Degarmo Technologies
Veteran-owned MSSP · Est. 2018
Healthcare & medical practices

The Security Rule rewrite is coming. Not yet, but it is coming.

HHS proposed the first major HIPAA Security Rule overhaul in two decades in January 2025. It is still not final — the target has slipped to 2027. That gap is the most useful thing a practice can be given, and most are spending it doing nothing.

What is proposed, and what is not law

Nobody is enforcing this yet. That is exactly why now is cheap.

The proposed rule was published in January 2025 and the comment period closed that March. The final rule is not issued; the published target has moved out to 2027. Anyone telling you these requirements are in force today is wrong, and we would rather you heard that from us.

What the proposal signals is the direction: multi-factor authentication for access to ePHI, encryption at rest and in transit, a maintained technology asset inventory and network map, vulnerability scanning at least every six months, penetration testing annually, and data restoration within 72 hours. Those are not exotic. They are the controls a practice should have regardless of what the Federal Register eventually says.

The honest reason to start now

Practices that wait for a final rule will implement under a deadline, at whatever the market charges when every practice in the country needs the same work in the same quarter. Practices that start now spread it over budget cycles and negotiate.

And the more immediate point: ransomware is not waiting for the rule. Small practices are targeted precisely because they hold highly sensitive data, run lean IT, and cannot afford downtime. MFA and tested backups are worth doing on Monday whether or not the Security Rule is ever finalised in the form proposed.

What we do for practices

Aimed at the controls that keep coming up.

01

Security risk analysis

The assessment the current Security Rule already requires and the proposal strengthens — done properly, documented, and kept current.

02

MFA and access control

Multi-factor on ePHI access, role-based permissions, and clean joiner-mover-leaver handling for clinical staff.

03

Encryption at rest and in transit

Devices, servers and email — configured and evidenced, not assumed.

04

Asset inventory and network map

Maintained rather than rebuilt annually. You cannot protect or evidence what nobody has listed.

05

Backup and 72-hour recovery

Tested restores against a defined recovery objective, with restoration priorities set by clinical criticality.

06

Vulnerability scanning and testing

Scanning on a schedule and annual testing, with the findings actually worked rather than filed.

How we work with practices

Clinical hours do not pause for IT.

A practice cannot take a maintenance window at ten on a Tuesday. Downtime is measured in patients not seen, and the EHR is not something staff can work around. Our founder has spent years working in and around this industry, and the support model reflects it.

We are also clear about our boundaries: we sign business associate agreements, we work alongside your EHR vendor rather than claiming to replace them, and we will tell you when something is the vendor's responsibility rather than billing you to work around it.

Work around the schedule

Patching and maintenance planned around clinic hours, not imposed on them.

BAA and vendor coordination

Business associate agreements in place, and a working relationship with your EHR and imaging vendors.

Documentation that survives audit

Risk analyses, policies and evidence kept current, so a request does not become a fire drill.

Next step

Start with the risk analysis you already owe.

The current Security Rule already requires a security risk analysis, and most practices we meet either have not done one or have one that predates half their technology. That is where we start — and it is the same document the proposed rule will expect you to have been maintaining all along.