Last reviewed: August 13, 2026. This page tracks the regulatory status of the HIPAA Security Rule as it affects dental practices. It is deliberately narrow: current requirements, proposed changes, and what practices can reasonably do now. For the evergreen explanation of safeguards and dental IT architecture, see the HIPAA-compliant dental IT guide.
Regulatory status can change after any given review date. Verify the current position directly with the primary sources linked below before making compliance decisions, and treat legal interpretation as work for qualified counsel.
Current Requirements
The HIPAA Security Rule in force today requires covered entities, including dental practices, to implement administrative, technical, and physical safeguards for electronic protected health information (ePHI). Its core obligations — risk analysis and risk management, workforce training and sanctions, access control and unique user identification, audit controls, integrity controls, transmission security, contingency planning, and Business Associate Agreements — remain the operative standard.
Primary sources:
Nothing described in the "proposed changes" section below replaces these requirements.
Proposed Changes (Proposed — Not Final)
On December 27, 2024, the HHS Office for Civil Rights announced a Notice of Proposed Rulemaking (NPRM) to update the HIPAA Security Rule, with official publication in the Federal Register on January 6, 2025. It was the first substantial proposed overhaul of the Security Rule in over a decade.
This is a proposed rule. Proposals published for comment are not law, may be modified before any final rule is issued, and may not be adopted at all. Do not treat the items below as current requirements or as deadlines.
Primary sources for the proposal:
- Federal Register: HIPAA Security Rule NPRM (January 6, 2025)
- HHS: HIPAA Security Rule NPRM — HHS states that the current Security Rule remains in effect while this rulemaking proceeds.
- HHS OCR HIPAA newsroom and rulemaking updates
Themes in the proposal that drew the most attention from healthcare providers include:
- Reducing the distinction between "required" and "addressable" implementation specifications.
- More prescriptive expectations around asset inventories and network mapping for systems that handle ePHI.
- Explicit expectations for multi-factor authentication, encryption of ePHI at rest and in transit, and vulnerability management.
- Stronger, more specific contingency planning and restoration expectations.
- Increased documentation and verification expectations involving business associates.
The final scope of any of these depends entirely on whether and how a final rule is issued. Check the Federal Register entry above for the current disposition rather than relying on this summary.
What Dental Practices Can Do Now
The practical answer is that most of the proposal's themes are already good practice under the existing rule, so preparation does not require betting on a regulatory outcome:
- Maintain a current, documented risk analysis and a risk management plan that follows from it.
- Keep an accurate inventory of systems and devices that create, receive, store, or transmit ePHI, including cloud services and imaging archives.
- Enforce multi-factor authentication on email, remote access, cloud systems, and administrative accounts.
- Encrypt ePHI at rest and in transit, including laptops, portable media, backups, and transfers to labs and specialists.
- Test restores from backup and document the results, not just backup job success.
- Keep Business Associate Agreements signed, complete, and retrievable.
- Log and retain system activity so access can be reviewed after the fact.
Each of these is covered as an actionable task, with owner and evidence, in the HIPAA compliance checklist for dental practices. The documentation side is covered in HIPAA audit preparation, and the failure patterns worth closing first are in common HIPAA violations.
If you want the technical controls implemented, monitored, and documented for your practice, that is what our HIPAA compliance service does. We support the technology side of your program; we do not provide legal advice, and no provider can certify a practice as HIPAA compliant.
Frequently Asked Questions
Is the updated HIPAA Security Rule in effect?
As of this page's last-reviewed date, the December 2024 NPRM published on January 6, 2025 is a proposed rule. Proposed rules are not current law. Confirm the present status through the Federal Register entry and HHS OCR before acting on it.
What would the proposed HIPAA Security Rule change?
The proposal addressed themes including reducing addressable specifications, asset inventories and network mapping, multi-factor authentication, encryption, vulnerability management, contingency planning, and business associate verification. The final content of any rule depends on the rulemaking outcome.
What should a dental practice do while the rule is pending?
Focus on requirements that already apply: a current risk analysis, an accurate ePHI system inventory, MFA, encryption, tested backups, signed BAAs, and retained audit logs.
Where can I verify the current regulatory status?
Use the Federal Register document for the proposed rule and the HHS Office for Civil Rights Security Rule pages linked above. Both are primary sources and reflect the current position.

