All covered entities must update their Notices of Privacy Practices to explain patient rights regarding reproductive health and substance use data protections (from the April 2024 Privacy Rule changes). Intake.Dental NPP templates are already updated for this deadline.
Alignment of substance use disorder records rules with HIPAA reaches mandatory compliance for affected practices.
The most sweeping Security Rule update since 2013 will mandate MFA for all ePHI systems, encryption at rest and in transit with no exceptions, annual technology asset inventories, biannual vulnerability scans, annual penetration testing, 72-hour incident response, and direct compliance liability for business associates.
Organizations will have 180–240 days post-publication to comply with the new Security Rule.
OCR levied over $6.6 million in fines in 2025 alone, with single penalties ranging from $80,000 to $3,000,000. Phase 3 audits launched targeting 50+ entities. Industry cost estimates for compliance with the incoming rules: $9 billion year one, $34 billion over five years.
Practices on Intake.Dental don't need to manually track most of the technical requirements — we ship them by default.
Penalties escalate. The new Security Rule also eliminates the 'addressable' safeguard option, meaning all technical safeguards become mandatory — reducing interpretation flexibility compared to current rules.
Yes. Under 45 CFR § 164.402, properly encrypted PHI may not trigger breach notification if the encryption keys were not compromised. Layered encryption (AES-256-GCM plus our optional Glyph Cipher add-on) strengthens this defense significantly.
Yes. Practices treating patients with SUD histories must align intake forms and data handling with the unified 42 CFR Part 2 / HIPAA protocols by February 2026. Intake.Dental's form templates are already updated.
OCR levied over $6.6 million in fines in 2025 with single penalties ranging from $80,000 to $3,000,000. Phase 3 audits targeted 50+ entities. The most common violations were inadequate risk assessments, ransomware incidents, and weak technical safeguards.
HIPAA is undergoing its most significant changes in over a decade. New Security Rule mandates, Privacy Rule updates, NPP revision deadlines, and escalating enforcement. Here's how to get ready.
Intake.Dental ships HIPAA-compliant by default — MFA, encryption, audit trails, BAA, and 72-hour incident response all built in.
© 2026 Intake Dental. Todos los derechos reservados.
Hecho con cuidado para consultorios dentales.