The overhaul moving through OCR right now turns the old “addressable” safeguards into hard mandates — encryption everywhere, MFA on every login, segmentation between sites. Almost none of it lives in a piece of software you can buy. It lives in how your network is built.
By Jonathan Eubanks · June 26, 2026 · 8 min read
⚡ The short version
I sat down with the office manager of a three-location medical practice a couple weeks ago. She wasn’t worried about phones or internet — she had a printout of the proposed HIPAA Security Rule changes and a yellow highlighter that had clearly seen a lot of use. “Half of this isn’t even about computers,” she said. “It’s about how the offices talk to each other. Nobody told me HIPAA was a network thing.”
She’s right, and she’s ahead of most people. For years the HIPAA Security Rule let practices treat a lot of its safeguards as “addressable” — a word that, in the real world, too often meant “we wrote a sentence about it in a binder and moved on.” The 2026 overhaul that’s working its way through the Office for Civil Rights changes that posture entirely. The direction is unmistakable: encryption of patient data at rest and in transit, multi-factor authentication on every point of access, network segmentation, vulnerability scanning, tested backups. Less “consider this,” more “do this and be able to prove it.”
I’ll be straight with you about where it stands, because there’s a lot of noise out there. As I write this, the updated rule is still proposed, not final — a good chunk of the exact control lists circulating online come from IT-vendor blogs rather than the rule text. So treat the specifics as directional until OCR publishes the final. But the direction itself isn’t in doubt, and once that final rule drops, the clock to comply is expected to be roughly 240 days. That is not a lot of runway for the kind of work this asks for — especially if you run more than one location.
Strip away the legal language and the proposed update lands on a short list of things that would have been “nice to have” a few years ago and are becoming “prove it or you’re out of compliance” now.
Encryption everywhere — including in transit. Encrypting patient data sitting on a server is the part most practices already understand. The phrase that catches people is “in transit.” Every time a chart, an image, or a billing file moves between your front desk and your back office, between your main clinic and your satellite office, between a provider at home and the EHR — that data is in transit, and it’s expected to be encrypted the entire way. That is a connectivity decision, not a checkbox in your records software.
MFA on every point of access. Not just the EHR login. Remote access, email, administrative accounts, the connection your billing company uses, the vendor who maintains your imaging equipment. The requirement is built to find the one door somebody left propped open — the legacy login, the “just for now” exception that became permanent.
Segmentation and a real map of your network. The proposal leans hard on knowing what’s on your network and keeping the sensitive parts walled off from the rest. The waiting-room Wi-Fi, the smart thermostat, the check-in tablet, and the system holding patient records should not all live on the same flat network where a foothold in one becomes a foothold in all. You can’t segment what you haven’t mapped, and most practices have never been handed an honest map.
Tested backups and vulnerability scanning. “We back up nightly” and “we have restored from backup and scanned for holes recently” are two very different sentences. The new posture wants the second one — backups an attacker can’t reach and encrypt along with everything else, and evidence you’ve actually checked your own walls.
A single-office practice has a hard enough time with this. But the place I see it get genuinely difficult is the practice that’s grown to three, five, eight locations — often by acquiring smaller practices that each came with their own internet provider, their own router somebody’s nephew set up, their own idea of a password policy.
What you end up with is a compliance obligation that’s identical across every site and a network that’s different at every site. The rule doesn’t care that your Dublin office is on fiber with a real firewall while the office you picked up last year is running on a consumer cable modem and a Wi-Fi password taped to the monitor. From OCR’s chair, it’s one covered entity, and the weakest location sets your real exposure. One unencrypted link between sites, one location without MFA, and the “yes” you wrote down stops being true everywhere.
This is the part that turns a paperwork exercise into a network project. Applying one uniform standard — same encryption, same authentication, same segmentation, same monitoring — across locations that were never built to match is exactly the kind of work that’s easy to half-do and very hard to prove. And in healthcare, “half-done” is the same as “no,” because healthcare remains the number-one ransomware target in the country. For a small practice, a breach isn’t an IT headache. It’s an extinction event.
Here’s the thing the compliance checklists rarely spell out: almost none of these mandates are satisfied by buying a product. They’re satisfied by how your network is designed. Encryption in transit between sites means secure, encrypted connectivity — a properly built SD-WAN or VPN backbone tying your locations together, not whatever the cable company happened to hand you. MFA on every access point means you actually know every door into your systems across every site. Segmentation means your network is deliberately divided so a problem in the waiting room can’t reach the records room. Monitoring and tested backups mean a managed service watching all of it, all the time, not a setting somebody flipped on once.
That’s why I keep telling practice owners to stop thinking of this as an IT-software purchase and start thinking of it as a network they have to be able to stand behind. The EHR vendor will tell you their product is “HIPAA compliant,” and that’s fine — but the rule applies to your whole environment, not just the one application. The space between your systems is where the gaps live.
Quick win: Before you spend a dollar on new tools, build one honest map — every location, every internet connection, every way into your systems, every device touching the network, and exactly how data travels between your sites. Most practices can’t produce that map, and that gap is the answer to half of what the rule is going to ask. You cannot encrypt, segment, or attest to a network you can’t see.
If pulling that map together across multiple locations feels like more than you want to take on alone, that’s the first thing we do for a practice getting ahead of this — lay out what you actually have, line it up against where the rule is clearly headed, and show you the real gaps before any deadline does. Because the carriers and providers pay us, there’s no advisory fee for that look, and we have no quota pushing you toward any one fix — which means we’ll tell you when a site is already in good shape. Talk to the team if you’d rather see the gaps now than discover them in a breach notification.
Here’s the good news buried in all of this: you’re not building three different things. The HIPAA direction, your cyber-insurance renewal, and plain common sense are all converging on the same short list. The insurer wants MFA everywhere, EDR on every endpoint, and tested backups before they’ll renew your policy. OCR is moving toward encryption, segmentation, and the same authentication and backup discipline. They’re describing the same network — segmented, monitored, encrypted end to end, with a real inventory behind it.
So the smart move isn’t to chase each questionnaire separately as it lands. It’s to build one defensible network across all your locations and then point every requirement at it — the insurance form, the HIPAA risk assessment, the next regulation that shows up. Do the work once, on your terms, and you stop scrambling every time a new deadline arrives with a number attached.
The HIPAA Security Rule overhaul feels like a burden because it reads like a legal document and arrives with a compliance clock. But strip away the framing and what it’s really handing every medical practice is a description of what a defensible network should look like in 2026 — encrypted between sites, segmented inside each one, with multi-factor authentication on every door and backups you’ve actually tested. That’s not a bad blueprint. The mistake is waiting until the final rule drops and the 240-day clock starts, then trying to retrofit five mismatched locations in a panic.
So get ahead of it while it’s still “directional.” Build the map before you buy anything. Bring your weakest location up to the standard of your best one, because the rule grades you on the weakest. Treat the insurance, regulatory, and security requirements as one network problem instead of three. And decide what your practice’s network should look like on your terms — this quarter, calmly — instead of the week the final rule lands.
If you run a multi-location practice and you want a straight read on where you actually stand across your sites before any deadline forces the issue, that’s exactly the work we do, and it costs you nothing. Sometimes the answer is “you’re in better shape than you thought” — and we’ll tell you that too. Either way, you’ll be making the call instead of a breach making it for you.
— Jonathan
Jonathan founded Buckeye Telecom in 2003 after years in the Columbus telecom industry — first at 5-Star distributors learning the carrier side, then carrying his own quota in telecom sales. He still works directly with clients — backed by the Buckeye team.
Talk to the Buckeye team — the owner is involved in every engagement, and there’s no advisory fee.
Prefer to talk now? Call or text 614-224-2003.