HIPAA Compliance for Optometry
Is MFA Required by HIPAA? The Proposed Security Rule, Explained
Where the proposed rule actually stands
In January 2025, the Office for Civil Rights published a proposed rule — an NPRM, in regulatory language — that would be the first major overhaul of the HIPAA Security Rule in over two decades. It drew thousands of public comments, and working through them takes time: the government's own spring-2026 target for finalizing came and went with nothing published, and the current federal agenda points to July 2027 for final action. Targets like that move.
Until a final rule is published with a compliance date, none of it is enforceable. So when a vendor tells you a new HIPAA mandate means you must buy something today, they are ahead of the law — and that's worth remembering about the vendor, too.
What today's Security Rule already requires
Here's the part that actually matters for your practice this year. The Security Rule that has been in force since 2005 requires access control — including unique user identification, so activity in your systems can be traced to a specific person — and person-or-entity authentication, meaning your systems verify that the person seeking access is who they claim to be. Those live at §164.312(a)(1) and §164.312(d), and they are not proposals.
Now look at a typical optometry exam lane: one shared Windows account. The tech starts the workup, the doctor finishes, a scribe documents — all under the same login. The audit log works perfectly and proves nothing, because it can't attribute a single action to a named person. That's not a future problem waiting on a rule in Washington. It's a gap under the rule you're already measured against.
What the proposed update would change
If finalized in a form close to what was proposed, the update would make multi-factor authentication mandatory for systems touching patient information, with narrow exceptions. More broadly, it would remove much of the "addressable" flexibility that lets practices document their way around technical safeguards — making requirements like encryption and MFA required rather than negotiable — and add expectations like maintained asset inventories, among other changes.
The direction of travel is unambiguous, even if the arrival date isn't: regulators want provable, per-person control over who touches patient data. Practices that build that now are simply early. Practices that wait will be doing it on a deadline.
The requirement that's already here: your insurance carrier
While the rule works through Washington, cyber-insurance carriers stopped waiting. MFA now shows up in renewal questionnaires as a condition of coverage — and, in the fine print that matters most, as a condition of a claim being paid. A practice that answers "yes" to an MFA question it can't back up has a bigger problem than a premium increase: after an incident, that answer is the first thing the carrier's counsel reads.
Between the current Security Rule and your carrier, the practical question was never really "when does the mandate land?" It was always "can we prove who was at the keyboard?" — and the cost of answering that badly doesn't wait for 2027 either.
What optometry practices should do now
Not panic-buy — sequence. First, fix the attribution gap you have under the current rule: shared lane logins that can't tie an action to a named person. Second, turn on MFA where it's cheap and disruptive to nobody: practice email, remote access, EHR administrator accounts. Third, write the decisions down in your security risk analysis with dates — because when the final rule does land, the practices in good shape will be the ones who can show they moved before they had to.
The hard case in optometry has always been the exam lane itself, where one shared account is how clinic actually flows. That's the specific problem our Sentry™ workstation identity layer was built for — a badge and a PIN per staff member on the shared lane account, with every sign-in written to a tamper-evident record. It's in a limited beta for practices we support.
Common questions
Does HIPAA require MFA today?
No. Today's Security Rule requires access control with unique user identification and person-or-entity authentication. MFA is one recognized way to strengthen authentication, and the proposed update would make it mandatory — but that rule is not final.
When will the proposed rule become final?
There is no official date. The government's spring-2026 target passed without action, and the current federal agenda points to July 2027 — a target, not a promise. Nothing is enforceable until a final rule publishes with a compliance date.
Our EHR has MFA — are we covered?
That covers the EHR login. The workstations in your exam lanes, your email, your remote access, and your other systems sit outside it — the same pattern as every other obligation your EHR doesn't carry for you.
If the rule finalizes, how long would we have to comply?
Final rules include a compliance window — historically measured in months, not days. But the window is for finishing, not starting: practices that already solved attribution and access control will spend it verifying, while everyone else spends it shopping under deadline.
What this means for you
Ignore the countdown clocks and the scare headlines. The honest position is simpler: MFA is proposed, attribution is required, and your insurance carrier is already asking. Fix the gap that exists under today's rule, take the cheap MFA wins now, and document both — and whatever shape the final rule takes, you'll meet it already standing.
Question three of our self-assessment asks whether every person in your practice has their own login — and it's one of the most commonly missed. Twelve plain questions, an honest grade, and a clear list of your gaps, in about three minutes.
Take the Free Self-AssessmentMacula Networks provides HIPAA compliance evidence and IT services to independent optometry practices nationwide. This article is general information, not legal advice. Rulemaking status, requirements, and timelines change; verify the current status of the proposed Security Rule update for your situation.