HIPAA — the programme you run now, and the Security Rule change coming
The Security Rule NPRM published 6 January 2025 would end "addressable": multi-factor authentication, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required. It has not been finalised — OMB targets July 2027 — while OCR continues enforcing the current rule, and its recurring findings are exactly the things the new rule makes mandatory.
Key dates
2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
All three safeguard categories — Administrative, Physical, Technical — plus the 2026 additions.
— HIPAA Compliance Checklist 2026 -
Carries a priority flag for the items with the tightest OCR enforcement history, so remediation starts where the fines actually land.
— HIPAA Compliance Checklist 2026 -
One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.
— Pillar 01 — The Compliance Operating System -
A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.
— Pillar 01 — The Compliance Operating System -
Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.
— Pillar 01 — The Compliance Operating System -
2026 is the first assessment year with no grace argument — PCI DSS v4.0.1 is the only active version and all 51 future-dated requirements have been mandatory since 31 March 2025.
— PCI DSS for Healthcare Kit -
A patient portal that embeds the gateway’s JavaScript is SAQ A-EP, whatever the vendor deck said. 6.4.3 and 11.6.1 were pulled from SAQ A in January 2025 and replaced with an eligibility criterion.
— PCI DSS for Healthcare Kit -
Roughly 70% of PCI’s controls are already the HIPAA Security Rule’s — and the HIPAA proposed rule moves toward PCI, not away.
— PCI DSS for Healthcare Kit -
Your billing company is both a service provider and a business associate. So is the gateway, the EHR payment module and the IVR vendor — collect the AOC, the BAA and the annual verification together.
— PCI DSS for Healthcare Kit -
When an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences — computed here from a single discovery time.
— PCI DSS for Healthcare Kit
Kits that cover it
5 products, cheapest first.
HIPAA Compliance Checklist 2026
Updated for the 2026 Security Rule Final Rule — covers all 12 new mandatory requirements plus the core Administrative, Physical, and Technical safeguards in a single actionable checklist.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
PCI DSS for Healthcare Kit
Healthcare takes card payments too — and PCI is assessed separately from HIPAA by people who do not care that you have a Security Rule programme. One control set for both, the SAQ decision that vendors keep getting wrong, and the dual clock when an incident touches PHI and cardholder data at once.
HIPAA Security Rule 2027 Readiness Kit
The 2027 Security Rule is already written. "Addressable" disappears — MFA, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required. Get ahead of it while OCR keeps enforcing the current rule.
HIPAA Readiness Accelerator
The 23-tab HIPAA programme workbook — Privacy Rule, Breach Notification and all three safeguard sets in one place, plus IoMT, telemedicine, AI clinical decision support, biometric and pediatric registers, BAA tracking, evidence, training and an executive dashboard. Largest product in the catalogue.
Bundles
5 bundles cover this alongside adjacent work — always below the sum of the parts.
Healthcare Provider Risk
The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.
Healthcare Now & Next
The whole HIPAA programme, the Security Rule change coming in 2027, and the payment side neither covers. Three products across the compliance a healthcare organisation is actually assessed on. 19% off buying separately.
Healthcare Security Pack
HIPAA + SOC 2 + Ransomware Readiness for healthcare SaaS and digital health. Healthcare ransomware is 31% of all attacks. 19% off list.
Compliance Trifecta Bundle
SOC 2 + HIPAA + ISO 27001:2022 readiness in one bundle — the three certifications every enterprise buyer asks for. 19% off list.
Compliance Big 5 Bundle
SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 25% off list.
Other regimes: EU AI Act · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum
Working to a date? The compliance calendar. Not legal advice.