requires covered entities to perform an accurate and thorough assessment of risks and vulnerabilities to electronic protected health information, manage those risks, control access, maintain audit capabilities and implement appropriate administrative, physical and technical safeguards.

In January 2026, OCR also specifically highlighted system hardening, patching, vulnerability identification, removal of unnecessary software and secure configurations as important measures for protecting electronic protected health information.

So the question for medical practices isn't simply:

“When will the new rule take effect?”

A better question is:

“If these requirements became mandatory tomorrow, how far away would we be?”

What Changes to HIPAA Are Proposed?

The proposed HIPAA Security Rule changes are significantly more prescriptive than the current framework.

Among the changes HHS has proposed are:

  • requiring multi-factor authentication, with limited exceptions;

  • requiring encryption of electronic protected health information at rest and in transit, with limited exceptions;

  • requiring vulnerability scanning at least every six months;

  • requiring penetration testing at least annually;

  • requiring an annual HIPAA Security Rule compliance audit;

  • requiring an inventory of technology assets;

  • requiring a network map showing how electronic protected health information moves through the organization;

  • requiring stronger security configuration controls and anti-malware protections;

  • requiring network segmentation;

  • requiring written incident response procedures;

  • requiring testing and revision of incident response plans;

  • requiring procedures to restore certain critical systems and data within 72 hours;

  • requiring more specific backup and disaster-recovery procedures;

  • strengthening requirements surrounding workforce access changes and termination; and

  • requiring substantially more written documentation.

Perhaps most importantly, HHS has proposed eliminating much of the distinction between HIPAA safeguards that are currently classified as “required” versus “addressable.”

In other words, the direction is toward less ambiguity.

“Addressable” Never Meant “Optional”

This is worth emphasizing because it has caused confusion for years.

Under the current HIPAA Security Rule, some implementation specifications are classified as “addressable.”

That does not mean a medical practice can simply decide not to implement them.

A covered entity must evaluate whether an addressable safeguard is reasonable and appropriate in its environment. If it chooses an alternative—or determines that the safeguard isn't appropriate—it needs to be able to support that decision.

HHS's proposed rule would largely remove this distinction and make implementation specifications mandatory, subject to specific limited exceptions.

That would fundamentally change the conversation from:

“Do we really need this?”

to:

“How are we implementing this?”

For practices that have relied heavily on the flexibility of the existing Security Rule, that could require significant changes.

MFA Is Moving From Best Practice Toward an Expectation

Most medical practices today rely heavily on cloud systems.

  • Microsoft 365.

  • Electronic health records.

  • Practice-management systems.

  • Cloud imaging.

  • Payroll.

  • Remote access.

  • Patient portals.

  • Vendor platforms.

Each account represents a potential entry point.

A password alone is increasingly inadequate protection for systems containing or providing access to sensitive information.

HHS's proposed rule would expressly require multi-factor authentication for access to relevant electronic information systems, with limited exceptions.

Even before a final rule, practices should be asking:

Which systems containing patient information still allow employees to log in with only a username and password?

That review should include more than the EHR.

Email accounts are particularly important because a compromised Microsoft 365 or Google Workspace account can expose patient communications, password-reset messages, attachments, contacts and information attackers can use for additional social engineering.

MFA should also be evaluated for administrators, remote access, cloud applications and other systems that could provide a path to ePHI.

Encryption Needs to Be More Than “Our EHR Is Encrypted”

Another common assumption is: “Our patient records are encrypted because they're in our EHR.”

That may be true.

But where else does patient information go?

Employees may receive records by email.

Documents may be downloaded to computers.

Scanned records may be saved in shared folders.

Employees may use laptops from home or other locations.

Reports may be exported from applications.

Backups may contain copies of patient data.

Information may also move between medical devices, vendors and cloud platforms.

HHS's proposal would require encryption of ePHI both at rest and in transit, subject to limited exceptions.

A useful exercise today is simply determining where ePHI exists outside the primary medical application.

Many organizations discover there is considerably more of it than they expected.

Proposed HIPAA requirements include a technology asset inventory.

Do You Actually Know Every Device That Can Access Patient Information?

One of the more practical proposed requirements is a technology asset inventory.

Think about a typical medical office.

There may be front-desk computers, clinical workstations, laptops, servers, tablets, smartphones, printers and scanners, wireless access points, medical devices, network equipment, remote-access systems, and cloud applications.

Now ask:

Do we have a current list of all of them?

And then:

Which of them can access, store or transmit ePHI?

HHS has proposed requiring both an asset inventory and a network map illustrating how ePHI moves through an organization's systems.

Even if that exact requirement changes before a final rule, knowing what technology your practice has and where sensitive information travels is foundational to protecting it.

You cannot reliably secure systems you don't know exist.

Vulnerability Management Is Getting Much More Specific

The current HIPAA Security Rule already requires organizations to assess risks and vulnerabilities to ePHI.

But the proposed rule puts much more specificity around how that happens.

HHS has proposed requiring:

Vulnerability scanning at least every six months.

And:

Penetration testing at least once every 12 months.

Those are different activities:

  1. A vulnerability scan searches systems for known weaknesses, outdated software, missing patches, insecure configurations and other identifiable vulnerabilities.

  2. A penetration test goes further by attempting to determine whether vulnerabilities can actually be exploited.

OCR's January 2026 cybersecurity guidance also specifically pointed healthcare organizations toward vulnerability scanning and monitoring authoritative vulnerability sources as ways to identify weaknesses.

For a medical practice, that means the old approach of simply confirming that antivirus is installed isn't enough.

Practices increasingly need a repeatable process for identifying vulnerabilities, deciding which ones matter, fixing them and documenting what was done.

Your Risk Analysis Needs to Be Real

HIPAA risk analysis is not new. It is already required.

The current Security Rule requires covered entities and business associates to perform an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI.

Yet the risk analysis remains one of the most important—and frequently misunderstood—parts of HIPAA security.

A checklist from an IT vendor is not automatically a HIPAA risk analysis. Neither is a vulnerability scan. Neither is an antivirus report.

A meaningful risk analysis considers where ePHI exists, what systems interact with it, what threats could affect those systems, what vulnerabilities exist and how those risks are being managed.

HHS's proposed rule would make the required analysis even more specific, incorporating the organization's asset inventory and network map and requiring identified threats and vulnerabilities to be evaluated.

If your practice's last risk analysis is several years old—or nobody can locate it—that's something worth addressing now.

What Happens When an Employee Leaves?

This is another area where healthcare cybersecurity and ordinary business operations collide.

Someone resigns.

HR processes the paperwork.

The office manager knows they're gone.

But who disables:

  • Microsoft 365?

  • the EHR account?

  • VPN access?

  • remote desktop?

  • cloud applications?

  • shared passwords?

  • building access?

  • vendor portals?

And how quickly?

HHS has proposed requiring certain regulated entities to notify appropriate personnel within 24 hours when a workforce member's access to ePHI or relevant systems changes or terminates.

Regardless of whether that exact timeline appears in the final rule, medical practices should already have a defined IT onboarding and offboarding process.

Former employees should not retain access to patient information because everyone assumed someone else disabled the account.

Can Your Practice Recover Within 72 Hours?

Another notable proposal concerns disaster recovery.

HHS has proposed requiring written procedures to restore certain critical electronic information systems and data within 72 hours of a loss.

That is not currently a blanket 72-hour HIPAA requirement.

But it's a valuable question to ask anyway:

Could your practice do it?

If ransomware encrypted your server tonight, what would happen tomorrow morning?

  • Could staff access the EHR?

  • Could appointments continue?

  • Could you communicate with patients?

  • Can your backups actually be restored?

  • How long would restoration take?

  • Which system would come back first?

A backup that completes successfully every night is important. A tested recovery process is better.

Your Incident Response Plan May Need More Than an IT Phone Number

The proposed HIPAA changes would also strengthen incident response requirements. HHS has proposed written procedures covering how employees report suspected security incidents, how the organization responds, and how those procedures are tested and revised.

That matters because a cyber incident quickly becomes more than a technical problem.

Imagine ransomware has affected the practice. Who decides whether systems should be shut down? Who contacts cyber insurance or legal counsel? Who determines whether patient notification is required? How will employees communicate if email isn't available? Who talks to patients, and who has authority to make those decisions?

Those answers should be established before an incident. An incident response tabletop exercise can be an effective way to find gaps without experiencing an actual attack.

HIPAA places obligations around business associate relationships and agreements.

Don't Forget Your Business Associates

Medical practices don't operate in isolation.

Patient information may be accessible to billing companies, EHR providers, cloud vendors, IT providers, transcription services, consultants, laboratories, imaging providers, and other outside organizations.

HIPAA already places obligations around business associate relationships and agreements.

The proposed cybersecurity rule would increase scrutiny further.

Among other things, HHS has proposed requiring business associates to provide covered entities with annual verification that certain technical safeguards have been deployed, supported by analysis from a subject-matter expert.

For a medical practice, that reinforces an important point:

Your cybersecurity risk doesn't stop at your firewall.

Practices should know which vendors have access to ePHI, confirm appropriate Business Associate Agreements are in place and understand what security responsibilities belong to the practice versus the vendor.

What Should Medical Practices Be Doing Now?

You don't need to implement every provision of a proposed regulation as though it were already law.

But waiting until a final rule is published to start evaluating your environment may create an unnecessary scramble.

A medical practice can begin with some practical questions:

  1. Do we have a current HIPAA security risk analysis?

  2. Is MFA enabled everywhere it reasonably should be?

  3. Do we have documentation listing every system, device, vendor and business associate that can access ePHI?

  4. Do we know where ePHI is stored outside our EHR?

  5. Do we have tested backups, and do we know how long recovery would actually take?

  6. Are computers and servers being patched, hardened and monitored consistently?

  7. Do we have a written incident response plan—and have we tested it?

  8. Is there a reliable process for immediately removing access when an employee leaves?

If several of those questions are difficult to answer, the issue probably isn't the proposed rule.

It's that there are cybersecurity gaps worth addressing under the current environment too.

HIPAA Is Becoming More Specific About Cybersecurity

Healthcare cybersecurity has changed dramatically since the Security Rule was last substantially updated.

Medical practices now depend on cloud services, remote connectivity, integrated software platforms, electronic records and a growing ecosystem of third-party vendors.

At the same time, healthcare has become an increasingly attractive target for cybercriminals.

HHS reported that between 2018 and 2023, reports of large healthcare breaches increased 102%, while the number of individuals affected increased more than 1,000%. Hacking and ransomware were major drivers of that increase.

The proposed HIPAA Security Rule changes reflect that environment and while the final requirements may change, the direction probably won't.

Healthcare organizations are being pushed toward cybersecurity that is more measurable, documented, tested and repeatable.

For medical practices, the best strategy isn't to panic about a regulation that hasn't been finalized.

It's to determine whether the security measures you already rely on would stand up to closer scrutiny.

Is Your Practice Ready for the Next Version of HIPAA Security?

SNH Technologies helps medical practices and healthcare organizations evaluate the technology behind HIPAA security, including Microsoft 365, endpoint protection, MFA, vulnerability management, backups, access controls, documentation, and incident preparedness.

If you're unsure where your current cybersecurity environment stands, start by identifying the gaps before new requirements make them urgent.