Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Regulatory tracker

What is law. What is not. Dated.

There is a lot of confidently wrong information in this market, and most of it comes from vendors who benefit from the confusion. This page separates what is enforceable today from what is a proposal with a target date in 2027.

Last reviewed July 15, 2026 Reviewed by Compliance Manager, CHPS Cadence Monthly, and on material change
The correction we make most often

MFA is not currently required by the HIPAA Security Rule.

The rule that would mandate it was published as a proposed rule on January 6, 2025 and has not been finalized. HHS moved it to the Long-Term Actions agenda with a target final-action date of July 2027. Anyone telling you otherwise is wrong, and a sharp compliance officer will catch it.

The honest framing is stronger anyway. These controls are already required by your cyber insurance carrier, already demanded by health-system security questionnaires, and already the thing OCR settlements turn on. We will not sign a client who refuses to enforce MFA — not because a rule says so, but because it is the control that most often decides whether a claim gets paid.

Timeline

Most recent first.

Each entry says what it is, what its status is, and what we would actually do about it. Items marked as proposed are not law and are labelled that way everywhere they appear on this site.

April 23, 2026 Enforcement expanding HHS Office for Civil Rights

Four simultaneous ransomware settlements, totalling $1,165,000

Across more than 427,000 individuals, each with a two-year corrective action plan. One of the four, Consociate Health, was a business associate: a third-party benefits administrator.

What to do OCR will penalize a business associate directly, regardless of size. If you are a billing company, an RCM firm, or a third-party administrator, this settlement is about you.

February 16, 2026 Enforcement expanding 42 CFR Part 2

42 CFR Part 2 full compliance deadline and civil enforcement

The full compliance deadline for the revised Part 2 rule hit, and OCR launched a Civil Enforcement Program the same month. Part 2 previously carried criminal penalties only and was effectively unenforced. It now carries HIPAA-style civil monetary penalties.

What to do This is a brand-new, real liability for every behavioral health and substance use disorder provider, and virtually no generalist IT company has heard of it. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA, not instead of it.

February 11, 2026 Enforcement expanding ASTP/ONC

Information blocking enforcement began

ASTP/ONC began issuing letters of nonconformity. Developers and health information exchanges face civil monetary penalties up to $1,000,000 per violation. Providers face disincentives instead: a zero in the MIPS Promoting Interoperability category, or a 75% reduction in the hospital market basket increase.

What to do The IT-adjacent exposure is real and under-discussed. A practice that cannot produce electronic health information because of a botched migration or an unrestorable backup has an information-blocking problem on top of a HIPAA one.

January 28, 2026 In force 45 CFR §160.404

Civil monetary penalty tiers adjusted

Tier 1, lack of knowledge: $145 to $73,011 per violation. Tier 4, willful neglect uncorrected: $73,011 to $2,190,294 per violation. The annual cap is $2,190,294 per provision.

What to do Note that the cap is per provision, not per organization. A finding that spans the risk analysis requirement and the audit controls requirement is two provisions.

October 2, 2025 In force 10 NYCRR §405.46

New York hospital cybersecurity regulation fully effective

Mandatory CISO, mandatory MFA, annual risk assessment, and 72-hour incident reporting. It applies to New York hospitals, not to Tennessee practices — we list it because it is the template other states are copying, and because it is a preview of where the federal rule is heading.

What to do Not applicable to our clients today. Worth watching if you operate across state lines.

March 31, 2025 In force PCI Security Standards Council

PCI DSS 4.0.1 future-dated requirements became mandatory

The 51 future-dated requirements are now in force. What actually bites a clinic: universal MFA into the cardholder data environment, a 12-character minimum password length, script inventory and change-detection on payment pages under requirements 6.4.3 and 11.6.1, and full-disk encryption no longer being sufficient on its own.

What to do Requirement 6.4.3 catches every online bill-pay page and every iframed portal payment. If you take a card on your website, this applies to you.

Published January 6, 2025 Proposed, not final RIN 0945-AA22

The HIPAA Security Rule overhaul is proposed. It is not law.

The notice of proposed rulemaking would mandate MFA, mandate encryption at rest and in transit, require annual penetration testing and semiannual vulnerability scanning, require asset inventories and network maps, and require 72-hour data restoration. The comment period closed March 7, 2025 with roughly 4,745 comments. More than 100 hospital systems and provider associations petitioned HHS to withdraw it. HHS has moved it to the Long-Term Actions agenda with a target final-action date of July 2027.

What to do Anyone who tells you MFA is now required by HIPAA is wrong, and a sharp compliance officer will catch it. The honest framing is stronger anyway: these controls are already required by your cyber insurance carrier, already demanded by health-system security questionnaires, and already the thing OCR settlements turn on. The rule will eventually catch up to what your underwriter has required since 2023.

October 2024, expanded 2026 In force HHS Office for Civil Rights

OCR Risk Analysis Initiative

Thirteen completed investigations and nineteen completed ransomware-breach investigations as of April 2026. Sixteen resolution agreements were announced between January and August 2025 citing failure to conduct an accurate and thorough risk analysis. OCR Director Paula Stannard has confirmed the initiative expands in 2026 to cover risk management, not just risk analysis.

What to do A completed risk analysis with no dated, evidenced remediation plan is now its own exposure. The plan is the newer half of the requirement and the one most often missing.

January 5, 2021 In force P.L. 116-321 / HITECH §13412

Recognized Security Practices, HITECH amendment

If a regulated entity can demonstrate it had Recognized Security Practices in place enterprise-wide for at least the previous 12 months, OCR must consider that as a mitigating factor: reduced penalties, narrower investigation scope, and shorter corrective action plan terms. Qualifying practices include NIST-derived standards (CSF, SP 800-53, SP 800-171) and HICP / §405(d) practices.

What to do This is a statutory discount that costs nothing but twelve months of disciplined recordkeeping, and almost no small organization has the documentation to claim it. We build the attestation as a standing artifact.

2003, amended 2013 In force 45 CFR Part 164, Subpart C

The HIPAA Security Rule as it exists today

Fully in force. There is no size exemption and there never has been. Every administrative, physical, and technical safeguard applies to a fifteen-person practice exactly as it applies to a health system. The difference is enforcement attention, not obligation.

What to do If you cannot produce a current risk analysis and a dated risk management plan, this is where to start.

Sources

Go and check us.

Everything on this page is traceable to a primary source. We are not linking to a summary of a summary, and we would rather you verified it than took our word for it.

This page is written for practice administrators and compliance officers and is not legal advice. Where a decision turns on a specific fact pattern, involve counsel — and if you do not have healthcare counsel, ask us and we will name three.

Keeping current

We update this page, not a newsletter you have to join.

It is reviewed monthly and carries a date. If something material changes between reviews, it goes up the week it happens.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.