confeplanet


2026 HIPAA Rule Updates: What Healthcare Providers, Administrators, and Compliance Officers Need to Know

All Days
Healthcare | Recorded Webinar | Duration: 90 Minutes
Brian L Tuttle

Live webinar instructions will be emailed to you 3 days prior to the event. || The recording, digital download, and full transcript will be available within 48 hours after the webinar.
Description

This webinar explores the critical HIPAA updates taking effect or approaching in 2026, with a primary focus on the proposed overhaul of the HIPAA Security Rule (from the December 2024 NPRM by HHS/OCR). It covers mandatory cybersecurity enhancements to protect electronic protected health information (ePHI), the February 16, 2026, deadline for updating Notices of Privacy Practices (NPPs), and related changes like 42 CFR Part 2 alignment for substance use disorder records. The session highlights how these changes modernize HIPAA requirements to combat rising cyberattacks, eliminate flexibility in safeguards, and impose stricter documentation, audits, and controls—urging healthcare organizations to prepare proactively to avoid penalties and ensure compliance.

Webinar Agenda:

  • Introduction to 2026 HIPAA Landscape and Key Deadlines
  • Overview of the Proposed HIPAA Security Rule Updates (NPRM from December 2024)
  • Detailed Breakdown of Major Security Rule Changes
  • February 16, 2026 NPP Update Requirements and Related Privacy Adjustments
  • Compliance Strategies, Implementation Steps, and Risk Mitigation
  • Recommended Cybersecurity Services and Best Practices

Areas Covered:

  • Elimination of "addressable" vs. "required" distinctions, making nearly all safeguards mandatory
  • Enhanced documentation requirements for policies, procedures, risk analyses, and compliance activities
  • Mandatory technology asset inventory and annual network mapping for ePHI flows
  • Annual formal compliance audits (with business associates sharing results)
  • Stricter cybersecurity controls, including: multifactor authentication (MFA) for all access, role-based access, automatic session timeouts, one-hour access revocation on termination, mandatory encryption of ePHI at rest and in transit, 24-hour incident reporting, written incident response plans with annual testing, 72-hour system restoration capability, NIST alignment, vulnerability scans every six months, and annual penetration testing
  • Updates to Business Associate Agreements (BAAs) with specific new clauses
  • Expanded annual risk assessments aligned with NIST Cybersecurity Framework
  • NPP revisions by February 16, 2026, to reflect updated patient rights, reproductive health privacy, and SUD record protections under 42 CFR Part 2
  • Integration of privacy/security into daily workflows, patient access improvements, and breach preparedness

Why Should You Attend?

With cyberattacks targeting healthcare at record levels, the proposed 2026 HIPAA Security Rule changes represent the most significant modernization since 2013—shifting many safeguards from optional to mandatory and introducing rigorous new requirements like MFA, encryption, and frequent testing. The imminent February 16, 2026, NPP deadline adds immediate urgency. Attending this webinar equips you with actionable insights to:

  • Avoid costly penalties and enforcement actions
  • Strengthen your organization's cybersecurity posture against evolving threats
  • Prepare efficiently for audits, documentation, and compliance burdens
  • Implement practical strategies now rather than reacting later
  • Leverage expert recommendations to align with NIST and reduce risks

Whether you're facing resource constraints or complex vendor relationships, this session provides clarity on what’s changing, why it matters, and how to stay ahead—essential for maintaining patient trust and operational resilience in 2026 and beyond.

Who Should Attend?

  • HIPAA Compliance Officers and Privacy/Security Officials
  • Healthcare Providers (hospitals, clinics, physicians, behavioral health practices)
  • Health Plans and Health Care Clearinghouses
  • Business Associates and Vendors Handling ePHI
  • IT and Cybersecurity Teams in Healthcare Organizations
  • Legal and Risk Management Professionals
  • Leadership and Administrators Responsible for Regulatory Compliance
  • Any Covered Entity or Business Associate Preparing for 2026 HIPAA Deadlines and Security Enhancements
Rhanda McKown

Brian L Tuttle

Brian L Tuttle, CPHIT, CHP, CBRA, Net+, A+, CCNA, MCP is a Certified Professional in Health IT (CPHIT), Certified HIPAA Professional (CHP), Certified HIPAA Administrator (CHA), Certified Business Resilience Auditor (CBRA), Certified Information Systems Security Professional (CISSP) with over 18 years' experience in Health IT and Compliance Consulting. With vast experience in health IT systems (i.e. practice management, EHR systems, imaging, transcription, medical messaging, etc.) as well as over 18 years’ experience in standard Health IT with multiple certifications and hands-on knowledge, Brian serves as compliance consultant and has conducted onsite and remote risk assessments for over 1000 medical practices, hospitals, health departments, insurance plans, and business associates throughout the United States. In addition, Mr Tuttle has served in multiple litigated court cases serving as an expert witness offering input related to best practices and requirements for securing and providing patient access to protected health information. Mr. Tuttle has also worked directly with the Office of Civil Rights (OCR) both in defending covered entities and business associates as well as being asked by the Federal government to audit covered entities and business associates on behalf of the OCR. Almost all of Brian’s clients are earned by referral with little or no advertising. 

Live webinar training is a virtual event that takes place in real time, where a speaker presents information, and participants can interact through a web conferencing platform.
Login to your dashboard and get your Live Instruction. You will also receive a notification via email. Live instructions will be emailed 12 hours before the live webinar.
Recording and Transcript will be available 24 hours after the live date.
Login to your dashboard and download the presentation (PDF).
A Digital Download is a digital file (webinar, video, audio, or other content) that can be downloaded and used without further processing. The download link is valid for 30 days. Please save it to your local storage for lifetime access. This link is unique to you and should not be shared.
Login to your dashboard and click on Digital Download. Download instructions will also be sent via email.
A transcript is a written record of the spoken words in a webinar, including presenter content and participant questions. It can be accessed within 30 days.
Login to your dashboard and download the transcript (PDF). Download instructions will also be emailed. The transcript is available for 30 days.
An on-demand session is a pre-recorded webinar that can be watched anytime with 30 days’ access.
Login to your dashboard and watch the recording. Instructions will also be emailed. Access is valid for 30 days with unlimited views.
Login to your dashboard and download the Invoice (PDF). A confirmation email will also be sent once the order is confirmed.
You can download the registration form or request a call.
Login to your dashboard, go to My Profile, and change your password.