
The Short Answer
Several pieces of federal healthcare cybersecurity legislation are advancing in 2026, and the most significant of them would transform HIPAA's technical safeguards from voluntary guidance into enforceable, specific requirements. For Phoenix-area medical practices, this is not a future concern to revisit later. It is a present-day operational question: does your current IT program already meet where the rules are heading, or are you running on legacy configurations that will need to be rebuilt under a deadline?
This article breaks down the legislation worth watching, what each measure would require in operational terms, and what a practice should be doing right now regardless of when any bill becomes final.
Why 2026 Is a Pivot Year for Healthcare Cybersecurity Rules
Healthcare has been regulated under HIPAA since 1996, but the Security Rule's technical safeguard requirements were written in broad, flexible language that gave covered entities wide latitude in how they met them. That flexibility made sense in 2003, when the rule was finalized. It makes less sense in an environment where ransomware groups specifically target hospitals and clinics, electronic health records hold decades of patient data, and a single breach can shut down clinical operations for days.
Congress and the Department of Health and Human Services (HHS) have both signaled that the era of flexible, self-interpreted security standards is ending. The legislative proposals moving through 2025 and into 2026 share a common thread: they want specificity, verification, and accountability, not just documented policies.
The Legislative-to-Operations Translation Framework
Before walking through individual bills and rule changes, it helps to have a framework for evaluating them from an operational standpoint. For each legislative development, ask three questions:
- What specific technical control is now required or being proposed? Move past the compliance summary and identify the actual system, process, or configuration being mandated.
- Who in your organization is operationally responsible for that control today? If the answer is "no one" or "we are not sure," that is the gap to close first.
- How will the requirement be verified? A rule that includes audit or attestation obligations changes the operational burden significantly compared to one that only requires internal documentation.
This is the same lens Onsite Technical Services applies when working with Phoenix-area medical practices. The goal is not to generate compliance paperwork. It is to connect each regulatory requirement to a specific, ongoing operational responsibility so that when an auditor, assessor, or breach-response team asks what controls were in place, the answer is a documented and active program, not a binder of policies that have not been touched in two years.
The HIPAA Security Rule Overhaul
In January 2025, HHS published a proposed update to the HIPAA Security Rule. The comment period closed in March 2025, and the final rule is expected to take effect in 2026. This is the most operationally significant development for most medical practices because it affects every covered entity, not just those holding government contracts or operating above a certain size threshold.
The proposed changes move away from "addressable" implementation specifications, which practices have historically interpreted as optional. Under the proposed rule, the major security requirements would become required with far less room for documented alternative approaches. Key areas the proposed rule addresses include:
- Multi-factor authentication (MFA): The proposed rule would require MFA for access to electronic protected health information (ePHI) systems. Many practices already operate MFA on Microsoft 365, but the question is whether MFA is enforced consistently across every system that touches ePHI, including the EHR, imaging platforms, and remote access.
- Encryption: The proposed rule would require encryption of ePHI at rest and in transit, removing the flexibility that allowed some organizations to use alternative protections in lieu of encryption.
- Network segmentation: Separating clinical systems from general business networks would move from a recommended practice toward an enforceable standard.
- Vulnerability scanning and patching: The proposed rule calls for documented, recurring vulnerability management, meaning practices need a verifiable patching program, not just a general intention to keep systems updated.
- Annual technical assessments: Covered entities would be required to conduct documented security risk assessments at least annually, and the assessment would need to be technically substantive, not a self-reported checkbox exercise.
- Incident response planning: Written, tested incident response plans would be required, with specific elements including restoration procedures and communication protocols.
The compliance timeline in the proposed rule varies by organization size, but the direction is clear. Practices that have operated on flexible, minimally-documented security programs should treat this as a rebuild-now signal, not a wait-and-see one.
The Health Infrastructure Security and Accountability Act
Introduced in the Senate and advancing through 2025, the Health Infrastructure Security and Accountability Act (HISAA) takes a harder line than the HIPAA Security Rule update. Its notable provisions include:
- Mandatory minimum cybersecurity standards: HISAA would direct HHS to establish specific, non-negotiable technical standards rather than leaving implementation to each covered entity's risk assessment. This would effectively end the "reasonable and appropriate" self-interpretation model for baseline controls.
- Annual audits for large organizations: Hospitals and health systems above defined revenue or patient-volume thresholds would face mandatory third-party cybersecurity audits. Smaller practices would face periodic government-run audits rather than purely complaint-driven enforcement.
- Increased civil monetary penalties: HISAA proposes significantly higher penalties for Security Rule violations, with enhanced penalties for organizations that experience a breach while out of compliance with the mandatory standards.
- Accountability for C-suite leadership: The bill includes provisions holding senior executives personally accountable for willful neglect of required cybersecurity controls, a shift from entity-level to individual-level accountability in enforcement.
HISAA has not yet passed as of this writing, and its final form may differ from the introduced version. However, the bill reflects bipartisan concern about healthcare sector cyber resilience, and its core provisions (mandatory minimums, mandatory audits, stronger penalties) are likely to survive in some form. Practices should not wait for a final vote to begin closing gaps.
The American Privacy Rights Act and Healthcare Data
The American Privacy Rights Act (APRA) is a federal privacy bill that has advanced further than most prior attempts at a comprehensive federal privacy law. While HIPAA-covered entities are partially carved out of APRA's scope, the bill's provisions around data minimization, consent for certain secondary uses of health data, and consumer rights to deletion and correction could create new obligations for practices that also collect data outside the strict HIPAA definition, including wellness programs, telehealth platforms operating under different regulatory frameworks, or patient engagement applications.
The operational implication: practices should understand which data flows in their environment are covered by HIPAA and which are not. Data collected through a patient portal integrated with an EHR is likely HIPAA-covered. Data collected through a third-party wellness application, marketing email platform, or patient satisfaction survey tool may not be, and APRA could apply to those flows even if HIPAA does not.
This is not a reason to stop using those tools. It is a reason to document what data they collect, where it goes, and whether the vendor relationships have appropriate data processing terms in place.
State-Level Activity to Watch in 2026
Arizona has not yet enacted healthcare-specific cybersecurity legislation beyond its data breach notification requirements, but several states have moved ahead of the federal government with sector-specific rules. California, New York, and Colorado have all enacted or proposed healthcare cybersecurity requirements that go beyond current HIPAA minimums. Federal legislation often draws from state models, so the provisions advancing at the state level today tend to predict federal requirements within a few years.
Phoenix-area practices with patients or business relationships in other states, particularly those operating telehealth services across state lines, should track both federal and multi-state developments. The patchwork of state laws that currently applies to non-HIPAA data privacy is beginning to extend into healthcare-specific cybersecurity obligations.
What These Developments Mean Operationally for a Phoenix Medical Practice
Legislation and proposed rules do not translate directly into operational action without a clear map from requirement to responsibility. Here is how the major themes above map to specific IT and security program elements that a practice should be able to verify today:
| Legislative Requirement | Operational Control | Verification Question |
| Multi-factor authentication for ePHI access | MFA enforced on EHR, Microsoft 365, remote access, and all ePHI-adjacent systems | Is MFA enforced by policy, not just offered as optional? |
| Encryption at rest and in transit | Full-disk encryption on all endpoints; encrypted data transmission enforced for ePHI | Are there any devices or data paths where encryption is not active? |
| Vulnerability scanning and patching | Recurring automated patch management with documented cadence and exception handling | Is there a report showing what was patched, when, and what is outstanding? |
| Annual security risk assessment | Documented risk assessment performed or reviewed with technical depth each year | When was the last assessment, and does it reflect current systems? |
| Incident response planning | Written IR plan covering detection, containment, restoration, and notification steps | Has the plan been tested or walked through in the past 12 months? |
| Audit log retention | Security event logs retained for six years to satisfy HIPAA obligations | Where are logs stored, and can they be produced for an audit? |
| Network segmentation | Clinical systems isolated from guest and general business traffic | Is the network architecture documented and enforced by device policy? |
If any row in that table produces an uncertain answer, that is a gap in the current program. Legislation formalizes these requirements, but the gaps themselves represent real operational and clinical risk today, before any bill passes.
The Operational Responsibility Question Every Practice Should Ask Its IT Provider
One of the consistent themes across every piece of 2026 healthcare cybersecurity legislation is that documentation and verification matter as much as the controls themselves. Having antivirus software installed is not the same as having a documented, monitored, managed endpoint protection program. Having a backup system is not the same as having tested, independent backup copies of both endpoint data and Microsoft 365 content that can be restored under a real incident.
Onsite Technical Services structures its healthcare IT program around this distinction. The technical safeguards in a managed program, including endpoint protection, identity monitoring, email security, patch management, encryption enforcement, access controls, and backup and recovery, are not product checkboxes. They are ongoing operational responsibilities. Someone has to configure them, monitor them, respond when they alert, document what was done, and verify that they are working. That recurring work is what a well-structured Managed Security and Support engagement covers.
The right question to ask any Managed Service Provider (MSP) is not "do you include antivirus?" It is: "Who is operationally responsible for monitoring, responding to, and documenting each safeguard, and how is that responsibility verified?"
Planning for IT Costs as Compliance Requirements Rise
Medical practices evaluating IT programs in light of tightening cybersecurity requirements often ask what properly managed healthcare IT costs. The honest answer is that it depends on the practice's size, architecture, and existing environment, but a reasonable planning benchmark for a properly managed Phoenix-area medical practice is approximately $200 to $250 per user per month. That is planning guidance, not a guaranteed quote. What it reflects is the real cost of the recurring operational work required to implement, monitor, and document technical safeguards at the level that current and emerging HIPAA requirements expect.
Practices that are currently paying significantly less than this range should ask what operational responsibilities are not being covered. A lower invoice does not mean the work is not needed. It usually means the work is not being done, or the practice is doing it informally without documentation, which is precisely what the 2026 legislative environment is designed to surface and penalize.
Microsoft 365 licensing, EHR platform costs, hardware, and project work are separate from a managed IT engagement and should be budgeted independently.
What Onsite Technical Services Does in a Healthcare Engagement
For Phoenix-area medical practices, Onsite Technical Services implements, operates, monitors, and documents the technical safeguards that support a practice's HIPAA program. The practice retains ownership of its HIPAA compliance program. OTS carries operational responsibility for the technical side: endpoint protection and detection, identity security monitoring, email threat protection, application and access controls, encryption enforcement, patching, backup and recovery, and the audit trail that documents that all of this is running and being maintained.
Periodic Business Technology Reviews (BTRs) are included in the Standard Managed Services engagement, giving practice leadership a structured, recurring touchpoint to review the security posture, address any open items, and plan for changes in the environment or regulatory requirements. As the 2026 legislative environment evolves, those reviews are the natural venue for translating new requirements into updated operational configurations.
Support coverage for managed healthcare clients includes business-hours helpdesk for day-to-day staff needs, 24/7 monitoring of the environment, and after-hours incident response when something requires immediate action. The helpdesk itself operates during business hours; the monitoring and incident response coverage does not stop when the office closes.
Learn more about how Onsite Technical Services supports Phoenix-area medical practices at onsite-tech.com/healthcare.
Frequently Asked Questions
Does the HIPAA Security Rule update apply to small medical practices?
Yes. The proposed HIPAA Security Rule update applies to all covered entities, regardless of size. The proposed compliance timelines do vary by organization size, with smaller practices generally receiving more time to implement changes. However, the core requirements, including MFA enforcement, encryption, documented patching, and annual risk assessments, would apply across the board. Small practices that have operated on minimal or informally documented security programs should use the implementation window to rebuild, not simply to delay.
What is the difference between the HIPAA Security Rule update and HISAA?
The HIPAA Security Rule update is a regulatory action by HHS that updates existing law. It is moving through the rulemaking process and is expected to take effect in 2026. HISAA is a separate piece of congressional legislation that would go further than the Security Rule update by establishing mandatory minimum technical standards, requiring third-party audits for larger organizations, increasing civil monetary penalties, and introducing personal accountability for senior executives. Both are advancing on parallel tracks, and both reflect the same directional shift toward specificity and enforcement in healthcare cybersecurity.
Does my practice need to worry about the American Privacy Rights Act if we are already HIPAA compliant?
Possibly, depending on what data your practice collects outside of the strict HIPAA definition. HIPAA-covered entities are partially carved out of APRA's scope for data that falls within HIPAA's coverage. However, data collected through third-party wellness applications, patient engagement tools, marketing platforms, or telehealth services that operate outside the HIPAA framework may not be covered by HIPAA and could fall under APRA. The practical step is to document what data your practice collects through each system, where it goes, and whether your vendor agreements include appropriate data handling terms.
How long does a medical practice need to retain security audit logs under HIPAA?
HIPAA requires audit log retention for six years. This is distinct from a shorter baseline that some endpoint security tools use for general log retention. A properly structured healthcare IT program maintains security event logs for the full six-year period in a way that can be produced for an audit or compliance review. If your current IT program cannot demonstrate six-year log retention, that is a specific gap to address.
What does properly managed medical practice IT cost in Phoenix?
A reasonable planning benchmark for a properly managed Phoenix-area medical practice is approximately $200 to $250 per user per month for the managed IT and security engagement. This is planning guidance, not a guaranteed quote, and the actual figure for a specific practice depends on size, architecture, and existing environment. Microsoft 365 licensing, EHR platforms, hardware, and project work are budgeted separately from the managed services engagement.

