HIPAA Security Rule Compliance for Miami Pediatric Practices

The HIPAA Security Rule you’re required to comply with today is still the version finalized in the 2013 Omnibus Rule — not the sweeping overhaul that’s been making headlines since January 2025. In its Fall 2026 Unified Agenda, HHS moved the proposed Security Rule update to its Long-Term Actions list, pushing the anticipated final rule to July 2027 (Clark Hill law firm alert; HIPAA Journal). That’s a meaningful delay from the May 2026 target HHS had originally set — but it does not mean pediatric practices can wait. The current rule is being enforced aggressively, and OCR’s own data shows the single most common failure driving settlements has nothing to do with the proposed changes at all.

The Quick Answer

Under the current HIPAA Security Rule (in effect since 2013), your pediatric practice must maintain administrative, physical, and technical safeguards for electronic protected health information (ePHI), built around an accurate, documented Security Risk Analysis. A sweeping proposed update — mandatory encryption, mandatory multi-factor authentication, eliminating the “addressable” safeguard category, and more — has been delayed to an anticipated July 2027 final rule (Clark Hill). That delay doesn’t reduce your risk today: OCR closed 21 enforcement actions in 2025 totaling roughly $8.3 million, its second-highest annual count on record, and its dedicated Risk Analysis Initiative — launched specifically to find practices that skipped this one requirement — has already produced multiple settlements against small providers (HIPAA enforcement data via HIPAA Journal).

Where the HIPAA Security Rule Actually Stands in 2026

Here’s the timeline, because a lot of what’s circulating online conflates “proposed” with “in effect”:

  • December 27, 2024 — OCR announces its intent to modify the Security Rule (HHS OCR fact sheet)
  • January 6, 2025 — The Notice of Proposed Rulemaking (NPRM) is formally published in the Federal Register (90 FR 898)
  • March 7, 2025 — The public comment period closes after drawing nearly 5,000 comments from healthcare organizations, many opposing the scope and cost of compliance
  • May 2026 — HHS’s original target date for a final rule passes with nothing published
  • Mid-to-late 2026 — HHS’s Fall Unified Agenda moves the rule to its Long-Term Actions list, setting a new anticipated final action date of July 2027

A coalition led by the College of Healthcare Information Management Executives (CHIME), representing more than 100 hospital and provider groups, formally petitioned HHS to withdraw or significantly narrow the proposal, citing underestimated compliance costs — particularly for smaller, under-resourced practices (reporting via multiple industry trade sources tracking the NPRM’s Unified Agenda status). That pushback is a real factor in the delay.

What the HIPAA Security Rule Requires Today

The current rule — unchanged since the 2013 Omnibus Rule — organizes requirements into three categories of safeguards under 45 CFR §§164.302–318:

Safeguard CategoryWhat It CoversExamples
AdministrativePolicies, workforce training, risk managementSecurity Risk Analysis, designated Security Officer, workforce HIPAA training, sanction policy for violations
PhysicalFacility and device access controlsLocked server rooms, workstation placement, device and media disposal procedures
TechnicalSystems and data protectionAccess controls, audit logs, transmission security, integrity controls

The Security Risk Analysis requirement appears twice in HIPAA’s Administrative Simplification provisions — once in the Security Rule itself (45 CFR §164.308, Security Management Process) and again in the Breach Notification Rule (45 CFR §164.402) — requiring “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI” (HIPAA Journal Security Risk Assessment guide).

What Changes If the Proposed Rule Is Finalized

Even delayed to 2027, the direction of travel is clear, and practices that get ahead of it now avoid a compressed compliance scramble later:

RequirementToday (Current Rule)Proposed (Delayed to 2027)
Encryption of ePHI“Addressable” — can be substituted with an equivalent alternativeMandatory, with only narrow, defined exceptions
Multi-factor authenticationNot explicitly requiredMandatory for systems accessing ePHI
“Addressable” vs. “Required” specificationsDistinction exists — addressable items allow flexibilityDistinction eliminated — nearly everything becomes required
System restoration after an attackGeneral contingency planning requiredWritten procedures to restore critical systems within 72 hours
Technology asset inventory & network mapNot explicitly requiredRequired, updated at least every 12 months and after major changes
Penetration testingNot explicitly requiredAnnual penetration testing plus regular vulnerability scanning
Network segmentationNot explicitly requiredRequired
Business associate breach notificationStandard Breach Notification Rule timelinesBusiness associates must notify covered entities within 24 hours of activating contingency plans

(Compiled from the HHS OCR NPRM fact sheet and multiple legal/compliance summaries tracking the rule: HHS.gov, AAMC, HIPAA Journal.)

If finalized as proposed, the rule takes effect 60 days after Federal Register publication, with a 180-day compliance window after that — a total of roughly 240 days from publication to mandatory compliance. Even at a 2027 final-rule date, that’s a real, foreseeable deadline, not a hypothetical one.

OCR Is Already Enforcing the Current Rule Aggressively

The proposed rule getting delayed doesn’t mean HIPAA enforcement is quiet. If anything, current-rule enforcement has picked up:

  • OCR closed 21 enforcement actions in 2025 for roughly $8.3 million — its second-highest annual enforcement count on record (HIPAA Journal enforcement data)
  • The Risk Analysis Initiative, launched in October 2024, targets entities specifically for never having completed a compliant Security Risk Analysis — the single most common documentation failure OCR finds
  • The Right of Access Initiative had produced 54 enforcement actions by May 2025, with penalties ranging from $3,500 for a solo dental practice up to $240,000 for a hospital system
  • There is no small-practice exemption. A solo or small pediatric practice is held to the same Security Rule requirements as a hospital system — the size of your practice affects the size of a likely penalty, not whether the rule applies to you
  • Hacking now drives roughly 9 out of 10 reported healthcare breaches, and the largest stated 2025 OCR settlement — $3,000,000 against Solara Medical Supplies — stemmed from a phishing attack

2026 HIPAA Civil Monetary Penalty Tiers

Penalty amounts are adjusted annually for inflation. As of the most recent update (Federal Register, January 28, 2026):

TierLevel of CulpabilityMinimum per ViolationMaximum per ViolationAnnual Cap
Tier 1Reasonable efforts made$145$73,011$2,190,294
Tier 2Lack of oversight$1,461$73,011$2,190,294
Tier 3Willful neglect, corrected within 30 days$14,602$73,011$2,190,294
Tier 4Willful neglect, not corrected$73,011$73,011$2,190,294

(Source: HIPAA Journal, HIPAA Violation Fines — Updated for 2026)

For context on how this plays out for small practices specifically, settlements involving practices with fewer than 25 employees have ranged from $10,000–$25,000 for those that self-reported and cooperated fully, up to $100,000–$500,000 for practices with significant documentation failures across multiple categories — including an April 2025 settlement where a missing risk analysis, tied to a breach originally reported in 2020, resulted in a $350,000 penalty.

What This Means Specifically for Pediatric Practices

Pediatric practices carry a few compliance wrinkles general adult-medicine practices don’t:

  • Parental access rules shift with the patient’s age. For most adult patients, the patient controls access to their own record. For pediatric patients, access rights depend on the minor’s age, applicable state law, and the type of service being delivered — emancipated-minor and mature-minor exceptions for sensitive services (like reproductive health or mental health) can restrict a parent’s access even though they’re the legal guardian. Your Security Risk Analysis and access control policies need to model this correctly, not default to “parent = record holder” in every case.
  • Immunization registry reporting creates an additional data flow to inventory. Every state operates an Immunization Information System (IIS), and federal Vaccines for Children (VFC) program participation — which most pediatric practices rely on — requires reporting VFC-administered doses to that state system. That data flow, and whichever business associate or interface vendor handles the transmission, needs to be inventoried and covered by a signed Business Associate Agreement (BAA).
  • The FERPA-HIPAA boundary moves the moment a record reaches a school. Health records maintained by a school nurse or district can shift from HIPAA to FERPA governance. When your practice shares immunization or health records with a school system, that handoff point needs to be understood and documented, not assumed.
  • Every vendor touching patient data needs a current BAA. Patient portals, appointment-reminder services, billing clearinghouses, and any EHR interface vendor are all potential business associates. A HIPAA Security Risk Analysis that doesn’t inventory every one of these relationships is incomplete by definition — and an incomplete risk analysis is exactly what OCR’s Risk Analysis Initiative is built to find.

The Requirement Almost Every Small Practice Gets Wrong

If there’s one pattern across nearly every OCR settlement involving a small provider, it’s this: the Security Risk Analysis either was never done, was done once years ago and never updated, or wasn’t accurate and thorough enough to count.

Two real examples make the pattern concrete:

Top of the World Treatment Center, a small addiction treatment provider, agreed to pay a $103,000 penalty in 2026 specifically to resolve an alleged violation of the risk analysis requirement under the HIPAA Security Rule — one of at least 11 OCR settlements to date centered specifically on this single requirement.

Northeast Radiology settled for $350,000 in April 2025, opened by a 2020 breach report affecting 298,532 patients, and resolved specifically around a missing risk analysis — five years after the underlying breach occurred.

The lesson from both: a risk analysis isn’t a one-time compliance box to check when you open your practice. It needs to be current, accurate, and revisited at least annually — and OCR is actively looking for practices where it isn’t.

Checklist: HIPAA Security Rule Compliance for Pediatric Practices

  • Confirm a Security Risk Analysis has been performed and is less than 12 months old
  • Designate a HIPAA Security Officer and Privacy Officer by name, in writing
  • Confirm signed Business Associate Agreements are on file for every vendor touching ePHI — EHR, patient portal, appointment reminders, billing clearinghouse, and IIS/vaccine registry interface
  • Review access control policies for how they handle minor patients, parental access exceptions, and mature-minor/emancipated-minor scenarios under your state’s law
  • Confirm workforce HIPAA training is current and documented for all staff, not just clinical staff
  • Review audit logging for systems that access ePHI, including the EHR and patient portal
  • Confirm domain authentication (SPF, DKIM, DMARC) is in place, given phishing’s role in the majority of reported breaches
  • Begin evaluating current encryption and multi-factor authentication status now, ahead of the anticipated 2027 requirement
  • Document a sanction policy for workforce members who violate HIPAA policies
  • Confirm a documented contingency plan and data backup/restoration procedure exists and has been tested

Getting Ahead of the Proposed 2027 Changes Now

Even with the final rule delayed, the direction is clear enough that waiting until 2027 to start is a mistake:

  • Start MFA rollout now. Multi-factor authentication is trending toward baseline requirement across every industry, not just healthcare — implementing it ahead of a mandate avoids a rushed, error-prone rollout under deadline pressure.
  • Audit current encryption status. Identify every system storing or transmitting ePHI that isn’t currently encrypted at rest or in transit, and build a remediation plan now rather than during a compressed 240-day compliance window.
  • Build a technology asset inventory and network map today. Even though not yet formally required, this is genuinely useful for your current risk analysis and puts you ahead of one of the most operationally demanding proposed requirements.
  • Treat “addressable” safeguards as required going forward. The proposed rule eliminates this distinction entirely — practices currently leaning on the addressable category to justify gaps should close those gaps now rather than waiting for a mandate to force the issue.

A Real Scenario: Risk Analysis Gap at a Growing Practice

A pediatric practice in Miami-Dade County had completed a Security Risk Analysis when the practice first opened five years earlier, but never updated it — despite adding a patient portal, switching EHR vendors twice, and adding two satellite locations in that time. When a routine OCR compliance review followed a patient complaint about record access, the practice couldn’t produce a current risk analysis reflecting its actual technology environment. The original analysis didn’t cover the patient portal, the new EHR vendor’s data flows, or the additional locations — meaning it no longer represented an “accurate and thorough” assessment of the practice’s actual risks, regardless of how thorough it had been five years earlier.

This is the exact failure pattern behind the Northeast Radiology and Top of the World Treatment Center settlements: not a single dramatic breach, but a risk analysis that quietly went stale while the practice’s technology environment kept changing around it.

How ITva Helps Pediatric Practices Stay HIPAA Compliant

We build HIPAA compliance into our managed IT service for pediatric practices as an ongoing process, not a one-time document:

  • Annual Security Risk Analysis reviews that account for every system change — new EHR modules, added locations, new vendors — not a static document that goes stale
  • Business Associate Agreement tracking across every vendor touching ePHI, including patient portals, appointment reminders, and immunization registry interfaces
  • Domain authentication (SPF, DKIM, DMARC) and encryption audits to close the exact gaps phishing and hacking exploit
  • HIPAA compliance expertise specific to pediatric practices, including the parental access and minor-consent nuances general IT providers often miss
  • 24/7 SOC monitoring and a 3.5-minute average ticket response time, so security incidents are caught and contained fast
  • No long-term contracts and a 90-day satisfaction guarantee

Frequently Asked Questions

Is the new HIPAA Security Rule already in effect?

No. The proposed update was published as a Notice of Proposed Rulemaking on January 6, 2025, and remains unfinalized. HHS moved its anticipated final rule date to July 2027 in its Fall 2026 Unified Agenda. The current rule — unchanged since 2013 — is what your practice must comply with today.

What’s the single biggest HIPAA compliance mistake pediatric practices make?

Never completing a Security Risk Analysis, or completing one years ago and never updating it as the practice’s technology environment changes. This is the failure behind OCR’s dedicated Risk Analysis Initiative and behind the majority of small-practice settlements.

Does HIPAA apply differently to a small pediatric practice than a hospital?

No. There is no small-practice exemption under the HIPAA Security Rule. Practice size affects the likely size of a penalty, not whether the requirements apply.

What will the proposed 2027 rule require that isn’t required today?

Mandatory encryption of ePHI at rest and in transit, mandatory multi-factor authentication, elimination of the “addressable” safeguard category, a technology asset inventory and network map, annual penetration testing, network segmentation, and 72-hour system restoration procedures after a cyberattack.

How does HIPAA handle parental access to a pediatric patient’s records?

It depends on the minor’s age, applicable state law, and the type of service delivered. Emancipated-minor and mature-minor exceptions for certain sensitive services can restrict parental access even when the parent is the legal guardian, which pediatric practices need to reflect accurately in their access control policies.

What should a pediatric practice do right now, given the rule delay to 2027?

Confirm a current, accurate Security Risk Analysis is on file, close any gaps currently justified under the “addressable” safeguard category, and begin auditing encryption and multi-factor authentication now rather than waiting for a mandate.

Get a Free HIPAA Compliance Assessment

Not sure whether your practice’s Security Risk Analysis is current and accurate? Book a free assessment and we’ll review where your compliance actually stands against both today’s requirements and the proposed 2027 changes. Or call us directly at (305) 629-5925.