Episode 603: HIPAA Security Rule Changes: January 2026 Update & What Practices Need to Know
Release Date: 01/23/2026
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an update (and are once again offering reassurance) around the proposed HIPAA Security Rule changes. We discuss: The proposed Security Rule update on the OCR’s spring regulatory agenda Why you’re already in good hands if you’re following PCT’s advice Some of the proposed changes that will impact therapy practices Reassurance about these proposed changes Effective dates versus compliance date Forecasting scenarios for these changes to...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Dr. Maelisa McCaffrey of QA Prep about how the landscape of insurance and documentation has shifted over the last decade. We discuss: Risk adjustment audits and how they impact providers Billing codes and audit red flags AI documentation and how insurance companies are using AI Considerations when using AI for documentation Pressuring professional associations to advocate for clinicians and clients Our upcoming CE event on January 30th...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what to do as a practice owner to prevent email hacks, and how to respond if one occurs. We discuss: Technical and behavioral measures to take to prevent email hacks Mandating two-factor authentication system-wide Education and staff training for prevention Creating a shame-free security culture in your practice Steps to take if you receive an email that looks suspicious Steps to take if you find out your email has been hacked Breach reporting...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re highlighting the stories that impacted your practices this year, and the main takeaways from each story. We discuss: The proposed changes to the HIPAA Security Rule Common sense security updates to incorporate into your practice The proliferation of AI and ways therapists can differentiate themselves from AI The proliferation of platforms offering practice management as a service How group practices can stand out from these practice management...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Ben Cutler, CEO of Hushmail, about how a secure email service can be a crucial part of your practice’s tech stack. We discuss: How secure email can complement the communication features of your EHR Communication gaps in EHRs that can impact your security circle Pairing secure forms with secure email to optimize the intake process Secure communications as a marketing asset Creating more efficient streamlined services for clients and...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we answer a frequently asked question: whether therapy practices actually need cybersecurity insurance. We discuss: The benefits and considerations of obtaining a cybersecurity insurance policy PCT’s stance on cybersecurity insurance for solo and group practices How cyber insurance relates to your full HIPAA compliance program Common reasons for claim denials The six major areas where cyber policies differ, and how to choose your policy How a PCT risk...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share some positive stories to bring you some peace of mind at this time of year. We discuss: Increasing transparency requirements for AI service providers Cross-jurisdictional licensure portability/practice permissions expansion No telehealth cliff for Medicare clients, and the in-person visit requirement How security standards are becoming easier to adopt Practice culture becoming easier due to supportive systems Listen here: For more,
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Gabrielle Juliano-Villani of Medicare Consulting for Therapists about recent updates regarding Medicare and telehealth. We discuss: The extension of in-person visit requirement What that means for new and established clients Coping skills for the ups and downs of business Main takeaways for practice owners with the recent extension Where to get updates on this topic Listen here: For more,
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we unpack what Practice Management Companies (PMCs) are, and the legal and ethical considerations for therapists when using these platforms. We discuss: The proliferation of Practice Management Companies The difference between PMCs and EHRs Why the benefits of PMCs are so tempting to new clinicians in particular How these companies are marketed vs. what clinicians can actually expect Who owns PMCs, and the implications of that How group practice owners can...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an update for you on what’s changed with teletherapy coverage for Medicare clients. We discuss: Our free 90 minute webinar that goes deeper into this topic What is still covered for behavioral/mental health services What has changed for behavioral/mental health services Who is considered an established client or a new client Exceptions to the in-person visit requirement Next steps to take to prepare for this change in your...
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we have an update (and are once again offering reassurance) around the proposed HIPAA Security Rule changes.
We discuss:
- The proposed Security Rule update on the OCR’s spring regulatory agenda
- Why you’re already in good hands if you’re following PCT’s advice
- Some of the proposed changes that will impact therapy practices
- Reassurance about these proposed changes
- Effective dates versus compliance date
- Forecasting scenarios for these changes to take effect
- Steps to take now (and important things to not do now) to be proactive rather than reactive
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.
PCT Resources:
- Article: HIPAA Security Rule Changes: January 2026 Update & What Practices Need to Know
- Explore our in-depth article unpacking the proposed HIPAA Security Rule updates — what’s really happening, why it matters, and why this is a runway, not a cliff. You can also use our free Mini Risk Tool(download link in article) for a gentle check-in to see where your practice stands and what would most meaningfully support your security and compliance foundation.
- PCT’s Comprehensive HIPAA Security Compliance Program (discounted) bundles:
-
- For Group Practices
- For Solo Practitioners
- Comprehensive HIPAA Security Policies & Procedures
- Forms & Logs for documenting implementation and maintenance of Policies & Procedures in practice
- Device & Workspace Security Suites
- Direct Support & Consultation from PCT team + therapist attorney Eric Ström, JD PhD LMHC (live & recorded + searchable library)
- Includes the Risk Analysis & Risk Mitigation Planning service + tool
- HIPAA Security & Privacy Ethics training
-
- HIPAA Risk Analysis & Risk Mitigation Planning service for mental health group practices — care for your practice using our supportive, shame-free risk analysis and mitigation planning service. You’ll have your Risk Analysis done within 2 hours, performed by a PCT consultant, using a tool built specifically for mental health group practice, and a mitigation checklist to help you reduce your risks.
- Group Practice Care Premium
- weekly (live & recorded) direct support & consultation service, Group Practice Office Hours — including monthly session with therapist attorney Eric Ström, JD PhD LMHC
- + assignable staff HIPAA Security Awareness: Bring Your Own Device training + access to Device Security Center with step-by-step device-specific tutorials & registration forms for securing and documenting all personally owned & practice-provided devices (for *all* team members at no per-person cost)
- + assignable staff HIPAA Security Awareness: Remote Workspaces training for all team members + access to Remote Workspace Center with step-by-step tutorials & registration forms for securing and documenting Remote Workspaces (for *all* team members at no per-person cost) + more