If you run or manage a medical practice in Arizona, you’ve probably heard whispers about big changes coming to HIPAA. Maybe your IT company mentioned it. Maybe you saw a headline and moved on because you had 40 patients to see that day. Here’s what’s happening, what it means for your practice, and why getting ahead of it now is easier than scrambling later.
What’s Actually Changing?
In January 2025, HHS published a proposed update to the HIPAA Security Rule. This is the first major overhaul since the rule was written over 20 years ago. The short version: HHS wants to eliminate ambiguity. The proposed changes would make nearly every security requirement mandatory:
Encryption everywhere. Required for all ePHI, both at rest and in transit. No exceptions.
MFA for everyone. Required for any system that accesses ePHI.
Annual penetration testing. A technical security test every year, not just a risk assessment.
72-hour recovery. Documented, tested recovery plan to restore critical systems within 72 hours.
Stronger vendor oversight. Business associates would need to verify and certify their own compliance.
Where Does This Stand Right Now?
As of mid-2026, this is still a proposed rule. It has not been finalized. HHS received nearly 4,800 public comments. The final rule has been pushed back significantly. HHS moved it to July 2027 on the regulatory agenda and demoted it from “final rule stage” to “long-term actions,” effectively dropping it from the 2026 agency rule list.
But here is what matters: OCR is not waiting for the new rule. They are actively enforcing what is already on the books. In April 2026 alone, OCR settled $1.16 million across four entities, all for failing to conduct proper risk analyses. The direction is clear, and enforcement is happening now.
Why This Is Actually Good News
The current rule is vague, and vague rules create anxiety. The new rule would remove the guesswork. Encrypt it. Require MFA. Test your backups. Done. That kind of clarity is actually easier to work with.
What Arizona Practices Should Do Now
1. Check your encryption. Is your server encrypted? Laptops? Email?
2. Turn on MFA. On your EHR, email, and remote access tools.
3. Test your backups. Actually test them. Can you get your practice back up within 72 hours?
4. Know your vendors. Ask each one what they’re doing to protect your data.
5. Get a current risk assessment. If it’s more than 12 months old, it’s time for a real one.
Arizona’s Extra Layer
Arizona’s breach notification law requires notification within 45 days. That’s stricter than the federal 60-day window.
The Bottom Line
The practices that start now will be ahead regardless of when the final rule lands. OCR is already enforcing current requirements aggressively. Waiting for a deadline is not a strategy when enforcement is happening today.
Asteroid IT works with Arizona medical practices to close these gaps before they become emergencies. Call 480-937-7021 or visit our website to get started.
