The 2026 HIPAA Security Rule is still a proposal. There is no deadline on your calendar, and any vendor implying otherwise is selling urgency that does not exist. What does exist is a federal enforcement campaign that has been settling with practices, including small ones, over a requirement that is already years old. This post is the 90-day HIPAA plan for dealing with that: what to do, in what order, and why.
It is the third piece in our HIPAA series. The 2026 Security Rule explainer covers what the proposal would change and where it actually stands. The MFA and encryption post covers the two technical controls that move first. This one turns all of it into a sequence you can run while still seeing patients.
You do not need a compliance project. You need 90 days of ordered work, and most of it lives inside tools you already pay for.
Why Run A 90-Day HIPAA Plan Around A Rule That Is Not Final?
Because the plan barely depends on the new rule. Almost everything in it is either already required, like the written security risk analysis, or already basic sound practice, like MFA and tested backups. The proposed 2026 Security Rule just tells you where enforcement is heading. The work protects you either way.
Here is the part that is not proposed. The Office for Civil Rights has been running a dedicated enforcement campaign around the security risk analysis since late 2024 and has closed more than a dozen cases under it. The pattern repeats: a breach or ransomware event, an investigation, no documented risk analysis on file, then a settlement plus a corrective action plan that runs two to three years with progress reports to the federal government. Settlements have ranged from around ten thousand dollars to several hundred thousand. Small practices have not been exempt, and the multi-year oversight usually costs more in time and disruption than the check does.
So the plan below front-loads the one thing the government already fines practices for, then closes the gaps attackers actually use, then makes it durable. Ninety days, three phases, no panic buying.
Days 1 To 30: Where Does Your Practice Actually Stand?
The first month is diagnosis, not spending. Get a real written risk analysis moving, build an inventory of every device and system that touches patient data, and pull every business associate agreement you can find. You cannot fix gaps you have not named, and OCR only credits what is documented.
Days 31 To 60: Which Gaps Get Closed First?
The ones attackers actually use. Turn on MFA for every account that touches patient data, verify full-disk encryption on every device, kill shared logins, and test that your backups restore. For most small practices this is configuration work inside licenses you already pay for, not a new purchase.
Days 61 To 90: How Do You Make It Stick?
By writing it down and giving it a rhythm. Train staff on the basics, put short written policies behind the controls you turned on, write a first-hour incident plan with names and phone numbers, and set a simple review cadence so none of this decays by December.
What If You Do Not Have Time To Run This Yourself?
Then do not run it alone, but do not skip it either. The diagnosis month is the part practices stall on, and it is the part with the most enforcement weight. That is the exact gap a fixed-fee risk analysis closes: your real gaps, named and prioritized, in order.
The plan above is generic by necessity. The version for your specific practice, with your actual risks found, documented, and put in priority order, is exactly what TidalPath's fixed-fee Risk Analysis produces. It is the first 30 days of this plan done for you, with the next 60 already sequenced, and it is the same document OCR asks for first.
Two ways to get a read on where you stand today:
Serving small medical practices across Nassau and Suffolk County, Long Island.
