Skip to content
Artwork for HIPAA Insider
HIPAA Insider · May 20 · 13 min

HIPAA Rules Just Changed: Security Is No Longer Optional

The 2026 HIPAA Rule Updates: From “Addressable” to Required HIPAA compliance is entering a new phase—and “optional” security measures are quickly disappearing. In this episode of the HIPAA Insider Show, Adam Z. and cloud security expert Gil Vidals break down the major HIPAA Security Rule updates shaping healthcare compliance in 2026. As regulators push key safeguards from “addressable” to REQUIRED, healthcare organizations of all sizes must rethink how they approach security, infrastructure, and risk management. We discuss: What HIPAA changes are already active Which requirements are still pending New mandatory encryption expectations The proposed 12-month penetration testing requirements Why MFA and stronger safeguards are becoming essential How smaller healthcare organizations can stay compliant without enterprise-level budgets This episode provides a practical look at how providers, MSPs, and health-tech teams can prepare for the next era of healthcare cybersecurity and compliance. Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

0:00-13:20

transcript

No transcript — this publisher did not publish one.

show notes

The 2026 HIPAA Rule Updates: From “Addressable” to Required

HIPAA compliance is entering a new phase—and “optional” security measures are quickly disappearing.

In this episode of the HIPAA Insider Show, Adam Z. and cloud security expert Gil Vidals break down the major HIPAA Security Rule updates shaping healthcare compliance in 2026.

As regulators push key safeguards from “addressable” to REQUIRED, healthcare organizations of all sizes must rethink how they approach security, infrastructure, and risk management.

We discuss:

  • What HIPAA changes are already active
  • Which requirements are still pending
  • New mandatory encryption expectations
  • The proposed 12-month penetration testing requirements
  • Why MFA and stronger safeguards are becoming essential
  • How smaller healthcare organizations can stay compliant without enterprise-level budgets

This episode provides a practical look at how providers, MSPs, and health-tech teams can prepare for the next era of healthcare cybersecurity and compliance.



Learn more about HIPAA Vault:
https://www.hipaavault.com/

Become a guest on the HIPAA Insider Show:
https://www.hipaavault.com/podcast-guest/

links2