No, HIPAA does not require MFA and encryption yet. The 2026 Security Rule that would make both mandatory is still proposed, not law, and OCR has not finalized it. But encryption and MFA are where enforcement is already heading, and for most small practices the work is configuration you can finish this month, not a big spend.
Does HIPAA Require MFA And Encryption Right Now?
Not strictly. Under the Security Rule that is in effect today, encryption of patient data and multi-factor authentication are both "addressable," not "required."
Addressable does not mean optional. It means you either implement the safeguard, put an equivalent alternative in place, or document in writing why it is not reasonable and appropriate for your practice. In a real OCR investigation, an unencrypted laptop with no documented justification is treated as a problem, not a loophole.
Two plain definitions before we go further. Encryption scrambles data so it is unreadable without the key, whether it is sitting on a drive or moving across the internet. MFA means a password alone is not enough to log in; a second factor, like a prompt on your phone, is also required.
One thing is already flatly required today: a security risk analysis. It is the most frequently cited deficiency in OCR investigations, and OCR has publicly widened its focus from finding risks to proving you did something about them. If your practice has not done a real risk analysis in the last year, that is the gap to close first, rule change or not. Here is what a real security risk analysis actually includes and how a small practice gets one done.
What Would Change If The 2026 Rule Is Finalized?
It would make encryption and MFA required, with limited exceptions, and erase the "addressable versus required" distinction entirely.
The proposed rule was published as a Notice of Proposed Rulemaking at 90 FR 800 on January 6, 2025. It would require encryption of patient data both at rest and in transit and MFA on systems that access that data. Every implementation specification that is "addressable" today would become mandatory. There are limited, risk-based exceptions, but the default flips from flexible to prescriptive.
Here is the honest status as of mid-2026: this is still a proposal, not law. The public comment period closed March 7, 2025. OCR received roughly 4,700 comments and is still working through them. The regulatory agenda targeted a final rule for spring 2026, that window passed with nothing published, and more than 100 hospital and provider groups have asked HHS to withdraw the proposal outright. There is no live deadline today because there is no final rule.
If OCR does finalize it close to as written, covered entities would get 240 days from publication to comply, about eight months. That is enough time only if you start the groundwork before any final rule lands. For the full picture of every change the proposal would bring, see our 2026 HIPAA Security Rule explainer.
There is no live HIPAA deadline for MFA and encryption today. There is a clear direction of travel, and a short runway if the rule lands.
What Does Encryption Actually Cover If We Use Microsoft 365?
Three places, and Microsoft 365 already handles most of the first one for you.
One blunt clarification, because it trips up a lot of offices: a signed BAA does not make you compliant. Microsoft secures the platform. Configuration, access control, and documentation are on you. That split is the whole reason this is configuration work, not a purchase.
What Should A Small Practice Do About MFA Today?
Turn it on for every account that touches patient data, and start with admin accounts.
Admin accounts are the keys to the whole tenant, so they go first. Then every clinical and front-desk account that touches email, the EMR login, or anything connected to patient data. The exceptions in the proposal are narrow, so plan to cover everyone rather than hunting for outs.
The objection you will hear from staff is that MFA is annoying. It does not have to be. With Conditional Access in Microsoft Entra ID, you can require a second factor when someone signs in from a new device or an unusual location, and skip the prompt on a trusted office machine. Done right, most staff see a prompt rarely, and an attacker with a stolen password still gets stopped. That is the entire point: stronger security without a daily tax on your team.
If you want this set up and documented properly instead of half-on, that is exactly the kind of work our HIPAA IT support covers.
What Does This Actually Cost A Small Office?
Less than most owners expect. Most of it is already included in what you are paying for.
If you are on Microsoft 365 Business Premium or a comparable Google Workspace plan, encryption at rest and in transit, MFA, Conditional Access, and message encryption are already in the license. BitLocker and FileVault are built into Windows and Mac at no charge. The real cost is time: configuring it correctly, turning it on for everyone, and writing down what you did so you can show it later.
The one place money can come up is the plan itself. If your office is on Microsoft 365 Business Basic, you may need to move up to Business Premium to get the compliance tooling, which is a modest per-user increase, not a capital project. The expensive path is not doing this. A single breach of unencrypted data carries notification costs and OCR exposure, and in New York the SHIELD Act adds its own data-security obligations on top.
What Should We Do This Month, Regardless Of The Rule?
Six things, none of which require waiting for OCR.
None of this depends on whether the 2026 rule is finalized this year. It is reasonable security for a medical or dental practice in 2026, and it is the same work you would have to do anyway if the rule lands. If you would rather hand the whole thing off, this is the day-to-day of our healthcare IT support.
These six steps are the middle of a bigger sequence. The 90-day HIPAA plan covers what comes before them and what locks them in afterward.
Not sure where your practice actually stands? PracticeReady walks you through it in about ten minutes and gives you a risk score and a prioritized list, no phone call required.
Frequently Asked Questions
No. As of mid-2026 it is still a proposed rule. The NPRM was published at 90 FR 800 on January 6, 2025, comments closed March 7, 2025, and OCR has not issued a final rule. The current Security Rule remains in effect.
Because OCR is already enforcing in this direction under the current rule, and because encrypted data changes your breach math. If a lost device or stolen data is properly encrypted, it generally is not a reportable breach. That protection exists today.
No. A signed BAA, plus an eligible plan, plus correct configuration supports compliance. The technology alone does not. Microsoft secures the platform; access, configuration, and documentation are your responsibility.
It does not have to. With Conditional Access, you can skip the prompt on trusted office devices and require a second factor only on new devices or unusual sign-ins. Most staff rarely see it.
If finalized close to as proposed, covered entities would get 240 days from publication, roughly eight months. That is not a deadline today, because there is no final rule. It is the runway you would have if one lands.
Serving small medical practices across Nassau and Suffolk County, Long Island.
