
Between the monsoon storms and the 110-degree days, we're all used to staying prepared for a bit of chaos. But there's a different kind of storm brewing in the world of data security: the 2026 HIPAA Security Rule updates.
For years, HIPAA had a lot of "addressable" rules, tech-speak for "it's a good idea if you can afford it." Well, the Department of Health and Human Services (HHS) has officially decided that "good ideas" aren't enough anymore. In 2026, many of those suggestions are becoming mandatory law.
If your current IT guy is still saying, "We're probably fine," it might be time for a second opinion. At Northern Arizona IT, we help businesses across Phoenix, Scottsdale, and Glendale navigate these headaches so you can focus on your patients and clients instead of looking over your shoulder for a federal auditor.
Here are the big changes you need to know about for 2026.
1. Multi-Factor Authentication (MFA) is No Longer Optional
Remember when MFA was just an annoying text message you'd get when logging into your bank? Those days are over. For 2026, MFA is mandatory for every system that touches electronic Protected Health Information (ePHI).
Whether it's your EHR, your email, or even the remote desktop your team uses to work from home in Scottsdale to avoid the traffic, you must have a second layer of security. It's one of the top strong authentication methods we recommend to keep hackers out.
2. Encryption is Required Everywhere
Encryption used to be one of those "addressable" items. Not anymore. Under the new rules, ePHI must be encrypted both "at rest" and "in transit."
- At Rest: the data sitting on your office server, your laptop hard drive, and even your backup drives must be scrambled so that if a thief walks off with the hardware, they can't read the data.
- In Transit: every email or file transfer containing patient info must be sent through a secure, encrypted tunnel.



