The 90-Day HIPAA Get-Ready Plan for Small Practices

The 2026 HIPAA Security Rule is still a proposal. There is no deadline on your calendar, and any vendor implying otherwise is selling urgency that does not exist. What does exist is a federal enforcement campaign that has been settling with practices, including small ones, over a requirement that is already years old. This post is the 90-day HIPAA plan for dealing with that: what to do, in what order, and why.

It is the third piece in our HIPAA series. The 2026 Security Rule explainer covers what the proposal would change and where it actually stands. The MFA and encryption post covers the two technical controls that move first. This one turns all of it into a sequence you can run while still seeing patients.

You do not need a compliance project. You need 90 days of ordered work, and most of it lives inside tools you already pay for.

Why Run A 90-Day HIPAA Plan Around A Rule That Is Not Final?

Because the plan barely depends on the new rule. Almost everything in it is either already required, like the written security risk analysis, or already basic sound practice, like MFA and tested backups. The proposed 2026 Security Rule just tells you where enforcement is heading. The work protects you either way.

Here is the part that is not proposed. The Office for Civil Rights has been running a dedicated enforcement campaign around the security risk analysis since late 2024 and has closed more than a dozen cases under it. The pattern repeats: a breach or ransomware event, an investigation, no documented risk analysis on file, then a settlement plus a corrective action plan that runs two to three years with progress reports to the federal government. Settlements have ranged from around ten thousand dollars to several hundred thousand. Small practices have not been exempt, and the multi-year oversight usually costs more in time and disruption than the check does.

So the plan below front-loads the one thing the government already fines practices for, then closes the gaps attackers actually use, then makes it durable. Ninety days, three phases, no panic buying.

Days 1 To 30: Where Does Your Practice Actually Stand?

The first month is diagnosis, not spending. Get a real written risk analysis moving, build an inventory of every device and system that touches patient data, and pull every business associate agreement you can find. You cannot fix gaps you have not named, and OCR only credits what is documented.

Start the written security risk analysis. Not a checklist someone filled out once and filed. A current document that names your actual risks and what you are doing about each one. This is already required, it is the single most common failure OCR finds, and it is what the enforcement pattern in the pillar post turns on. If you have one, check the date. Older than a year, refresh it.
Build the inventory. Every computer, laptop, tablet, server, and phone that touches patient data, plus every system and vendor: EMR, email, billing, patient texting, fax, backup. You cannot analyze risk on assets you have not listed, and the proposed rule would make this inventory mandatory anyway. Doing it now is not wasted work under any outcome. Tablets are the devices most often missing from that inventory. Here is why that happens and what to do about it.
Run the BAA sweep. Match that vendor list against the signed business associate agreements you actually have on file. Every vendor that touches patient data needs one. A missing BAA is one of the easiest findings for an investigator and one of the cheapest fixes for you. Close those gaps on paper before you spend a dollar on anything technical.

Days 31 To 60: Which Gaps Get Closed First?

The ones attackers actually use. Turn on MFA for every account that touches patient data, verify full-disk encryption on every device, kill shared logins, and test that your backups restore. For most small practices this is configuration work inside licenses you already pay for, not a new purchase.

Turn on MFA everywhere patient data lives. Admin accounts first, because they are the keys to everything, then every staff account that touches email, the EMR, or anything connected to patient data. Set up with conditional access, most staff rarely see a prompt and a stolen password stops working as a master key. The MFA and encryption post walks through the setup and the cost, which for most offices is close to zero.
Verify encryption on every device. BitLocker on Windows, FileVault on Mac, on every laptop and workstation that touches patient data, and confirm your Microsoft 365 or Google Workspace plan is HIPAA-eligible with a BAA in place. A lost encrypted laptop is a non-event. A lost unencrypted one can be a reportable breach.
Kill shared logins. One login per person, including the generic front-desk account everyone knows the password to. If you cannot tell who did what, you cannot investigate an incident, you cannot offboard someone cleanly, and an auditor will notice in about five minutes.
Test a restore, not a backup. "The backup ran" is not the same as "the data comes back." Pick a real file or folder, restore it, and time how long it takes. The only backup that counts is one you have watched come back before you were depending on it.

Days 61 To 90: How Do You Make It Stick?

By writing it down and giving it a rhythm. Train staff on the basics, put short written policies behind the controls you turned on, write a first-hour incident plan with names and phone numbers, and set a simple review cadence so none of this decays by December.

Train staff on the basics. Short and real: spotting phishing, using MFA, what not to send over regular email, who to tell when something looks wrong. Then record who attended and when. Documentation is the difference between "we trained everyone" and being able to prove it.
Put short written policies behind the controls. Access, offboarding, device use, email handling. A page each is fine. Policies that match what your office actually does beat a 60-page binder nobody has opened since it was purchased.
Write the first-hour incident plan. Who gets called, in what order, with phone numbers, on paper somewhere staff can find it. The first hour of a ransomware event is a terrible time to figure out who your IT contact is.
Set the review rhythm. Once a quarter: new devices on the inventory, departed staff fully offboarded, new vendors checked for BAAs, one restore tested, risk analysis still accurate. This is also a fair test of whoever handles your IT. If they cannot produce this documentation, that tells you something worth knowing.

What If You Do Not Have Time To Run This Yourself?

Then do not run it alone, but do not skip it either. The diagnosis month is the part practices stall on, and it is the part with the most enforcement weight. That is the exact gap a fixed-fee risk analysis closes: your real gaps, named and prioritized, in order.

The plan above is generic by necessity. The version for your specific practice, with your actual risks found, documented, and put in priority order, is exactly what TidalPath's fixed-fee Risk Analysis produces. It is the first 30 days of this plan done for you, with the next 60 already sequenced, and it is the same document OCR asks for first.

Two ways to get a read on where you stand today:

Serving small medical practices across Nassau and Suffolk County, Long Island.