The 2025 HIPAA Security Rule updates take effect in 2026 and introduce stricter
technical safeguard requirements for any entity that handles electronic protected health
information (ePHI) — including law firms that receive medical records.
This checklist from our friends at LlamaLab helps your firm assess exposure and close
gaps before OCR enforcement ramps up.