Ohio medical practices and law firms have a narrow window to close security gaps before HIPAA's 2026 overhaul makes multi-factor authentication and encryption mandatory instead of optional, and before regulators expect a documented risk analysis on file. Acting now also positions a practice to claim the legal protection built into Ohio's cybersecurity safe harbor law.
What Changes When HIPAA's "Addressable" Safeguards Become Mandatory in 2026?
The short answer is that the flexibility built into the current rule disappears. Under today's HIPAA Security Rule, safeguards are split into "required" and "addressable" categories, and addressable items have historically given covered entities room to document an alternative approach instead of implementing the safeguard itself. According to Medcurity's breakdown of the 2026 changes, that flexibility goes away for core protections like multi-factor authentication and encryption, which move into the required column with no substitute allowed.
Johnson Lambert's review of the mandatory control changes frames this the same way, describing HHS narrowing the gap between what the rule says on paper and what a practice actually has to prove to stay compliant, with enforcement tightening alongside the new controls. For a solo physician's office or a five-attorney firm running on a shared file server and a part-time IT contractor, that is a meaningful operational shift, not a paperwork update. Budgeting for MFA and encryption tools in 2025 is a smaller line item than scrambling to deploy them under a compliance deadline in 2026.
Why Is HHS Enforcement Already Getting Tighter Right Now?
Enforcement pressure is not waiting for the 2026 effective date to arrive. Anatomy IT's summary of 2025 OCR enforcement activity points to ransomware incidents, missing or outdated risk analyses, and Part 2 substance use disorder record compliance as the areas drawing the most scrutiny from investigators this year. A practice that has never completed a proper risk analysis, or completed one years ago and never touched it since, sits squarely in the range regulators are already looking at.
That risk analysis requirement sounds simple on paper and is not simple in practice. DoctorsManagement's look at the hidden burden of HIPAA describes security risk analysis as one of the most persistent challenges for small medical practices, largely because most practices lack the internal staff or time to conduct one properly, let alone keep it current as systems and vendors change. An open OCR inquiry, regardless of how it resolves, still costs staff hours and legal fees a small practice did not budget for. Waiting until the 2026 rule takes effect to start that work means starting from behind, with less runway to fix what an investigation finds.
How Does Ohio's Cybersecurity Safe Harbor Law Actually Work?
Ohio's law offers an affirmative defense, not blanket immunity. Bricker's coverage of the law taking effect explains that a business sued over a data breach can raise this defense if it can show it had implemented and maintained a recognized cybersecurity framework before the incident occurred. The law does not stop a breach from happening and does not stop someone from filing a lawsuit, but it gives a defendant a documented, framework-based response instead of an empty file when a plaintiff's attorney asks what was in place to protect patient or client data.
AccountableHQ's overview of Ohio's data privacy law in healthcare notes that this matters more for providers than in some other industries, since medical practices already carry HIPAA obligations on top of any state-level breach notification duties. A practice doing the work HIPAA already requires, against a recognized framework, is closer to safe harbor eligibility than it might assume, which makes the 2026 mandatory controls and the Ohio defense two sides of the same project rather than two separate to-do lists.
Why Does the Safe Harbor Law Matter for Law Firms Too?
Ohio's safe harbor protection is not limited to healthcare. Bricker's coverage of the law describes it as available to businesses generally that adopt and maintain a recognized cybersecurity framework, and law firms hold exactly the kind of sensitive client data that makes them a target for the same breach lawsuits medical practices face. A firm handling client financial records, litigation files, or merger documents carries real exposure if that data is exposed, and a documented framework gives the firm the same defense a medical practice can raise, along with a stronger answer when corporate clients start asking firms to prove their own security posture as part of vendor due diligence.
Does Your Practice or Firm Actually Qualify for Safe Harbor Protection?
Qualification depends on adopting and maintaining a specific, recognized security framework, not on good intentions or a general sense that security is taken seriously. VirtualSprout's practical guide to qualifying for the safe harbor walks through what that adoption looks like day to day, including documented policies, staff training, and evidence that the framework's controls are actually running rather than sitting in a binder. A practice cannot claim the defense after the fact. The framework has to already be in place and operating when the incident happens, which is exactly why the work has to start well before a breach, not after one.
What Should a Small Practice or Firm Do Before 2026?
The path forward is largely the same whether the goal is meeting the 2026 HIPAA requirements, satisfying OCR if it comes asking questions, or qualifying for Ohio's safe harbor defense. The work overlaps almost entirely, which means a single project can cover all three.
- Complete or update a formal HIPAA security risk analysis, and put a process in place to keep it current instead of letting it sit untouched for years.
- Turn on multi-factor authentication everywhere it is not already required, including email, remote access, and any system holding patient or client records.
- Confirm encryption is applied to data at rest and in transit, not assumed because a vendor mentioned it once during a sales call.
- Adopt a named, recognized cybersecurity framework and document that adoption in writing, since that documentation is what makes the safe harbor defense usable later.
- Review vendor and business associate agreements to confirm partners handling patient or client data are held to the same standard.
How Do Today's Addressable Safeguards Compare to What 2026 Requires?
The table below reflects the shift Medcurity and Johnson Lambert describe for two of the most commonly discussed controls.
| Safeguard | Status Today | Status Under the 2026 Rule |
|---|---|---|
| Multi-factor authentication | Addressable, alternative measures allowed | Required, no substitute permitted |
| Encryption of data at rest and in transit | Addressable, alternative measures allowed | Required, no substitute permitted |
That table looks small, but it represents a real shift in expectations. Practices and firms that treated MFA and encryption as items to consider someday will not have that option once the 2026 rule is in force, and the practices that already treat them as required will already have most of what safe harbor eligibility asks for.
None of this requires guessing at what regulators or courts will accept. It requires an honest look at what safeguards are already in place, what is missing, and how close a practice or firm is to the framework-based protection Ohio law now offers. Book a strategy call with Securafy to walk through where the gaps are and what it would take to close them before the 2026 deadline arrives.
By Ric Hall
Join The Conversation
Have a question or perspective on this topic? Add it below.