top of page
Search

What Independent Medical Practices in Palm Beach County Need to Know About HIPAA in 2026


If you run an independent medical practice in Palm Beach County, 2026 is not a year to be casual about HIPAA compliance. The regulatory landscape has shifted more significantly in the past 18 months than it did in the previous decade — and most independent practices are behind.


I've been doing healthcare IT in Palm Beach Gardens for 25 years, working exclusively with dental and medical practices across Palm Beach, Martin, and St. Lucie counties. What I'm seeing in 2026 is a compliance gap that is wider than it has ever been — not because practice owners don't care, but because the rules changed faster than most practices had time to respond.


Here's what changed, what it means for your practice, and what you need to have in place right now.


What changed in 2026


The HHS Office for Civil Rights finalized significant updates to the HIPAA Security Rule that took effect in 2026. These updates represent the most substantial revision to the Security Rule since it was originally implemented in 2003.


The most consequential change is the elimination of the distinction between "required" and "addressable" safeguards. Under the original Security Rule, certain technical safeguards were labeled "addressable" — meaning practices could choose not to implement them if they documented a reasonable alternative. In practice, many practices and their IT providers used this flexibility to skip inconvenient or expensive safeguards without penalty.


That flexibility is gone. Nearly all security measures that were previously addressable are now effectively mandatory. For independent medical practices in Palm Beach County, this means that safeguards your IT provider may have characterized as optional in previous years — encryption of data at rest, automatic logoff, audit controls — are now required without qualification.


The second major change is increased specificity around risk analysis requirements. The updated rule requires practices to document their risk analysis with significantly more detail than previously expected — including specific identification of all systems that store, process, or transmit ePHI, documented threat and vulnerability assessments, and evidence of how identified risks are being addressed on an ongoing basis.


The third change is increased enforcement activity. HHS OCR has signaled clearly that independent practices are a priority enforcement target in 2026 — not because they're the biggest violators, but because they represent the largest gap between regulatory requirements and actual compliance posture in the healthcare market.


What this means for your practice specifically


Independent medical practices in Palm Beach County are disproportionately affected by these changes for several reasons.


First, most independent practices have been operating under IT arrangements that were designed for the old regulatory environment. If your IT provider set up your systems more than two years ago and hasn't conducted a formal HIPAA risk assessment since, your compliance posture reflects requirements that no longer exist. What was acceptable in 2023 may be a violation in 2026.


Second, independent practices typically have more vendor relationships touching patient data than they realize. Your EMR vendor, your billing service, your patient communication platform, your scheduling software, your cloud storage provider, your IT company — every one of these relationships requires a current, signed Business Associate Agreement. Under the updated rule, BAAs themselves must now reflect the updated security requirements. BAAs signed before 2024 may need to be reviewed and updated.


Third, cyber insurance carriers have accelerated their own requirements in parallel with the regulatory changes. Many Palm Beach County practices are discovering that their cyber insurance policies now require documented evidence of specific security controls — MFA, endpoint protection, backup testing, and risk assessments — before claims will be paid. Practices that cannot produce this documentation are finding their claims denied at exactly the moment they need coverage most.


The five things your practice needs to have in place right now


1. A current, documented HIPAA risk assessment.


Not the one your IT provider completed during onboarding three years ago. A current one — conducted within the past 12 months, documented with the specificity the updated rule requires, and updated to reflect any changes in your technology environment since the last assessment.


The risk assessment is the foundation of your entire compliance program. Every other safeguard flows from it — because the risk assessment identifies what risks exist, and the safeguards address those risks. A practice that hasn't updated its risk assessment since the rule changed is building its compliance program on an outdated foundation.


2. Encryption on all devices that store or transmit ePHI.


Under the updated rule, encryption is effectively mandatory for all ePHI — at rest on your servers and workstations, and in transit across your network and to cloud systems. This includes devices you may not have considered part of your ePHI environment — tablets used for patient intake forms, laptops used by physicians who work from multiple locations, and mobile devices used to access your EMR remotely.

Ask your IT provider specifically: which devices in our environment store or transmit ePHI, and which of those are encrypted? If they can't answer that question precisely, your encryption posture is unknown — which means it's likely insufficient.


3. Multi-factor authentication on all systems that access ePHI.


MFA is no longer optional for any system that accesses patient data. This includes your EMR, your billing platform, your email system, and any remote access tools your staff or IT provider uses to connect to your network. Single-factor authentication — a username and password alone — does not meet the updated standard.


The most common vulnerability I find in independent medical practices is remote access without MFA. Physicians and staff who access the EMR from home or from a mobile device using only a password represent a significant, unaddressed breach risk. A single compromised password is all an attacker needs to access your entire patient record system.


4. Audit controls — specifically, a SIEM.


The updated rule's requirement for audit controls is now explicit: you must have mechanisms that record and examine activity in systems containing ePHI, and those records must be retained and producible for an investigation.


In practice, this means a Security Information and Event Management system — a SIEM — that collects logs from across your environment continuously and retains them for the required period. Without a SIEM, your IT provider cannot produce the audit trail OCR investigators request first when they investigate a breach. This is one of the most common gaps I find in independent medical practices, and it's one of the most consequential — because it's the gap that turns a manageable incident into a regulatory crisis.


5. Current BAAs with every vendor.


Review every vendor relationship that involves access to your patient data and confirm that a current, signed BAA is in place. Then review the BAAs themselves — specifically whether they reflect the updated security requirements from the 2026 rule changes. BAAs that predate the updates may need to be renegotiated.


This review should include vendors you may not have historically thought of as healthcare vendors — your cloud storage provider, your patient communication platform, your practice management software company, and your IT provider. All of them are business associates if they access, store, or transmit ePHI.


What the enforcement environment actually looks like in 2026


OCR's enforcement activity in 2026 has followed a pattern worth understanding. Investigations are no longer triggered exclusively by large breaches affecting hundreds of thousands of patients. Smaller practices are increasingly the subject of enforcement actions — triggered by patient complaints, small breaches that require notification, and random audits.


The most common findings in enforcement actions against independent practices are consistent: inadequate risk analysis, missing or outdated BAAs, lack of audit controls, and failure to implement the technical safeguards required by the Security Rule. These are exactly the gaps that the 2026 rule changes were designed to address — which means practices that haven't updated their compliance posture are at elevated risk of exactly the violations OCR is now actively looking for.


The financial exposure is significant. HIPAA penalties range from $100 to $50,000 per violation, with an annual cap of $1.9 million per violation category. A single investigation finding multiple violations across multiple categories can generate penalties that threaten the financial viability of an independent practice — particularly one that also faces the operational disruption of a breach or ransomware event at the same time.


The compliance posture independent practices in Palm Beach County should have


Let me be direct about what a properly compliant independent medical practice in Palm Beach County should have in place right now — and what you should be asking your IT provider to confirm.


A current HIPAA risk assessment completed within the past 12 months, documented with system-level specificity. Encryption on all devices and in all data transmission. MFA on every system that accesses ePHI. A SIEM providing continuous audit logging retained for the required period. Current BAAs with every vendor that touches patient data.


Written security policies that your staff has been trained on, with documentation of that training. An incident response plan that identifies what happens in the first 24 hours after a breach is detected. And a backup and recovery system that has been tested — not just configured.


If you're not sure whether your practice has all of these in place, that uncertainty is itself the answer. A practice with a properly built compliance program knows it. A practice that's unsure has gaps.


Where to start


If you're an independent medical practice in Palm Beach County and you're not certain your compliance posture reflects the 2026 HIPAA Security Rule updates, the right starting point is an objective assessment of where you actually stand.


Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It covers your security and compliance posture across six categories — access controls, device security, data protection, network security, HIPAA compliance, and vendor risk — and produces a written summary with prioritized recommendations. Yours to keep with no obligation.


Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.


Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.

 
 
bottom of page