Blog · Compliance

HIPAA Security Rule updates and what they mean for clinic email

Proposed Security Rule changes raise the bar on technical safeguards. Practices that still run PHI through consumer mail will feel it first.

Security Rule conversations in Washington change timelines, but the direction is consistent: more specificity on encryption, multi-factor access, asset inventory, and the ability to restore operations after an incident. "We use TLS sometimes" will not read as a program.

Email, fax, and forms are in scope

Electronic PHI is electronic PHI whether it is a message, a TIFF from a fax server, or a form submission. If your risk analysis pretends those channels are "just communication," the analysis is incomplete.

A practice-sized response

  • Name the systems that create or transmit ePHI.
  • Require unique logins and MFA on those systems.
  • Turn on audit logs you can actually export.
  • Execute BAAs before go-live, not after a letter from OCR.

HIPAA Companion is already aligned with that list for physician offices: encrypted email and fax, logged form submissions, and a BAA on every plan. Use the product as part of the program, then write down the procedures so the technology is not the only control.