Single Post

HIPAA Security Rule 2026: The Mandatory MFA Survival Guide for Small Offices

Published September 1, 2026 | For Michigan medical, dental, and vision practices

If you own or manage a small healthcare practice, multi-factor authentication is no longer a cybersecurity improvement you can keep postponing. It is becoming a baseline expectation from regulators, cyber insurance carriers, technology vendors, and patients who trust you with sensitive information.

However, begin with an important distinction: as of September 2026, the HIPAA Security Rule’s proposed MFA requirement has not been finalized. The current rule remains in effect. The U.S. Department of Health and Human Services (HHS) has proposed making MFA mandatory for access to systems containing electronic protected health information (ePHI), but the proposal is not yet enforceable as a final rule.

That distinction matters. It also does not mean your office should wait.

“The best time to prepare for a security requirement is before it becomes an emergency.”

This guide explains what the proposed HIPAA Security Rule 2026 MFA changes could mean for a small office, how to build a practical implementation plan, and which mistakes can create unnecessary compliance and insurance problems.

Start by understanding what is: and is not: required today

Use this section to separate current obligations from proposed changes.

The existing HIPAA Security Rule requires covered entities to use reasonable and appropriate safeguards based on their risk analysis. It also requires access controls and person or entity authentication. The current rule does not specifically name MFA as a mandatory control.

Still, MFA may be considered a reasonable and appropriate safeguard when your risk assessment identifies stolen credentials, remote access, phishing, or unauthorized account use as risks. In other words, while MFA is not explicitly required in the existing rule, failing to implement it may be difficult to justify in an environment where staff access ePHI through cloud systems, email, remote desktops, and mobile devices.

The proposed update would go further. According to the HHS HIPAA Security Rule NPRM fact sheet, the proposal would require MFA with limited exceptions. The official HHS NPRM page also makes clear that the current Security Rule remains in effect during the rulemaking process.

If finalized substantially as proposed, MFA would apply broadly to systems that create, receive, maintain, or transmit ePHI. For a small office, that could include:

  • Electronic health record and electronic medical record systems
  • Dental imaging and practice-management platforms
  • Billing and claims systems
  • Email and collaboration accounts
  • Cloud file storage and document-sharing tools
  • VPN, remote desktop, and remote support tools
  • Administrative consoles and privileged accounts
  • Vendor portals that provide access to patient information

Treat the proposed rule as a planning deadline rather than a reason to make unsupported legal claims. This approach helps you improve your security now while preserving flexibility as HHS finalizes the language and timeline.

Next, map every path to patient information

Use this step to identify where a mandatory MFA small office program must begin.

Many practices enable MFA for their EHR but overlook the email account used to reset EHR passwords. Others protect Microsoft 365 accounts but leave a remote desktop tool, billing portal, or vendor login exposed. Attackers look for precisely these gaps.

Create a simple access inventory. For every system, record:

  1. What information does the system store or access?
  2. Which employees, vendors, and administrators can log in?
  3. Can the system be accessed from outside the office?
  4. Is MFA available, and is it enforced for every user?
  5. Who owns the relationship with the vendor?
  6. Is a signed business associate agreement in place where required?

Pay special attention to accounts with elevated permissions. A compromised administrator account can allow an attacker to create new users, disable security controls, access backups, or move through multiple systems.

IT professionals monitoring cybersecurity and healthcare technology systems

This inventory should become part of your documented Security Risk Assessment. It also gives your IT provider a practical map for prioritizing remediation instead of attempting a disruptive, unplanned technology overhaul.

Follow a phased MFA rollout

Use this section as your implementation roadmap. A phased approach allows your team to improve protection without overwhelming clinical, administrative, or billing staff.

Phase one: Protect identity foundations

Begin with the accounts that control access to everything else:

  • Email and collaboration administrators
  • Microsoft 365, Google Workspace, or identity-provider administrators
  • Network and firewall administrators
  • Backup and security platforms
  • Remote support and remote access accounts

Require MFA for these accounts before expanding to general users. Prefer authenticator applications, passkeys, hardware security keys, or secure push notifications with number matching. SMS may be better than no MFA, but it is generally less resistant to phishing and telephone-number takeover.

At the same time, remove shared accounts wherever possible. Every employee should have an individual login so your office can identify who accessed a system and when.

Phase two: Secure daily clinical and business workflows

Move next to systems used throughout the workday:

  • EHR and practice-management platforms
  • Dental imaging or vision-care applications
  • Billing and payment systems
  • Cloud storage
  • Scheduling and patient communication tools
  • Remote access to office workstations

Coordinate with each vendor before switching on enforcement. Confirm that staff know how to enroll their devices, what to do when a phone is replaced, and how to report a suspicious authentication prompt.

Use this space to explain that MFA is not an extra password. It combines at least two different authentication factors:

  • Something you know: a password or passphrase
  • Something you have: a phone, authenticator app, security key, or token
  • Something you are: a fingerprint or other biometric

Two passwords do not count as two independent factors. Make that distinction part of staff training.

Healthcare practice manager enrolling a secure authenticator app

Phase three: Extend controls to vendors and exceptions

Do not stop once employees are enrolled. Review third-party access, including EHR support teams, billing companies, managed service providers, and equipment vendors.

Require vendors to use individual accounts and MFA wherever their platforms support it. Remove access when a contract ends, an employee leaves, or a support relationship changes.

If a legacy medical device or specialized application cannot support MFA, document the limitation. Record the compensating controls, the business justification, the vendor’s upgrade plan, and the person responsible for reviewing the exception. A documented exception is not the same as ignoring the problem.

As you move toward full coverage, test your emergency or “break-glass” procedures. Your office needs a secure way to restore access during a device failure or clinical emergency without creating a permanent, unmanaged back door.

Avoid the most common small-office mistakes

Use these warnings as a final quality check before you declare the project complete.

Mistake one: Protecting only the EHR

Email, cloud storage, remote access, and administrative systems can expose the same patient information. MFA must follow the data, not simply the application name.

Mistake two: Enabling MFA without documenting it

Update your policies, risk assessment, employee onboarding materials, and incident response procedures. Record which systems are covered, which exceptions remain, and how often access is reviewed.

Mistake three: Using one shared authenticator device

Shared phones, shared administrator accounts, and universal recovery codes make accountability difficult. Issue individual credentials and establish a controlled recovery process.

Mistake four: Approving every push notification

Train staff to reject unexpected prompts and report them. Push fatigue attacks can succeed when users approve a request simply to make the notification disappear.

Mistake five: Forgetting cyber insurance requirements

Cyber insurance applications increasingly ask whether MFA is enforced on email, remote access, privileged accounts, and backups. Answer accurately. A checkbox that says “MFA enabled” may not reflect whether MFA is required for every user and every relevant access path.

Strong MFA is only one part of an insurable security program. Review your backups, patching, endpoint protection, logging, employee training, and incident response plan as well.

Build a compliance-ready plan for your Michigan practice

Use the next 60 to 90 days to turn MFA from a vague concern into a measurable program.

During the first two weeks, complete your system inventory, identify all ePHI access paths, review administrative accounts, and confirm your business associate agreements.

During weeks three through six, enforce MFA on email, administrator accounts, remote access, EHR systems, billing platforms, and cloud storage. Train staff by role and document every implementation decision.

During the final weeks, review vendor access, test account recovery, verify backup protection, close unnecessary accounts, and prepare evidence for your next cyber insurance application or renewal.

Michigan practices should also review MFA requirements for state services. The Michigan Department of Health and Human Services HIPAA resources provide additional information, and the MILogin MFA job aid explains authentication options used with Michigan systems.

If your practice does not have the internal time or expertise to manage this process, ClearPath360’s managed IT services can help you assess access, coordinate vendor requirements, implement MFA, and maintain the systems after deployment. Our cybersecurity solutions are designed around proactive protection, documented controls, and clear communication.

“Compliance is not a document you complete once. It is a system you maintain so your team can keep serving patients with confidence.”

The HIPAA Security Rule 2026 MFA proposal may change before it becomes final. Your responsibility today is more practical: know where ePHI can be accessed, reduce unnecessary exposure, and make strong authentication the normal way your practice operates.

That preparation can help protect patient trust, strengthen your cyber insurance position, and give your office a clearer path when the final rule arrives. Contact ClearPath360 to discuss a practical MFA and HIPAA security readiness plan for your Michigan practice.

This article is for general educational purposes and is not legal or regulatory advice. Confirm final requirements with qualified HIPAA counsel and monitor official HHS guidance for rule updates.

Help Desk Chat
Scroll to Top