For the first time in over a decade, the U.S. Department of Health and Human Services (HHS) has proposed major updates to the HIPAA Security Rule 2025. If you run a healthcare practice, this one is worth reading closely, because several things that used to be optional are about to stop being optional.
Healthcare data breaches have increased 102% over the past five years, and the number of people affected is up 1,002% since 2019. Whatever most practices are doing now is not keeping up.
Healthcare breaches by the numbers
This is what is driving the proposed changes:
- 167 million individuals were affected by healthcare breaches in 2023 alone
- Hacking-related incidents targeting healthcare providers increased by 89%
- Healthcare organizations have become the #1 target for cybercriminals
What changes in the 2025 HIPAA Security Rule updates
Mandatory multi-factor authentication (MFA): Under the proposed updates, MFA will be required for every system that touches electronic Protected Health Information (ePHI). Every user, from physicians to front desk staff, will have to verify their identity with a second factor.
Encryption requirements: The new rules make encryption of ePHI mandatory, both at rest and in transit. The old "addressable" designation, which let an organization skip encryption as long as it documented why, goes away.
Vulnerability scanning and penetration testing: Practices will be required to run vulnerability scans at least every 6 months and a penetration test every year, then fix what those turn up.
Stricter risk analysis requirements: The proposed updates raise the bar for risk analysis. Practices will need more detailed documentation and a regular review of security risks rather than a document that gets written once and filed.
Business associate oversight: Covered entities will face stricter requirements for checking that their business associates (vendors with access to ePHI) keep adequate security controls in place. Your vendor's weak security becomes your problem.
How safemode IT helps healthcare practices achieve HIPAA compliance
For years, safemode IT has been helping healthcare organizations in Kyle, San Marcos, Bastrop, and Austin get to HIPAA compliance and stay there. Our healthcare IT services cover MFA rollout, data encryption, regular vulnerability assessments, and the security documentation the new rule will expect you to produce.
Contact safemode IT today to schedule a HIPAA readiness assessment and find out how far your practice is from the 2025 Security Rule requirements.
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Frequently asked questions
What are the proposed 2025 HIPAA Security Rule changes?
HHS has proposed mandatory multi-factor authentication for all systems that access ePHI, mandatory encryption of ePHI at rest and in transit, vulnerability scanning at least every 6 months plus annual penetration testing, more detailed risk analysis and documentation, and stricter oversight of business associates. It is the first major update to the Security Rule in over a decade.
Will MFA be required under the new HIPAA Security Rule?
Yes, under the proposed updates. MFA would be required for every system that accesses electronic Protected Health Information, and every user, from physicians to front desk staff, would need to verify their identity with a second factor.
Is encryption of ePHI mandatory under the proposed HIPAA rule?
Yes. The proposal makes encryption of ePHI mandatory both at rest and in transit. The previous "addressable" designation, which let an organization skip encryption if it documented the reason, would be eliminated.
How often will healthcare practices need vulnerability scans and penetration tests?
Under the proposed rule, vulnerability scanning at least every 6 months and penetration testing once a year. The point is to find and fix security weaknesses before an attacker does.
Can safemode IT get our practice ready for the HIPAA Security Rule changes?
Yes. We help healthcare organizations in Kyle, San Marcos, Bastrop, and Austin with MFA rollout, data encryption, regular vulnerability assessments, and the security documentation the new rule calls for. Learn more about our cybersecurity services or reach out to schedule a HIPAA readiness assessment.
Last updated: April 4, 2026


