false
OasisLMS
Login
Catalog
HIPAA Under the Microscope: Security Rule Updates
Webinar Recording
Webinar Recording
Back to course
[Please upgrade your browser to play this video content]
Video Transcription
Video Summary
TJ Blackman of TASPAC discussed proposed 2026 HIPAA Security Rule changes and what they could mean for dental offices. He explained that the rule is still proposed and may change, but the direction is clear: stronger, more mandatory cybersecurity requirements.<br /><br />Key changes include removing the current flexibility around “addressable” safeguards and making protections like multi-factor authentication, encryption, and stronger documentation mandatory. MFA would apply broadly, including remote access, cloud systems, email, admin accounts, and on-site workstations. Encryption would be required for data at rest and in transit, including backups, laptops, cloud storage, and file transfers.<br /><br />Other major proposals include stronger network segmentation, especially for guest Wi-Fi, cameras, IoT devices, and office equipment; regular vulnerability scanning and annual penetration testing; more robust backup and disaster recovery planning with air-gapped, encrypted backups; asset inventory and network mapping; updated vendor oversight and BAAs; and much faster breach notification, likely within 24 hours instead of 60 days.<br /><br />TJ emphasized that healthcare remains a major target for cyberattacks and ransomware. His advice: start asking vendors whether they are preparing for the changes, but avoid rushing into expensive upgrades until the final rule is clearer.
Keywords
HIPAA Security Rule
2026 proposed changes
dental office cybersecurity
multi-factor authentication
data encryption
network segmentation
vulnerability scanning
breach notification
×
Please select your language
1
English