The HIPAA Security Rule has not changed significantly since 2013. In those thirteen years, the hospice technology environment has transformed: cloud-based EHR systems, mobile devices for field staff, electronic care coordination with hospital systems, and digital family communication tools are all now standard. The threat environment has transformed equally dramatically.
The proposed 2026 update to the HIPAA Security Rule addresses this gap — and for hospice agencies, several of the proposed changes are particularly relevant given the distributed nature of hospice care delivery.
What the Proposed Rule Contains: The Five Most Important Updates for Hospice
Change 1: Encryption Would Become Mandatory
The original HIPAA Security Rule listed encryption as "addressable" — organizations could document a reasonable alternative if encryption wasn't implemented. The proposed 2026 update would remove that flexibility. Under the proposed rule, encryption of ePHI at rest and in transit would be required with no documentation workaround.
For hospice agencies: Every device used to access patient records must be encrypted. This includes:
- Office workstations and laptops
- Tablets and smartphones used by field nurses and social workers
- Devices used by chaplains and aides to document visits
- Backup systems and cloud storage containing patient records
For hospice agencies with field staff on personal devices — which is the operational norm — this creates an immediate action item. A nurse's personal phone used to access the agency EHR must be encrypted. For iPhones, encryption is enabled automatically when a passcode is set. For Android devices, encryption must be verified explicitly.
Change 2: MFA Would Be Required for All ePHI Access
Multi-factor authentication was previously recommended. The proposed 2026 update would make it legally required for every account with access to ePHI — no exceptions.
For hospice agencies: Every clinical staff member, administrative staff member, and any contractor accessing patient records must use MFA. This includes access to:
- The hospice EHR (Netsmart myUnity, Brightree, Axxess, MatrixCare, Suncoast)
- Email accounts that receive or transmit patient information
- Cloud storage systems containing clinical documentation
- Any remote access to agency systems
The practical implementation for most hospice agencies using Microsoft 365 involves enabling Conditional Access policies that require MFA for all users. A qualified cybersecurity provider manages this without disrupting clinical workflows.
Change 3: Biannual Vulnerability Scanning Would Be Required
The original rule required "periodic" technical evaluation. The proposed 2026 update would specify at minimum biannual automated vulnerability scanning.
For hospice agencies: This means scheduled vulnerability scans of your IT environment — the systems, devices, and networks through which ePHI flows — at least twice per year. Results must be documented. Identified vulnerabilities must have a documented remediation timeline.
For agencies without IT staff, this means engaging a managed security provider who conducts and documents the scans as part of their service.
Change 4: Annual Penetration Testing Would Be Required
Separate from vulnerability scanning, the proposed 2026 rule would require annual penetration testing by a qualified internal or external party.
For hospice agencies: Annual pen testing by an external firm is the appropriate approach for most hospice agencies. Cost ranges from $3,000–$15,000 depending on scope. The test results and remediation actions must be documented.

