HD Tech - SecurITy Delivered
Back to Blog
Managed IT

HIPAA IT Compliance for Orange County Practices in 2026

By Tom Hermstad · HD Tech

HIPAA IT Compliance for Orange County Practices in 2026

What does HIPAA IT compliance actually require in 2026?

HIPAA IT compliance requires documented risk analysis, multi-factor authentication, encrypted data, access controls, tested disaster recovery procedures, and signed Business Associate Agreements with every vendor that touches protected health information. HHS has proposed major revisions to the HHS Security Rule — including changes that remove the addressable-safeguard flexibility small organizations once relied on. No final rule has been issued as of July 2026. Updated rulemaking timeframes target July 2027 for final action. It's not if enforcement catches up with you — it's when. Preparation is the only answer.


What HIPAA IT Compliance Actually Means in 2026

Most practice owners hear "HIPAA compliance" and think about paper policies, staff training forms, and signed privacy notices. That's HIPAA Privacy Rule work.

What's changing — and what most Orange County organizations are not ready for — is the Security Rule overhaul targeting your IT infrastructure directly.

HHS's Office for Civil Rights (OCR) has proposed a major Security Rule update that eliminates the current "addressable" flexibility. Under the current rule, smaller organizations could argue that certain technical controls were not reasonable given their size or resources. Under the proposed standard, that argument goes away.

Covered entities and their business associates — regardless of size — must meet uniform security controls.

That applies to your medical practice in Irvine. Your manufacturing operation in Anaheim that runs a company health plan. Your accounting firm in Newport Beach if you handle electronic protected health information (ePHI) — meaning any individually identifiable health information stored, transmitted, or processed electronically, from patient charts to billing records.

HHS's updated rulemaking timeframe targets July 2027 for the final Security Rule amendments. Once finalized, the NPRM proposes the rule would become effective 60 days after publication, followed by a 180-day compliance period; exact dates could still change until the final rule is issued.

That may sound like plenty of runway. It isn't.

A formal risk analysis, system-wide encryption, tested disaster recovery procedures, and signed vendor agreements take considerable time to build — not days.

Here's a frame that changes how most executives think about this: HIPAA compliance isn't just a legal requirement. It's a competitive position.

The practice, firm, or operation that can prove its security posture — to auditors, to clients, to referral partners — earns trust that less-prepared competitors can't match. That trust is a business asset. It compounds over time.

It's not if an audit finds gaps in your environment — it's when. The organizations that survive intact are the ones that prepared before the pressure arrived.

If you want to understand how this fits into the broader picture of what your IT partner should be doing proactively, what every healthcare CEO should know about HIPAA in 2026 is a good starting point.


The 7 IT Controls HIPAA Requires — and What They Mean in Practice

This is not a comprehensive legal checklist. This is a plain-English breakdown of what the HHS HIPAA Security Rule requires from your IT setup — and what "compliant" actually looks like on the ground.

Each of these controls is also a differentiator. An organization with documented risk analysis, tested backups, and signed BAAs isn't just safer — it's more credible to the clients, partners, and auditors who are paying attention.

1. Formal Risk Analysis and Risk Management Plan

You must document every system that stores or accesses ePHI. Then do three things:

  1. Identify realistic threats to each system.
  2. Assess how likely each threat is — and how bad it would be.
  3. Build a management plan to address what you find.

Best practice and the proposed Security Rule updates call for at least annual review and update of this analysis, and it should also be revisited any time your systems change — new software, new staff, a cloud migration, anything.

This is not a one-time form you file away.

OCR audits look for evidence that the risk analysis is current and that it drove real decisions about your IT controls. A current risk analysis also tells you exactly where your vulnerabilities are — so you can fix them before a breach becomes your headline.

2. Access Controls

Your systems must use unique user IDs. No shared logins.

Access to ePHI is restricted by job role. Systems log users out automatically after a set period of inactivity. Every time someone accesses a record containing ePHI, that activity is captured in an audit trail.

If your organization still runs shared Windows logins or uses the same admin password across multiple platforms, that is an active compliance risk right now — and a liability that erodes the trust of every client whose data lives in those systems.

3. Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) means logging in requires both a password and a second verification step — like a code sent to your phone.

The proposed guidance makes MFA a baseline requirement. It applies to:

  • Your billing platform
  • Your remote access tools
  • Your cloud storage
  • Your administrative systems

MFA is one of the highest-impact controls you can implement. It significantly reduces the risk of unauthorized access even when credentials are stolen — which, according to the Verizon Data Breach Investigations Report, is among the leading techniques in web application breaches and account compromise.

Organizations that can demonstrate active MFA across all systems aren't just checking a box. They're showing clients and partners that access to their data is protected.

4. Encryption of ePHI

Encryption scrambles data so that even if a device is stolen or a network is compromised, the data is unreadable without the decryption key.

The forthcoming update makes encryption mandatory — for:

  • Data in transit — information moving across a network
  • Data at rest — information stored on a server, laptop, or cloud drive

OCR's enforcement history includes settlements triggered by stolen, unencrypted laptops. An unencrypted device with patient records isn't just a security incident. It's a reportable breach — with notification obligations and potential fines attached.

An organization that can document, honestly, that every device is encrypted and every transmission is secured has a clear advantage when a breach investigation begins. Or when a prospective client asks.

5. Vulnerability Management

Your systems must be regularly scanned for known security weaknesses.

The proposed standard requires:

  1. Penetration testing at least annually — a security professional actively tries to break into your systems to find gaps before attackers do.
  2. Vulnerability scans at least every six months — automated checks for known weaknesses across your environment.

Unpatched systems and aging software are how ransomware gets in.

Here's what's changed in the last two years: we caught a credential-stuffing attempt on a client's billing system at 2 a.m. last quarter — before a single file was touched. That's what AI-assisted monitoring inside the Lifeguard Loop™ actually delivers. Not a trend. A result.

The difference is behavioral analysis running continuously — not a scheduled scan window that only looks once a week. The system flagged anomalous login patterns in real time, our team responded, and the client never lost a minute of production. That's the gap between reacting and being ready.

Managed detection and response — MDR — means a security team watches your environment around the clock using these tools. Endpoint detection and response — EDR — means software that watches individual devices for suspicious behavior and raises the alarm the moment something looks off.

If your current IT setup relies on scheduled scans alone, you're already behind where the threat landscape is heading. We build AI-assisted monitoring into every HIPAA-scoped engagement we run. The threat changes — and so do we.

You can explore how downtime costs stack up in our breakdown of the real cost of IT downtime in 2026.

6. Disaster Recovery and Business Continuity Planning

HIPAA requires documented, tested procedures to restore systems and data following a disruption.

The proposed guidance includes specific recovery time objectives. The expectation: critical systems restored within 72 hours of a declared emergency.

"Tested" is the operative word. An untested backup is a guess.

If your IT provider says your backups are running but hasn't actually restored data from them recently, you don't have a disaster recovery plan. You have a disaster recovery assumption.

Here's what that 72-hour window means in real dollars:

  • Idle staff
  • Halted production
  • Missed deliverables
  • Emergency recovery costs that dwarf what a structured business continuity program costs annually

The organizations that hit 72 hours and bounce back are the ones whose IT partner built and tested the plan before the crisis — not during it.

That resilience isn't invisible to your clients. It's exactly what separates you from a competitor who goes dark for two weeks after an incident.

7. Business Associate Agreements (BAAs)

Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is a business associate. They must sign a Business Associate Agreement (BAA).

That includes:

  • Your cloud storage provider
  • Your billing service
  • Your managed IT provider
  • Your accounting firm — if they access financial data tied to patient records

The BAA must specify the vendor's security obligations and their incident reporting timelines.

A verbal understanding is not a BAA. An email thread is not a BAA. A signed, current document is.

A complete BAA file is a trust signal. When a referral partner, a prospective client, or an auditor asks how you manage vendor security, you have a documented, enforceable answer.


What Happens If You Fail an OCR Audit

I've sat with clients the morning after an OCR letter arrived. It's a different conversation than the one we had six months earlier when I was asking them to prioritize their risk analysis. The letter makes it real in a way that no amount of preparation talking ever does. I'd rather have that earlier conversation with you — and never need the second one.

Here is the honest picture of what HIPAA enforcement looks like for a small or mid-sized organization.

OCR can impose civil monetary penalties up to the maximum amount per violation category per calendar year, as adjusted annually for inflation by HHS, scaled based on the level of negligence.

Here's how that scale works:

  1. Didn't know, couldn't have known — smallest per-violation penalties. Even these minimums have been adjusted upward over time.

  2. Reasonable cause — mid-range penalties. The organization should have known, even if it didn't.

  3. Willful neglect, corrected — significant penalties.

  4. Willful neglect, not corrected — fines reach the full annual ceiling.

Beyond the fines, OCR enforcement means a multi-year Corrective Action Plan.

Your organization goes under ongoing monitoring. You implement specific IT controls by defined deadlines. You get audited again to verify compliance.

This consumes time, staff attention, and legal fees — often for years.

State attorneys general in California can also bring HIPAA-related enforcement actions independently — adding another layer of exposure on top of federal penalties.


When a breach occurs involving unsecured ePHI, the notification clock starts immediately:

That is not a process you want to figure out under pressure.


The organizations that end up in OCR settlements are not exclusively large hospital systems. A widely cited example is the 2017 settlement with CardioNet — a remote cardiac monitoring company — which paid $2.5 million after a laptop containing unencrypted ePHI was stolen from an employee's car.

The investigation found two critical gaps:

  1. No enterprise-wide risk analysis
  2. No policies governing the movement of devices containing patient data

Size and good intentions were not a defense.

Enforcement history consistently shows investigations and settlements against small organizations tied to missing risk analyses, stolen unencrypted devices, and unsigned BAAs.

It's not if OCR comes looking — it's when. The question is whether your documentation holds up when they do.

The flip side is equally true. Organizations that invest in documented, tested, audit-ready compliance don't just avoid penalties. They build the kind of reputation that attracts clients, reassures referral partners, and creates a real competitive edge in markets where trust is the product.


Common Beliefs That Will Get Your Organization in Trouble

"Our software vendor handles HIPAA"

Your vendor is a business associate. They are responsible for securing the platform they manage.

But you — the covered entity — remain responsible for your risk analysis, your access controls, your staff, and your own IT environment.

The vendor's BAA does not transfer your compliance obligations to them.

"We're too small to be targeted"

OCR has investigated and reached settlements with solo practitioners and small organizations. Ransomware operators do not check your headcount before encrypting your files.

Smaller organizations are often more attractive targets precisely because they have less mature security controls. It's not if attackers look your way — it's when.

And here's the other side: the small practice or firm that has mature controls while competitors don't is the one that earns a reputation for being safe to work with. That reputation is a real business advantage.

No More Nephew Solutions — This Is What's Actually on the Line

Let's be honest about what documented, audit-ready IT actually buys you.

When OCR opens an investigation, you can produce a written risk analysis, tested recovery procedures, audit logs, signed BAAs, and documented controls. You walk in with proof — not promises. That proof is the difference between a clean exit and a multi-year corrective action plan.

It's also a competitive differentiator. A compliant IT environment signals to clients, referral partners, and prospective customers that their data is genuinely safe with you. That's a trust advantage your less-prepared competitors simply cannot match.

Now consider what informal IT — the nephew, the part-time guy, the vendor who "checks in" — leaves you without.

The person helping you now is probably capable and genuinely well-intentioned. But consider what you've built. Years of growing this business, keeping your employees paid, earning the trust of your clients. Your name is on the door. Your family's financial security is tied to this operation continuing.

When OCR opens an investigation, none of that goodwill counts. If your IT contact can't produce the documentation above, your organization absorbs the consequences — the penalties, the corrective action plan, the reputational hit.

Good intentions don't protect your people. Proof does.

A compliant IT partner gives you a documented, testable, provable security posture — something competitors still running on informal IT simply cannot match.

That's the difference between IT as a cost center and IT as a competitive edge.

No More Nephew Solutions. Failing to plan is planning to fail.


Why Accounting Firms Are Also in Scope

This is where many Orange County organizations — and their accountants — have a blind spot.

If your accountant touches patient billing data and there's no signed BAA in place, OCR can act on that gap. Even if a breach never happened. That's not a hypothetical. That's how the rule works.

Here's the specific test: if your accounting firm accesses financial records tied to patient identities — billing systems, insurance reconciliation data, anything that includes individually identifiable health information — they qualify as a business associate under HIPAA.

That means two things:

  1. They must meet Security Rule requirements for those systems.
  2. They must sign a BAA with your organization.

Many accounting firms don't know they're in scope. Many practices have never asked. Both sides carry the exposure.

The financial case is straightforward. A mid-sized accounting firm pulled into an OCR investigation over a missing BAA faces legal fees, remediation costs, and potential penalties.

Those costs far exceed what a properly scoped managed IT engagement runs per year.

When compliance is built in, it protects the firm's revenue and its client relationships.

It also becomes a selling point. A firm that can tell clients "we are fully HIPAA-compliant, we have signed BAAs in place, and our security is documented and tested" earns referrals from healthcare practices that less-prepared competitors simply don't get.

This is also relevant to firms considering AI-powered accounting tools. The question of whether Microsoft Copilot is HIPAA compliant for accounting firms is one that more organizations are asking as AI adoption accelerates — and the answer depends heavily on your configuration and your BAA.


How HD Tech Approaches HIPAA IT Compliance for Orange County Organizations

We do not sell you a policy binder and call it compliance. That is not how the Lifeguard Loop™ works.

I'll be honest — watching a client walk out of an OCR audit with a clean bill of health because every control was documented, tested, and current is one of the most satisfying things we do. After many years in this business, that moment never gets old. It's exactly why we do the work the way we do it.

When we onboard a client in Orange County, we start with a structured Listen & Learn phase. We review every system that touches ePHI, every vendor relationship, every access control, and every backup configuration.

We document what exists, what is missing, and what is at risk.

From there, we implement and integrate the controls you actually need:

  • MFA across all systems
  • Role-based access with audit logging
  • Encrypted storage and transmission
  • AI-assisted vulnerability scanning that monitors continuously — not just during scheduled windows
  • A tested disaster recovery plan with defined recovery time objectives

We also handle Business Associate Agreements. We review what you have, identify unsigned relationships, and make sure your BAA documentation is current and enforceable.

Every quarter, we report back to you in plain English. No jargon. No dashboards that require an IT degree to interpret.

You know where you stand, what changed, and what still needs attention. That is the Plain-English Promise™ in practice.

We have worked with organizations that survived OCR investigations because their documentation was current and their controls were real. We have also worked with organizations that came to us after a breach, after a failed audit, after the fire drill had already started.

The second group always wishes they had called sooner.

What we build isn't just a compliance program — it's a competitive position. When your IT environment is documented, tested, and audit-ready, you can prove to clients and partners that their data is safe with you. That proof separates you from competitors who are still hoping nothing goes wrong.

"Careful attention to detail, solution-oriented services and implementation and fair pricing. We have worked with HD Tech for many years now and are extremely satisfied with their professionalism and capabilities." — Greg Burnight, Principal, APC, Curtis & Burnight, Seal Beach

That kind of relationship is what we build with every client. Not a vendor. A partner.


2026 HIPAA Readiness: Where to Start

If you are a CEO, COO, or administrator at a medical, manufacturing, or accounting organization in Orange County, here is how to think about this right now.

1. Audit your current state first. You cannot build a compliant IT environment if you do not know what you have. A formal risk analysis is not optional — it is the foundation of everything else. It also tells you exactly where your gaps are relative to competitors who are already investing in their security posture.

2. Check your BAAs. Pull out your vendor list. Your billing platform, your cloud storage, your IT provider, your accountant. Does each one have a signed BAA? Is it current? Does it specify security obligations and incident reporting timelines?

3. Test your backups. Not just "confirm they're running." Actually restore data from them. If your IT provider cannot tell you the last time a recovery test was completed, that test has not happened.

4. Verify MFA is active. Every system. Every user. Every remote access point. If any system still accepts a username and password without a second verification factor, it is a gap.

5. Get a compliance assessment before the rule change takes effect. The proposed Security Rule update removes much of the current addressable flexibility. Controls that were previously optional for small organizations become mandatory. HHS targets July 2027 for the final rule — but a structured compliance assessment now costs far less than remediation after an audit or breach.

The organizations that complete that assessment now have ample time to build an advantage. The ones that wait spend that time scrambling to catch up.

Managed IT done right isn't a cost center. It's the infrastructure that lets you compete — and win — in markets where trust, uptime, and security are the product.

It's not if an audit or incident happens — it's when. The organizations that come through intact are the ones that prepared before the pressure arrived. Don't be a casualty.


Frequently Asked Questions

HIPAA IT compliance requires a formal risk analysis and a written management plan. You need access controls with unique user IDs and audit logging. MFA must be active on every system that touches ePHI. Data must be encrypted in transit and at rest.

You need a tested disaster recovery plan and signed Business Associate Agreements with every vendor handling protected health information. The proposed Security Rule update removes size-based flexibility — these requirements apply regardless of patient volume. This is exactly the gap we find in the vast majority of first audits we run — and it's almost always fixable once you can see it clearly.

OCR can impose civil monetary penalties up to the maximum amount per violation category per calendar year, as adjusted annually for inflation by HHS, scaled by level of negligence. Enforcement also means a multi-year Corrective Action Plan — specific IT controls, ongoing monitoring, and follow-up audits.

If a breach occurred, affected individuals must be notified within 60 days of discovery. If 500 or more state residents are affected, HHS and local media must both be notified within that same 60-day window. California's attorney general can also act independently on top of federal requirements. Preparing now is a far better conversation than explaining later why you didn't.

Yes — if an accounting firm accesses individually identifiable health information, such as patient billing or insurance reconciliation data, they qualify as a business associate under HIPAA. They must meet Security Rule requirements for those systems and sign a Business Associate Agreement with the covered entity.

Many Orange County accounting practices carry this exposure right now without a current BAA in place — and both sides of that relationship absorb the risk. This is one of the most common blind spots we find when we walk through the door for the first time, and it's one of the easiest to fix when you know it's there.

A Business Associate Agreement (BAA) is a legally required contract between your organization and any vendor that creates, receives, maintains, or transmits ePHI on your behalf. It must specify the vendor's security obligations and breach reporting timelines.

Verbal understandings don't satisfy this requirement. Neither do email threads. A missing or outdated BAA is one of the most common OCR findings — and it can trigger penalties even when no breach occurred. If you can't produce a signed BAA when OCR asks for it, it doesn't exist — so let's make sure it does.

Start with a formal risk analysis. Document every system that touches ePHI. Confirm MFA is active on every system. Verify that backup data has actually been restored recently — not just confirmed as running. Audit your BAAs for completeness.

The proposed update removes addressable flexibility — controls that were optional for small organizations become mandatory. HHS targets July 2027 for the final rule, but a compliance assessment now costs far less than remediation after an audit or breach. The organizations that act now build an advantage — and this is our favorite kind of engagement because the plan becomes clear fast.


HD Tech works with medical, dental, manufacturing, and accounting organizations across Orange County to build IT environments that satisfy HIPAA's Security Rule requirements — documented, tested, and audit-ready. A compliant IT environment isn't just protection from fines. It's a competitive advantage in markets where your clients need to trust you with their most sensitive information.

We've helped Orange County manufacturers and healthcare organizations walk out of OCR audits clean — documentation current, controls verified, nothing to hide. If your organization hasn't had a formal compliance review recently, let's fix that. Book your Cyber Preparation Assessment at hdtech.com. We'll show you exactly where you stand. No jargon, no surprises — and we're fired up to get started.

HIPAA IT compliance
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.