Building a Security Rule Program for HIPAA-compliant healthcare data archiving
According to HHS’s current Security Rule summary, the rule covers ePHI that regulated entities create, receive, maintain, or transmit. HIPAA-compliant healthcare data archiving is not an official certification or product label. Moving data out of production does not remove applicable security duties.
This matters because archives often contain years of clinical, financial, and operational history. The HHS proposed rule overview reports on large breaches from 2018 through 2023. It states: “From 2018-2023, reports of large breaches increased by 102 percent and the number of individuals affected by such breaches increased by 1002 percent.”
What Counts as Archived ePHI
According to HHS’s current Security Rule summary, ePHI is protected health information maintained in or transmitted by electronic media. Archived ePHI can include retired EHR records, document images, migrated databases, interfaces, exports, backups, and recovery copies.
Financial and ERP records enter Security Rule scope when they contain ePHI handled by a regulated entity. Non-PHI records do not become ePHI merely because they share an archive.
Scope follows the data and the regulated activity, not the production status of its former application. A DataArk active archive platform can centralize legacy clinical, financial, and ERP data while supporting controlled access after source retirement.
Who Is Responsible for Archive Security
Under HHS’s current Security Rule summary, covered entities and business associates have duties tied to the ePHI they create, receive, maintain, or transmit. A covered entity should define its control ownership and oversight across internal and vendor-managed archive environments.
According to HHS, before a regulated entity permits a business associate to create, receive, maintain, or transmit ePHI, it must obtain satisfactory assurances through a contract or other written arrangement. Whether an archive provider is a business associate depends on the facts, not the vendor’s label alone.
Clear ownership turns healthcare data regulatory compliance into daily practice. Can your team name each control’s owner, scope, review process, and evidence source?
Current HIPAA Security Rule Requirements for Archived ePHI
This section describes the operative HIPAA Security Rule as of September 1, 2026. According to HHS’s current summary, the rule includes risk analysis, administrative, physical, and technical safeguards, contingency planning, documentation, and business associate conditions.
The HHS Security Rule summary states that required Security Rule documentation must be kept for six years after its creation or last effective date, whichever is later. This overview is educational and is not legal advice.
Administrative Safeguards for Archive Governance
HHS’s current Security Rule summary describes administrative safeguards as policies and procedures used to select, develop, implement, and maintain security measures. For archives, apply that framework across data, users, workflows, vendors, interfaces, and recovery resources.
Key archive governance controls include:
- Risk analysis: Identify where archived ePHI exists and assess threats, weaknesses, likelihood, and impact.
- Risk management: Select, track, and document safeguards that reduce identified risks to reasonable and appropriate levels.
- Assigned responsibility: Name accountable leaders for archive security, compliance, data quality, access, and recovery.
- Workforce controls: Authorize access by role, train users, review permissions, and remove access when duties change.
- Incident procedures: Define how teams detect, escalate, investigate, contain, document, and learn from archive-related events.
- Contingency planning: Maintain backup, restoration, emergency-mode, testing, and revision procedures for archived ePHI.
- Evaluation: Reassess controls after material technical, operational, organizational, or threat changes.
A strong governance, risk, and compliance program connects each policy to operating evidence. Examples include risk records, access reviews, incident tickets, recovery results, and approved exceptions.
Physical Safeguards for Systems and Media
HHS’s current Security Rule summary describes physical safeguards for facility access, workstations, and devices or media that contain ePHI. Cloud hosting may change who operates controls, but regulated entities still need documented responsibility and oversight.
Include more than the main archive servers in your review. Assess legacy media, migration devices, removable copies, administrator workstations, backup media, and vendor facilities.
Your health data stewardship practices should also govern media reuse and final disposition. Teams need authorization, chain of custody, validation, and documentation for each controlled copy.
Technical Safeguards for Access, Auditability, and Integrity
According to HHS’s current Security Rule summary, technical safeguards include access control, person or entity authentication, audit controls, integrity protections, and transmission security. These controls apply to systems that contain or use ePHI.
For an active archive, examine events that affect confidentiality, integrity, or availability:
- User activity: Searches, record views, downloads, exports, printing, and release-of-information actions.
- Authentication events: Successful logins, failed attempts, account lockouts, emergency access, and session changes.
- Privileged activity: Configuration changes, account administration, data corrections, and support access.
- Data movement: Extracts, imports, interfaces, transfers, backup jobs, restoration, and migration staging.
- Integrity events: Reconciliation results, failed loads, altered records, deletion attempts, and validation exceptions.
Your approach to secure healthcare data archiving should support authorized access, audit trails, and integrity protections. Availability matters too, because approved users may need historical records for care, billing, audits, or operations.
Why Addressable Does Not Mean Optional
HHS’s current Security Rule summary states that the rule includes required and addressable implementation specifications. HHS also states that addressable does not mean optional.
If an addressable specification is not reasonable and appropriate, HHS requires the regulated entity to document why. The entity must implement an equivalent alternative when that alternative is reasonable and appropriate.
Apply this process to the actual archive environment. Are you documenting data sensitivity, access paths, threats, costs, controls, technical limits, and operational effects?
Start With an Archive-Specific HIPAA Risk Analysis
According to HHS’s current Security Rule summary, a regulated entity’s risk analysis must assess risks and vulnerabilities to all ePHI it creates, receives, maintains, or transmits. For an archive, document relevant assets, threats, vulnerabilities, likelihood, impact, current controls, and needed remediation.
Make the analysis repeatable rather than treating it as a one-time report. Update it after major migrations, acquisitions, vendor changes, integrations, incidents, or material changes to the threat environment.
Inventory Data Stores, Copies, Interfaces, and Vendors
Start with a complete inventory of places where archived ePHI may exist or move. Hidden copies and dependencies can create risk even when the main archive is well controlled.
Include these components:
- Repositories: Production archives, databases, indexes, object stores, and document stores.
- Working copies: Source extracts, migration staging areas, validation files, temporary exports, and support copies.
- Resilience resources: Backups, replicas, recovery environments, and offline or vendor-held media when used.
- Connections: EHR links, interfaces, APIs, file transfers, identity services, monitoring tools, and reporting platforms.
- People and providers: Users, administrators, support teams, business associates, subcontractors, and other third parties.
For each item, record its owner, location, sensitivity, criticality, support status, and control scope. This creates a shared baseline for security, privacy, compliance, and IT operations.
Trace Access Paths and Data Movement
Map how people and systems reach archived ePHI. Include routine access, emergency access, privileged support, automated interfaces, exports, and account termination.
Trace how the go-forward EHR retrieves historical information and how users authenticate. Also show where data is copied, transformed, cached, printed, or sent to another party.
The goal is not simply to reduce access. It is to provide the right access for care and operations while limiting unapproved paths and unmanaged copies.
Identify Unsupported Legacy-System Risk
Legacy applications may rely on unsupported operating systems, databases, interfaces, or hard-coded accounts. Weak logging, missed patches, and scarce technical expertise can make those environments harder to defend and recover.
Compare compensating controls with the option to migrate needed data and retire the source application. An application rationalization strategy can reduce avoidable technology exposure while preserving required information.
Keeping historical data does not always require keeping the original system running. Could retirement reduce your security, cost, staffing, and modernization burden?
Evaluate Security Controls Across the Archive Lifecycle
For HIPAA-compliant healthcare data archiving, security starts before data reaches the repository and continues through final disposition. Review controls during extraction, transfer, validation, storage, retrieval, export, support, recovery, vendor transition, and disposal.
Ask for configuration details and test results, not feature names alone. Evidence should show where a control applies, who owns it, how it performs, and when it was last reviewed.
Control Access and Authentication
Use unique identities and role-based access to separate clinical retrieval, HIM workflows, reporting, technical administration, and emergency access. Grant the least access needed and review elevated permissions more often.
Connect the archive to enterprise identity controls when appropriate. Define processes for approval, periodic review, deprovisioning, failed login response, and privileged support.
Under HHS’s current Security Rule, regulated entities must use reasonable and appropriate safeguards and person or entity authentication procedures. The current rule does not impose the January 2025 NPRM’s proposed broad MFA requirement. MFA may still be a reasonable risk-based safeguard.
Assess Encryption Without Overstating Current Law
According to HHS’s current Security Rule summary, encryption implementation specifications are addressable. A regulated entity must assess whether each specification is reasonable and appropriate, document its decision, and use an equivalent alternative when required by the addressable framework.
Do not limit the review to the primary repository. Evaluate ePHI at rest, in transit, in staging, in exports, in backups, and during migration or support.
Record the decision, affected assets, technical approach, exceptions, compensating measures, owner, and review trigger. This evidence matters as systems and threats change.
Preserve Auditability and Data Integrity
Under HHS’s current Security Rule summary, audit controls must record and examine activity in systems that contain or use ePHI. Define which events are logged, who reviews them, how alerts escalate, and how evidence remains available.
HHS’s current summary also requires policies and procedures that protect ePHI from improper alteration or destruction. Archive integrity controls should address cybersecurity events and migration accuracy.
Reconciliation, record counts, referential matching, exception handling, and user validation can show whether migrated records remain complete and usable. Review whether your team protects this evidence like other compliance records.
Which control gaps need an owner and a documented remediation date?
Plan for Backup, Recovery, and Emergency Access
According to HHS’s current Security Rule summary, contingency planning includes retrievable exact copies of ePHI, restoration procedures, emergency-mode operations, and periodic testing and revision.
HHS’s current rule does not set the January 2025 NPRM’s proposed 72-hour restoration deadline. Current recovery targets should reflect documented risk, operational need, clinical impact, dependencies, and other applicable obligations.
Define Archive Recovery Priorities
Not all archived data supports the same level of urgency. Historical clinical context, release-of-information requests, legacy accounts receivable, and long-term reporting may need different recovery sequences.
For each service, define minimum access needs, dependencies, owners, communications, and escalation paths. Set recovery objectives through your risk and business continuity process, not a claimed universal HIPAA target.
Emergency access also needs practical testing. Teams should know how authorized users reach essential information when normal identity, EHR, network, or vendor services are disrupted.
Test Restoration and Preserve Evidence
A backup is useful only if the organization can restore and use the information. Test archive restoration, identity services, integrations, search, authorization, data integrity, and expected workflows.
Document results, issues, remediation owners, and retest dates. Include recovery copies and any vendor or infrastructure dependencies that could block access.
The April 2026 OCR ransomware settlements involved over 427,000 individuals, and the entities paid a total of $1,165,000 to OCR. Do your tested controls and documented risk management stand up to leadership review?
Manage Archive Vendors and Business Associate Responsibilities
Under HHS’s current Security Rule summary, an archive provider may be a business associate when it creates, receives, maintains, or transmits ePHI on a covered entity’s behalf. Before permitting that activity, the regulated entity must obtain satisfactory assurances through a contract or other written arrangement.
The covered entity should maintain oversight consistent with its responsibilities. Security, compliance, procurement, operations, and counsel should align written terms with actual control ownership and service delivery.
Ask for Control Evidence, Not Check-Box Assurances
Vendor claims do not replace operating evidence. Ask how controls work across the systems, people, locations, subcontractors, and support processes that touch your data.
Useful due diligence questions include:
- Architecture scope: Which platforms, interfaces, identity services, backup systems, and support tools can affect archived ePHI?
- Access governance: How are accounts approved, reviewed, monitored, elevated, and removed?
- Audit controls: Which events are recorded, who examines them, and how are concerns escalated?
- Testing: What security assessments, recovery exercises, and control tests occur, and what evidence is available?
- Incident duties: Who investigates, communicates, preserves evidence, and meets contractual reporting requirements?
- Subcontractors: Which parties can access or maintain ePHI, and how are their safeguards overseen?
- Responsibility model: Which controls belong to the vendor, the health system, or both?
Compare contract promises with current procedures and test results. Resolve unclear ownership before implementation or renewal.
Plan for Contract Termination and Data Disposition
Exit planning should begin before the archive goes live. Define export formats, data validation, transition support, access termination, and evidence needed to complete a secure handoff.
Address return or destruction where feasible and continuing safeguards where destruction is infeasible. Include vendor-held copies, backups, support files, and subcontractor environments in the plan.
Retention and disposition decisions may depend on record type, jurisdiction, contracts, legal holds, and organizational policy. Use qualified counsel, then confirm your exit plan reflects those decisions.
What vendor obligation or exit dependency should you clarify before the next review?
Understand What HIPAA Does and Does Not Say About Retention
HHS’s current Security Rule summary sets a six-year period for required Security Rule documentation; it does not establish a general retention period for all medical records. Medical-record retention may instead depend on other federal rules, state law, contracts, legal holds, payer requirements, and organizational policy.
Under HHS’s current summary, required Security Rule documentation must be kept for six years from creation or last effective date, whichever is later. Do not apply that documentation period to medical records without jurisdiction- and record-specific legal review.
Govern Retention by Record Type and Jurisdiction
Use approved schedules that classify archived information by record type and applicable authority. Each data class should have an accountable owner, documented basis, review process, and disposition trigger.
Coordinate HIM, privacy, compliance, legal, security, finance, and data governance. This work should account for legal holds and changes in laws, contracts, or business needs.
Avoid placing one broad retention label on an entire archive. Clinical, financial, HR, ERP, and technical records may follow different authorities and business needs.
Control Secure Disposal and Media Reuse
Secure disposition requires more than retiring hardware. It should cover cloud copies, exports, backups, temporary files, vendor-held media, and other controlled copies across the lifecycle.
Define authorization, chain of custody, removal methods, validation, and documentation. Media reuse also needs a process that prevents prior ePHI from remaining accessible.
Match the method to the medium, technology, risk, and applicable requirements. Can you show what was approved, completed, checked, and closed?
Current HIPAA Security Rule vs. the January 2025 NPRM
The table below separates HHS’s current Security Rule from the January 2025 Federal Register NPRM. As of September 1, 2026, HHS stated that the current rule remained in effect.
The NPRM was not a final rule as of that date. Every proposal below remains conditional and would apply only if HHS finalizes it.
| Topic | Current requirement | Proposal if finalized as drafted | Archive implication | Prudent readiness action |
|---|---|---|---|---|
| Asset visibility | Under HHS’s current rule, risk analysis must cover all ePHI a regulated entity handles. | If finalized as drafted, the January 2025 NPRM would require written technology asset inventories and network maps. | Archives, interfaces, identity paths, backups, and support tools would need clear mapping. | Build and maintain an archive inventory with owners and dependencies. |
| Risk analysis | Under HHS’s current rule, regulated entities must assess risks and vulnerabilities to ePHI. | If finalized as drafted, the January 2025 NPRM would require more detailed written elements and review practices. | Archive threats, copies, users, vendors, and recovery resources would need deeper documentation. | Standardize the method, evidence, approvals, and remediation tracking. |
| Encryption | Under HHS’s current rule, encryption implementation specifications are addressable. | If finalized as drafted, the January 2025 NPRM would require encryption at rest and in transit, subject to proposed exceptions. | Repositories, staging data, exports, backups, transfers, and support copies could be affected. | Document present decisions, exceptions, coverage, and technical gaps. |
| MFA | HHS’s current rule requires reasonable safeguards and authentication procedures, not the NPRM’s proposed broad MFA requirement. | If finalized as drafted, the January 2025 NPRM would require MFA for relevant technology assets, subject to proposed exceptions. | User, administrator, vendor, and emergency access paths could require changes. | Review MFA coverage and document excluded or dependent workflows. |
| Vulnerability management | Under HHS’s current rule, risk management must use reasonable and appropriate safeguards for identified risks. | If finalized as drafted, the January 2025 NPRM would require automated scans at least every six months, with risk-based increases. | Archive platforms and supporting assets would need defined scanning scope and evidence. | Confirm asset coverage, ownership, remediation, and exception handling. |
| Security testing | Under HHS’s current rule, evaluation duties apply initially and after relevant environmental or operational changes. | If finalized as drafted, the January 2025 NPRM would add annual penetration testing, compliance audits, and control testing. | Vendors and internal teams would need coordinated testing and evidence exchange. | Clarify test scope, schedules, findings, ownership, and retesting. |
| Network controls | HHS’s current rule requires reasonable and appropriate safeguards but does not categorically require network segmentation. | If finalized as drafted, the January 2025 NPRM would require segmentation under specified conditions. | Archive tiers, management planes, integrations, and recovery environments could need review. | Map trust boundaries and assess pathways between archive components. |
| Recovery | Under HHS’s current rule, contingency planning includes backups, restoration, emergency operations, and testing. | If finalized as drafted, the January 2025 NPRM would require certain critical systems and data to be restored within 72 hours. | Criticality and dependencies would need precise classification and test evidence. | Define risk-based recovery priorities and test full workflows now. |
| Business associates | Under HHS’s current rule, applicable business associate relationships require satisfactory assurances in a contract or other written arrangement. | If finalized as drafted, the January 2025 NPRM would add verification duties for business associate safeguards. | Vendor evidence and responsibility mapping would become more important. | Strengthen due diligence, contract alignment, and evidence reviews. |
Regulatory Status as of September 1, 2026
HHS announced the proposed changes in December 2024, and the Federal Register published the NPRM on January 6, 2025. A notice of proposed rulemaking begins rulemaking; it does not create an operative final rule.
As of September 1, 2026, HHS’s proposed-rule page still identified the action as proposed. HHS’s current Security Rule summary stated that the current rule remained in effect, with no final effective or compliance date established for the proposal.
Do not label the proposed controls as 2026 HIPAA requirements. Any future duties and dates would depend on the text and publication of a final rule.
Proposed Provisions Most Relevant to Archives
If finalized as drafted, the NPRM would change several archive planning assumptions. Health systems should track affected assets, owners, dependencies, evidence, exceptions, and implementation questions.
If finalized as drafted, the proposed provisions would include:
- Written visibility: The January 2025 NPRM proposed technology asset inventories and network maps for assets that may affect ePHI.
- Detailed risk analysis: The January 2025 NPRM proposed written analyses covering specified assets, threats, vulnerabilities, likelihood, impact, and risk levels.
- Encryption: The January 2025 NPRM proposed encryption of ePHI at rest and in transit, subject to proposed exceptions.
- MFA: The January 2025 NPRM proposed MFA for relevant technology assets, subject to proposed exceptions.
- Vulnerability management: The January 2025 NPRM proposed automated scans at least every six months and more often when risk warrants.
- Testing: The January 2025 NPRM proposed annual penetration tests, compliance audits, and control testing.
- Segmentation: The January 2025 NPRM proposed network segmentation under specified conditions.
- Business associate verification: The January 2025 NPRM proposed added verification of business associate safeguards.
- Backup controls: The January 2025 NPRM proposed separate backup-related protections for electronic information systems.
- Critical restoration: The January 2025 NPRM proposed restoring certain critical systems and data within 72 hours.
The Federal Register NPRM proposed scans at least every six months and restoration of certain critical systems and data within 72 hours. These are proposed benchmarks, not current HIPAA deadlines.
What Health Systems Can Prepare Now
Preparation does not require treating the NPRM as final. Many readiness steps also support current risk analysis, risk management, resilience, and evidence quality.
Focus on practical housekeeping:
- Inventory the environment: Confirm archive assets, ePHI stores, interfaces, identity paths, copies, vendors, and recovery resources.
- Map data movement: Document routine, privileged, emergency, export, integration, support, and termination paths.
- Review safeguards: Reassess encryption, MFA, access, logging, scanning, patching, segmentation, and compensating-control decisions.
- Test access and recovery: Validate authorization, search, retrieval, integrity, dependencies, and expected workflows after restoration.
- Address legacy exposure: Compare continued operation of unsupported systems with migration and retirement options.
- Strengthen evidence: Record owners, scope, exceptions, approvals, test results, remediation, and review dates.
- Improve vendor oversight: Align contracts, operating responsibilities, subcontractor controls, incident duties, and exit plans.
These steps can reduce current risk and improve future flexibility. Which readiness actions should your team prioritize now?
An Archive Readiness Checklist for Security and Compliance Teams
Use this checklist in a working session with security, privacy, compliance, HIM, infrastructure, applications, recovery, procurement, and legal stakeholders. For each item, assign an owner, evidence location, review trigger, and status.
Keep the checklist connected to remediation work. A completed box has little value when evidence is missing, stale, or outside the control’s real scope.
Scope and Governance Checks
- Confirm archive scope: List ePHI data classes, repositories, copies, media, interfaces, exports, and recovery environments.
- Name accountable owners: Assign responsibility for security, privacy, infrastructure, data governance, access, integrity, vendors, and recovery.
- Record criticality: Classify services by clinical, compliance, revenue-cycle, and operational impact.
- Document retention authority: Link each data class to its approved schedule, authority, owner, and disposition trigger.
- Include third parties: Identify business associates, subcontractors, support providers, and shared control responsibilities.
- Capture legacy dependencies: Include unsupported applications, identity services, interfaces, databases, and specialized technical knowledge.
- Update the risk register: Record threats, weaknesses, treatment decisions, owners, deadlines, acceptance, and review triggers.
Control and Evidence Checks
- Review access: Verify unique users, roles, least privilege, emergency access, privileged administration, and periodic review.
- Test deprovisioning: Confirm access ends after role changes, terminations, vendor changes, and contract closure.
- Document authentication: Record present controls, MFA decisions, exceptions, dependencies, and compensating measures.
- Review encryption decisions: Cover repositories, transfers, staging, exports, backups, recovery copies, and support workflows.
- Examine audit controls: Verify event coverage, review ownership, alert escalation, evidence protection, and follow-up.
- Validate integrity: Check migration reconciliation, referential matching, record completeness, usability, and exception resolution.
- Assess technical exposure: Review patching, vulnerabilities, unsupported components, isolation, and compensating controls.
- Confirm incident readiness: Test detection, escalation, investigation, evidence preservation, communications, and remediation.
- Record testing evidence: Keep dates, scope, methods, findings, owners, corrections, approvals, and retest results.
Recovery and Vendor Checks
- Verify retrievable copies: Confirm complete, protected, and recoverable copies of archived ePHI.
- Set recovery priorities: Define risk-based sequences for clinical, HIM, financial, ERP, and reporting use cases.
- Test full restoration: Validate identity, integration, authorization, search, integrity, and workflow usability.
- Confirm emergency access: Test approved access when normal identity, EHR, network, or vendor services fail.
- Review written arrangements: Confirm applicable BAAs, security terms, responsibilities, incident duties, and subcontractor controls.
- Inspect vendor evidence: Review access controls, logs, testing, recovery results, exceptions, and remediation.
- Plan the exit: Define export, validation, transition support, access removal, return or destruction, and closure evidence.
Review each open item with its assigned owner. Which controls still lack current evidence or a clear review trigger?
How Active Archiving Can Reduce Legacy Risk
Active archiving moves required information into a governed repository that supports ongoing, authorized use. It can help health systems retire redundant or unsupported applications without losing access to needed data.
Results depend on implementation, migration quality, control design, and ongoing operations. An archive is not automatically compliant, secure, or resilient because of its product category.
Preserve Access Without Preserving the Legacy Application
Health systems need historical information, but they may not need every aging application that once held it. A well-planned active archive can preserve contextual access to clinical, financial, and ERP records after source retirement.
Access may include EHR integration, single sign-on, release-of-information workflows, audit support, billing activity, and authorized reporting. The design should reflect real user needs without carrying unnecessary legacy risk.
MediQuant’s DataArk® supports centralized access to legacy healthcare data across multiple systems and data types. Product fit still requires a review of configuration, responsibilities, integrations, safeguards, evidence, and operational needs.
Evaluate an Archive Partner Against Operational Evidence
Look for healthcare-specific experience with complex, multi-system archives and migrations. Ask how the partner protects integrity, maintains access, supports audits, tests recovery, and divides control responsibilities.
Buyer questions should include:
- Migration method: How are data extraction, reconciliation, referential matching, exceptions, and user validation managed?
- Access workflows: How do clinical, HIM, financial, technical, and emergency users reach the right records?
- Control evidence: What configurations, reviews, logs, tests, and remediation records can the partner provide?
- Recovery proof: Can restored data be searched, authorized, understood, and used in expected workflows?
- Exit readiness: How will data, metadata, evidence, and access transfer at contract end?
- Measured results: Which implementation outcomes can be supported with defined scope and customer-approved evidence?
MediQuant brings experience from thousands of complex, multi-system archives. Ask whether that experience fits your organization’s legal, security, compliance, and operational needs.
Frequently Asked Questions About the HIPAA Security Rule and Archived Data
These answers summarize the article’s federal Security Rule guidance as of September 1, 2026. They are educational and do not replace advice based on your organization’s facts and applicable laws.
What Is the HIPAA Security Rule’s Primary Purpose?
According to HHS’s current summary, the rule protects the confidentiality, integrity, and availability of ePHI handled by regulated entities. That includes archived ePHI while it remains electronically maintained.
What Are the Three HIPAA Security Rule Safeguard Categories?
HHS’s current summary identifies administrative, physical, and technical safeguards. Archive examples include governance policies, media controls, access controls, audit controls, and integrity protections.
Does the HIPAA Security Rule Apply to Inactive or Archived ePHI?
According to HHS’s current summary, yes, when a covered entity or business associate electronically maintains the information as ePHI. Production status does not remove applicable Security Rule duties.
Does Addressable Mean a Safeguard Is Optional?
No. HHS states that addressable does not mean optional. It requires a documented assessment and an equivalent alternative when that alternative is reasonable and appropriate.
Is Encryption Required for Archived ePHI?
HHS’s current summary treats encryption specifications as addressable under the current rule. If finalized as drafted, the January 2025 NPRM would require encryption at rest and in transit, subject to proposed exceptions.
Is MFA Mandatory Under the Current HIPAA Security Rule?
HHS’s current rule requires reasonable safeguards and authentication procedures, not the NPRM’s proposed broad MFA requirement. If finalized as drafted, the January 2025 NPRM would add MFA requirements with proposed exceptions.
Did the 2025 HIPAA Security Rule Proposal Take Effect in 2026?
No, not as of September 1, 2026. HHS stated that the current Security Rule remained in effect, and the January 2025 NPRM remained proposed.
How Should a Health System Conduct Risk Analysis for an Archive?
HHS’s current summary requires risk analysis across all ePHI a regulated entity handles. Include archive systems, media, copies, interfaces, users, vendors, threats, vulnerabilities, impact, controls, and remediation.
What Documentation Must Be Retained Under the Security Rule?
HHS’s current summary requires Security Rule documentation to be kept for six years from creation or last effective date, whichever is later. That period is not a universal medical-record retention rule.
Build a Defensible Archive Roadmap
Start by confirming your archive scope, controls, evidence, recovery plans, vendors, and unsupported dependencies. Then prioritize gaps by risk, operational impact, ownership, and effort.
Use the January 2025 NPRM as a planning signal, not as current law. A defensible roadmap protects needed data and access while reducing avoidable legacy exposure.
MediQuant helps health systems archive legacy clinical, financial, and ERP data while supporting authorized access and system retirement. Learn More about MediQuant’s approach to enterprise healthcare data archiving.









