MenuClose Menu

Is your dental practice prepped for the upcoming HIPAA Rule changes?

July 28, 2026
77
CDA Endorsed Services logo next to Abyde's logo, above text that reads "HIPAA"
QUICK SUMMARY: Updates to the HIPAA Security Rule have been proposed, meaning stricter and more comprehensive compliance standards. Iyou’re unsure if your practice has up-to-date and accurate documentation, business associate agreements, Security Risk Analysis and established protocols, you may be at risk when the changes go into effect. Abyde, a CDA Endorsed Services partner, shares what actions to take now. 

What’s changing with HIPAA?

The U.S. Department of Health and Human Services proposed significant updates to the HIPAA Security Rule in 2025—the first major revision in over two decades. These proposed changes include mandatory vulnerability scanning, stricter encryption standards, multi-factor authentication and 72-hour system restoration timelines after an incident. Most of what HHS has proposed isn’t new in principle; rather, it formalizes protocols that practices are already expected to adhere to.  

The final ruling on these proposed changes is currently slated for July 2027. This means that if your current HIPAA procedures for the dental practice are lacking, you’ll be at risk of noncompliance when the new changes become official, and you will face more potential costs for having to catch up in short time.  

Where does your HIPAA compliance stand now? Let’s check. 

While the final rule hasn’t been published yet, it’s not too soon to assess where your current HIPAA compliance stands. Ask yourself these questions: 

  • Is your Security Risk Analysis current, complete and specific to your practice? 
  • Is workforce HIPAA training documented and up to date for every staff member? 
  • Do you have current, signed business associate agreements with every vendor who handles patient data? 
  • Are your policies and procedures in writing, practice-specific and reviewed within the last year? 
  • Do you know every device in your practice that stores or accesses patient data (computers, tablets, phones)? 
  • Is patient data encrypted on those devices when it’s being transmitted or stored? 
  • Does every dental team member have their own unique login? 
  • Are your systems receiving regular software and security updates? 
  • Could you produce evidence of all the above within 24 hours if the Office for Civil Rights contacted you

If your answer to any of those questions is no or I’m not sure, it’s crucial to address gaps in your current HIPAA compliance ahead of the upcoming proposed changes. 

Where do the gaps in HIPAA compliance usually show up?

A current, compliant HIPAA program is a dynamic thing, not a one-time project. Here are a few areas where practices most often fall short: 

Security Risk Analysis

Update your practice’s Security Risk Analysis every 12 months or whenever your technology, staffing or locations change significantly to ensure it remains current, practice-specific and thorough. Even practices that have completed an assessment or analysis have learned that it didn’t qualify during an investigation. 

Workforce training

All training must be documented—not just when it happened but also what was covered. New hires, role changes and policy updates all create training obligations that many practices don’t track consistently. 

Policies and procedures

Generic templates with your name on them are unlikely to hold up under scrutiny. Your policies need to reflect how your practice actually operates and should be reviewed often and as things change. 

Business associate agreements

Every vendor who touches patient data needs a signed business associate agreement (CDA has a BAA for members). Refusing to provide a signed BAA is grounds for ending your professional relationship with that vendor.  

Incident response

A documented response plan is already required under existing HIPAA regulations, but the proposed changes are expected to be significantly stricter when it comes to the speed and specificity of response plans. Ensure that your response plan is clear, detailed and accurate. 

California dental practices should take note: patients can sue directly for violations without waiting on federal regulators. The state runs its own medical privacy law (the Confidentiality of Medical Information Act), and in some areas it’s stricter than HIPAA. Getting your HIPAA fundamentals in order is still the first and most important step, but there are state-level obligations worth a separate look once the basics are covered. 

Now is the time to update your HIPAA compliance 

HHS will announce the compliance deadline when the proposed HIPAA changes are finalized in July 2027. In past rulemakings, that window has been around 180 days. Six months may sound manageable, but a practice without existing HIPAA programs may struggle to make the necessary changes in that timeframe.  

Practices that navigate the proposed changes the most successfully will be the ones that treated compliance as a living program, kept it current and arrived at the new rules with the fundamentals already in place. 

  

Abyde is a CDA Endorsed Services partner and provides HIPAA compliance software for independent and group dental and medical practices. This article is intended for educational purposes and does not constitute legal advice. 

Feedback

Was this resource helpful?

Sign up for text updates from CDA