
HHS proposed the first major overhaul of the HIPAA Security Rule since 2013 in a rule published on January 6, 2025. The comment period closed in March 2025, but the proposal has not been finalized. The latest Unified Agenda places it under long-term actions and projects final action for July 2027, after an earlier projection of May 2026. That date is an agency estimate, not a deadline, and it has already moved. For now, the current Security Rule remains in effect. The direction of travel is clear, but the final requirements and timing are not. (HHS; Unified Agenda, RIN 0945-AA22)
Most small healthcare practices have not read it. Many do not know it exists.
A defensible small-and-midsize-business benchmark comes from NetDiligence's 2025 Cyber Claims Study, which analyzed 10,402 insurance claims from incidents occurring between 2020 and 2024. Organizations under $2 billion in annual revenue made up 98% of the dataset. Their average total incident cost was $243,000 for 2024 events, compared with a five-year average of $264,000. Those figures describe insured claims across industries, not healthcare practices specifically, but they are a stronger benchmark than an unsupported small-practice estimate. (NetDiligence, 2025) Civil monetary penalties under the current schedule range from $145 per violation at the lowest tier to over $2.19 million per violation category per year at the willful-neglect-uncorrected tier.
A full-time CISO can command $200,000 or more per year in base salary, before bonus, equity, and benefits. Compensation varies substantially by company size, industry, and the scope of the role. (IANS and Artico Search, 2025 CISO Compensation Benchmark)
Most practice owners see those numbers, do the math, and quietly roll the dice. They have an EHR vendor, an MSP, a cyber insurance policy, and a HIPAA training module everyone clicked through last year. So, they move on.
That is the most expensive bet a healthcare owner can make in 2026.
I've spent more than 10 years building security and compliance programs, led multiple HITRUST certification engagements, and deployed Zero Trust architecture across a multi-state clinical operation. Before that, I sat in the CEO seat. I have watched the same pattern play out in small and mid-size healthcare practices for decades: smart owners, capable clinicians, decent IT support, and no one in the room who can turn a pile of tools into a defensible HIPAA program.
That is the actual gap. It is not technology. It is leadership.
The proposed rule would make a major structural change: it would remove the distinction between "required" and "addressable" implementation specifications and make all implementation specifications required, with specific, limited exceptions.
For two decades, the rule split safeguards into two buckets. Required meant you had to do it. Addressable meant you had to consider it and could document why it did not apply. That second bucket gave smaller practices a soft landing. Most of them used it to avoid doing the work.
If the rule is finalized substantially as proposed, that distinction would largely disappear.
Under the proposal, the following safeguards would become required for covered entities and business associates, subject to the specific exceptions and details in any final rule:
Many of these safeguards are established cybersecurity practices. Separately from the proposed rule, OCR has initiated the 2024-2025 HIPAA Audits. The program covers 50 covered entities and business associates and reviews selected Security Rule provisions most relevant to hacking and ransomware. HHS does not provide a March 2025 start date on its audit page. (HHS OCR HIPAA Audit Program)
For a small practice that has been getting by with an MSP, a firewall, and an annual HIPAA training video, this is not a tune-up. This is a structural lift.
Most small healthcare practices already own more security tools than they realize. EHR vendors have access controls. MSPs install endpoint protection. Cyber insurance carriers require MFA. The pieces are usually in place, somewhere, partially deployed, and largely undocumented.
What practices do not have is someone who can do the things tools cannot:
That function is what a Chief Information Security Officer does. And almost no practice under $20 million in revenue has one in-house. The math does not work at that size.
A fractional CISO, also called a virtual CISO or vCISO, provides senior cybersecurity and compliance leadership on a part-time basis. They typically support several organizations at once, which is what makes the economics work.
Instead of $200,000 or more per year in base salary for a full-time hire, a small healthcare practice can engage senior security leadership for a fraction of that. The right vCISO has actually run healthcare security programs, owned HIPAA and HITRUST work end to end, briefed boards, and managed real incidents. They are not a tool reseller in a consultant's jacket.
Fractional CFOs and fractional COOs have been a normal part of the SMB playbook for years. Fractional CISO services in healthcare are catching up, especially as the proposed Security Rule update raises the cybersecurity baseline under discussion. The model is not new. The buyer education is.
The proposed update would have especially significant implications for three small healthcare segments. Different settings, same underlying leadership problem.
A behavioral health group running on a cloud EHR, a telehealth platform, and a payroll system rarely has a dedicated IT lead, let alone a security function. The data they hold is among the most sensitive in healthcare: substance use treatment, custody-related records, minors in care, and court-ordered services. A breach in a behavioral health practice is not just an OCR event. It is a state attorney general event, a 42 CFR Part 2 event, and frequently a malpractice exposure. Cybersecurity for mental health clinics is one of the most underserved problems in healthcare today. The current Security Rule already applies regardless of practice size, and the proposal would raise the required baseline further.
Nobody publishes enforcement or attack data broken out by dental practice, so claims that dentistry is among the most targeted segments in healthcare cannot be sourced, and I am not going to make one. What can be sourced is where the large dental losses have actually landed: with the vendors and benefit administrators that aggregate the data. Dental benefits administrator DentaQuest notified more than 15 million individuals after a May 2026 breach, and the 2023 ransomware attack on Medicaid dental administrator MCNA exposed 8,923,662 records.
At the practice level the exposure is structural rather than statistical. Practice management systems, imaging archives, and patient databases sit on local servers or single-tenant cloud setups, often with weak backups and no segmentation between the front-desk machines and the clinical systems. If the proposal is finalized substantially as written, preparation for a dental practice would include MFA on the practice management system, encrypted imaging storage, a tested recovery plan, and a current, documented risk assessment. In my own assessment work, most dental offices have none of those, and a practice of five chairs does not have the cash reserves to sit out a two-week outage. That is my professional observation rather than a published figure.
Home health and hospice run the most distributed clinical workforce in healthcare. Field clinicians use personal phones, agency-issued tablets, point-of-care apps, and a sprawl of vendor-supplied tools to document care in patients' homes. The attack surface is enormous, mobile device management is usually incomplete, and the business associate ecosystem (scheduling, billing, hospice-specific EHRs, DME suppliers) is layered three or four deep. If finalized substantially as proposed, the update would require home health agencies and hospice providers to strengthen device controls, vendor oversight, and incident response capabilities. Most agencies are still treating it as an IT issue.
In every one of these segments, the practice owners I talk to understand the risk at some level. They just do not know where to start, and many have already been burned by vendors who sold them tools instead of outcomes.
If the HIPAA Security Rule is the regulatory pressure, cyber insurance is the operational one. Renewal questionnaires ask about MFA coverage, encryption, endpoint detection and response, backup testing, incident response plans, and named security leadership. Controls affect eligibility and access to competitive insurance capacity. Businesses that cannot substantiate their answers may face limited capacity, non-renewal, or restrictive terms, but there is no credible published basis for predicting a particular premium increase or discount.
Your cyber insurance broker is now the de facto enforcer of cybersecurity standards in small healthcare. If you do not have answers ready before your next renewal, the market will give them to you in the form of a price hike or a denial.
A fractional CISO engagement in a small healthcare practice typically starts with a HIPAA Risk Assessment: what exists, what is exposed, what matters most, and where the gaps are against the current Security Rule and the safeguards in the proposal. From that comes a prioritized roadmap. Not a wish list. A sequenced plan tied to business risk, payer requirements, and insurance renewal timing.
From there the work is unglamorous and high-leverage. Vendor reviews. Business associate agreements that actually get read. Tabletop exercises with the leadership team. HIPAA policies that match how the practice actually operates instead of a template downloaded from the internet. Quarterly briefings to the owner or board in business language. Documentation that holds up under an OCR investigation, a payer credentialing audit, or a Joint Commission survey.
The goal is not to turn a 30-person practice into a hospital security operation. It is to give that practice the leadership function it has been missing, before an incident, an audit, or an insurance renewal forces the issue at the worst possible time.
The proposal is not yet in force, but the current Security Rule remains enforceable. OCR's 2024-2025 HIPAA Audits are underway, cyber insurers already evaluate many of the controls highlighted in the proposal, and healthcare ransomware continues to disrupt operations. The Unified Agenda currently projects final action for July 2027, but that projection has moved before and may move again. Any final rule will establish its own compliance dates.
The practices that act now will be ready for their next audit, their next renewal, and their next clinical onboarding cycle. The practices that wait will be reading about themselves in a state attorney general press release.
At Cybersecurity Advisory Group, the healthcare clients I work with are not asking whether they have a cybersecurity problem. They know they do. They are asking who can actually run the program for them at a scale that fits a small practice. Owners who have been burned once or twice by vendors selling tools instead of outcomes are particularly fast to recognize the difference.
The fractional CISO model is the answer. It is here, it is affordable, and it works. The market just needs to catch up to the problem.
Connect with Melissa Thornton on LinkedIn
Updated September 2026 to correct the status of the proposed HIPAA Security Rule, replace an unsourced small-practice breach cost range and an unsourced premium-increase figure, correct the name of OCR’s audit program, and remove an unsourceable claim about ransomware targeting of dental practices.