HIPAA Is Changing in 2026: What Every Oklahoma Business Handling Patient Data Needs to Know

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

February 9, 2026 11 min read
Share:
HIPAA Changes 2026

If your organization stores, transmits, or processes protected health information (PHI), 2026 is shaping up to be the most consequential year for HIPAA compliance in over a decade. The Department of Health and Human Services (HHS) has finalized major updates to the Privacy Rule and proposed a sweeping overhaul of the Security Rule, the first significant revision since the Security Rule was originally introduced in 2003.

These aren’t incremental tweaks. They represent a fundamental shift in how the federal government expects healthcare organizations, business associates, and any covered entity to protect electronic protected health information (ePHI). And several of these changes carry hard deadlines that are already on the calendar.

I’ve been working in healthcare IT for the better part of three decades. HIPAA was signed into law in 1996, and for most of my career it was a framework with a lot of “reasonable and appropriate” flexibility baked in. That flexibility is what allowed so many small Oklahoma practices to survive a compliance audit on the strength of a binder full of policies and a handshake promise that the network was “secured.” In 2026, that era ends. HIPAA didn’t really grow teeth until this year, and the bite is going to be felt in every dental office, medical group, behavioral health clinic, and business associate in the state.

Here’s a detailed breakdown of what’s changing, when it takes effect, and what your Oklahoma organization should be doing right now to prepare.

The February 16, 2026 Deadline: Privacy Rule and Part 2 Updates

The first major compliance milestone is already here. By February 16, 2026, all HIPAA-covered entities must update their Notices of Privacy Practices (NPPs) to comply with the finalized changes to the HIPAA Privacy Rule and the revised 42 CFR Part 2 regulations governing substance use disorder (SUD) treatment records.

The Part 2 final rule, published in February 2024, aligns SUD patient records more closely with HIPAA while preserving heightened protections for this sensitive information. Under the updated framework, covered entities must clearly explain to patients how SUD records may be used and disclosed, including the specific limitations that go beyond standard HIPAA requirements.

Critically, this requirement doesn’t apply only to traditional SUD treatment programs. Any covered entity that receives or maintains Part 2 records, including through integrated care models, health information exchanges, or care coordination arrangements, must update their NPP. Many Oklahoma organizations don’t realize they fall under this obligation until they take a closer look at the data flowing through their systems.

Additionally, signed attestations are now required for certain non-treatment PHI disclosures, confirming that requested information will not be used to investigate or penalize individuals for seeking lawful reproductive health services or SUD treatment.

The HIPAA Security Rule Overhaul: The Biggest Change in 20 Years

On January 6, 2025, HHS published a Notice of Proposed Rulemaking (NPRM) detailing what would be the most extensive update to the HIPAA Security Rule since it was first enacted. HHS has indicated it expects to finalize the rule in 2026, with compliance deadlines likely set at six to twelve months after publication. Some provisions may shift between the proposed and final versions, so any compliance plan should be built with enough flexibility to absorb last-minute changes.

That said, the direction is clear. The proposed changes will affect every covered entity and business associate regardless of size. Here are the most impactful provisions in the NPRM as published.

No More “Addressable” Safeguards

This is arguably the single most consequential change. Under the current Security Rule, certain safeguards are classified as “addressable,” meaning organizations can document a justification for not implementing them if they determine the safeguard isn’t reasonable or appropriate for their environment. The proposed rule eliminates this distinction entirely. All safeguards become mandatory, with only very limited, formally documented exceptions tied to specific risk-based justifications. Documentation without implementation will no longer pass an audit.

Mandatory Multi-Factor Authentication (MFA)

MFA will be required for virtually every scenario where someone accesses ePHI, not just remote access but internal access as well. This includes EHR systems, patient portals, administrative accounts, and any system that creates, receives, maintains, or transmits ePHI. Any exceptions must be formally documented with a specific, risk-based justification, and blanket approvals will not be accepted.

Required Encryption for All ePHI

Encryption of ePHI both at rest and in transit is expected to move from “addressable” to explicitly required. Encryption must meet recognized security practices such as NIST standards (SP 800-111 for data at rest, SP 800-52 for data in transit) or FIPS 140-3 validated algorithms. Organizations must be able to demonstrate not just that encryption exists, but that it’s properly implemented and managed with appropriate key management and access controls.

Asset Inventory and Network Mapping

Every organization would be required to maintain a comprehensive, up-to-date inventory of all technology assets that process, store, or transmit ePHI. This includes a network map documenting how ePHI flows between internal systems and external partners, updated at least annually or after any significant environmental or operational change. Ad-hoc system deployments and informal server builds will no longer be acceptable.

24-Hour Breach Reporting for Business Associates

The proposed rule tightens breach notification timelines dramatically. Business associates would be required to report security incidents to covered entities within 24 hours of discovery. This change is designed to compress the response window and ensure covered entities can take immediate action to contain threats across their vendor ecosystem.

Annual Compliance Audits and Incident Response Testing

Covered entities would be expected to conduct formal compliance audits every 12 months, with business associates required to share audit results with all of their covered entity clients. Organizations would also need to maintain written incident response plans and test them annually. The proposed rule further calls for the ability to restore critical electronic systems and ePHI within 72 hours of a cyber incident.

Enhanced Business Associate Agreements

Business Associate Agreements (BAAs) would no longer be able to rely on generic compliance language. The updated requirements call for BAAs to include specific cybersecurity provisions, including MFA, encryption, incident reporting timelines, vulnerability scanning, penetration testing requirements, and alignment with NIST-recognized security practices. Covered entities would also need to obtain annual written verification that their business associates have actually implemented the required technical safeguards.

Why This Matters in Oklahoma Right Now

Oklahoma isn’t a spectator in this shift. Our healthcare sector has already lived through one of the largest breaches in state history. Integris Health confirmed a cyberattack affecting roughly 2.4 million patients, with stolen data used to directly extort individuals in the weeks that followed. If you want the full operational breakdown of that event and the lessons every Oklahoma practice should take from it, we wrote about it in detail in our post on the Integris Health data breach.

Integris wasn’t a one-off. The University of Oklahoma was hit. Smaller clinics and dental practices across the state have quietly dealt with ransomware events that never made the news. For a sector-wide look at why hospitals and healthcare organizations keep getting hit, our hospital ransomware lessons post walks through the pattern.

On top of the federal changes, Oklahoma’s own breach notification framework is tightening. Practices need to be prepared to notify affected residents and, in some cases, the Attorney General under shorter timelines than they may be used to. When you stack the federal Security Rule overhaul on top of state-level changes on top of rising ransomware activity in the state, 2026 is the year the cost of staying on the old path goes up sharply.

What the New Rules Actually Mean for a Small Oklahoma Practice

Most of the coverage of HIPAA 2026 has been written with hospital systems in mind. But the majority of covered entities in Oklahoma aren’t hospitals. They’re five-dentist practices, ten-provider medical groups, independent behavioral health clinics, chiropractors, physical therapy offices, and the business associates that support them. Those organizations are the ones most exposed to the shift from “addressable” to “required.”

In practical terms, here’s what the new environment looks like for a typical small practice.

Your “addressable” exceptions are gone. If your current Security Rule documentation has language along the lines of “encryption is not reasonable for our environment because…” you need to assume that reasoning will no longer stand. Plan for encryption at rest on every workstation, every server, every backup target, and every mobile device, and encryption in transit for every connection that touches ePHI.

Every login that touches a patient record needs MFA. Not just the VPN. Not just remote access. The EHR, the practice management system, the email account that receives patient intake forms, the cloud admin consoles, the backup portal. If a password by itself opens a door, that door will not pass an audit.

You need a real asset inventory. Not a spreadsheet someone made two years ago. A living list of every device and application that touches ePHI, tied to a network diagram showing how the data flows. For a lot of small practices this will be the first time they have ever actually mapped it.

Risk analysis moves from “set it and forget it” to an annual exercise. If your last risk analysis is dated four years ago, that gap becomes very hard to defend. Build the calendar entry now.

You need a written, tested incident response plan. When I sit with a small practice owner for the first time, I usually ask what happens if the front desk computer gets ransomware at 7:30 a.m. on a Monday. The answer is almost always a long pause. In 2026, “we’d figure it out” is not an answer a regulator will accept. The plan has to be written, the people have to have rehearsed it, and the backups have to be proven restorable.

Your BAAs need real teeth. The boilerplate BAAs your vendors handed you five years ago won’t cut it. You’ll need provisions on MFA, encryption, incident reporting windows, and written annual attestation that your business associates have actually implemented controls. This includes your billing company, your transcription service, your IT provider, your cloud backup vendor, and any SaaS tool that holds ePHI.

What Brian Tells Oklahoma Dental and Medical Clients

ArcLight has worked very heavily in healthcare since 2008. Dental practices, medical groups, specialty clinics, behavioral health. It’s one of our core focus areas, and HIPAA is the rule set that runs through all of it. Here is the short version of what I tell a practice owner when they ask how to get ready for 2026.

First, stop thinking about HIPAA as a paperwork exercise. For years, the game in some corners of the industry was “have a binder, have a policy, hope nobody looks too closely.” The 2026 rules are written specifically to close that gap. If your safeguards only exist on paper, you’re not compliant. You’re exposed.

Second, assign a real HIPAA compliance officer, even if it’s a part-time internal role or an outsourced function. Someone has to own the annual risk analysis, the policy updates, the training log, and the incident response plan. When that role is “everyone and no one,” nothing gets done.

Third, pick a partner who has actually done this in Oklahoma. Healthcare IT isn’t generic IT with a HIPAA sticker on it. The workflows, the EHR integrations, the state breach notification rules, the cyber insurance underwriting requirements, they all move together. We lay out our full approach on our healthcare IT services page, and the specific version for dental groups on our dental office IT support page.

Steps You Should Take Now

Regardless of where your organization stands today, there are concrete steps you can take right now to prepare for the 2026 HIPAA changes.

Conduct a HIPAA gap analysis. Assess your current security controls against the proposed requirements. Identify gaps in MFA, encryption, asset inventory, and incident response planning before the rule is finalized.

Update your Notice of Privacy Practices. If you haven’t already, revise your NPP to reflect the Part 2 SUD record protections and the reproductive health PHI provisions ahead of the February 16 deadline.

Implement MFA across all ePHI systems. Don’t wait for the final rule. MFA is a recognized security best practice and one of the most effective defenses against ransomware and credential theft. Start with EHR systems, portals, and administrative accounts.

Deploy or verify encryption. Ensure ePHI is encrypted at rest and in transit across every system, including endpoints, servers, cloud storage, and mobile devices.

Build your technology asset inventory. Document every device, application, and system that touches ePHI. Create a network map showing how data flows internally and to external partners.

Review and strengthen BAAs. Update Business Associate Agreements to include specific cybersecurity requirements. Begin requesting written verification of technical safeguards from your vendors.

Develop and test your incident response plan. Ensure you have a written plan that’s been tested and that your team can realistically restore critical systems within 72 hours of an incident.

ArcLight Group Is Here to Help

At ArcLight Group, we’ve been helping Oklahoma businesses navigate HIPAA compliance for nearly two decades. Our managed IT and cybersecurity services are purpose-built for organizations in regulated industries, including healthcare, dental, behavioral health, finance, and legal.

Whether you need a full gap analysis, help implementing MFA and encryption across your EHR environment, an outsourced HIPAA compliance officer, or a partner to manage your compliance program end-to-end, our team has the experience and the tools to get you where you need to be before the deadlines arrive.

Call The ArcLight Group at (918) 270-6600 or reach out through our website to schedule a HIPAA 2026 readiness conversation. We serve Tulsa, Oklahoma City, Broken Arrow, Bartlesville, and surrounding communities.

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.