Managed IT
Client Platform Custom Software
Industries
Plans & Pricing About Client Login
August 25, 2026TechPro IT Solutions

The End of 'Addressable' Security: MFA and Encryption in 2026

HIPAA, FTC, and PCI rules are turning 'addressable' MFA and encryption into hard requirements. See what South Florida businesses must do now.

The End of 'Addressable' Security: MFA and Encryption in 2026

The word "addressable" has a specific meaning in HIPAA's Security Rule, and for two decades businesses have leaned on that meaning to put off basic security work. That era is ending — not just in healthcare, but across nearly every regulatory framework that touches South Florida businesses. If your compliance checklist still treats multi-factor authentication or encryption as "nice to have," 2026 is the year that assumption gets expensive.

Key takeaways
  • HHS OCR's December 2024 proposal would eliminate the "addressable" category in HIPAA almost entirely — but as of mid-2026 it's still unfinalized.
  • The FTC Safeguards Rule and PCI DSS 4.0.1 already require MFA today — no waiting on a final rule needed.
  • Florida's FIPA law gives encrypted data a legal safe harbor, excusing breach notification obligations that unencrypted data doesn't get.
  • Businesses that build a compliance checklist now, across all applicable frameworks, avoid scrambling when deadlines finally land.

Why 'Addressable' Is Becoming a Dangerous Word

HIPAA's Security Rule has long split its requirements into two buckets: "required" specifications and "addressable" ones. Addressable never meant optional — covered entities were still supposed to implement the safeguard, document why they couldn't, or put an equivalent alternative in place. In practice, though, that distinction created wiggle room. Plenty of businesses used "addressable" as cover to delay MFA rollouts or skip encryption projects for years, betting that a documented risk assessment would be enough if an auditor ever asked.

Regulators noticed. On December 27, 2024, HHS's Office for Civil Rights issued a Notice of Proposed Rulemaking that would remove the required-versus-addressable distinction and make nearly all implementation specifications mandatory, with only limited exceptions [F2]. That's a healthcare-specific proposal, but it reflects a pattern showing up everywhere: the FTC, the payment card industry, and Florida's own breach-notification law are all moving in the same direction — fewer gray areas, more hard requirements.

HIPAA's Proposed Overhaul: What's Actually Changing

The proposed rule was published in the Federal Register on January 6, 2025, and its public comment period closed March 7, 2025 [F3]. As of mid-2026, it still isn't final [F3]. OCR had originally targeted spring 2026 for finalizing it, but the Office of Management and Budget's own Unified Agenda now points to July 2027 [F4]. In other words: this rule is coming, but slower than regulators themselves expected.

That delay doesn't mean the substance is going away. As proposed, the rule would require vulnerability scans at least every six months and penetration testing at least every twelve months [F6]. It would also impose real time limits on incident response: a 24-hour notification window when a contingency plan is activated, and a 72-hour window to restore data [F6]. Perhaps most striking for offices with regular staff turnover, it would require cutting off a former employee's system access no later than one hour after their employment ends [F7].

For small and mid-size medical practices, this likely means budgeting for new scanning tools, staff time to document offboarding and access procedures, and possibly outside help to manage the compliance paperwork these rules require. For medical offices and their business associates, this is a strong argument for HIPAA-ready medical office IT built around these controls now, rather than a rushed retrofit once the rule locks in.

FTC Safeguards Rule: MFA and Encryption Aren't Optional Anymore

While HIPAA's overhaul sits in regulatory limbo, the FTC Safeguards Rule is already fully in force — and it applies to more South Florida businesses than most owners realize. It covers non-bank financial institutions: mortgage brokers, auto dealers, tax preparers, and similar businesses, regardless of company size [F8]. The rule mandates multi-factor authentication for all covered companies [F8].

The FTC is also specific about what counts as acceptable MFA. It requires at least two of three factor types: something you know (a password), something you have (a token), and something you are (biometrics) [F9]. Notably, FTC guidance discourages basic SMS codes and un-matched push notifications — the methods most businesses already use — because anyone who can be tricked into typing a password can be tricked into typing a text code too, but it supports phishing-resistant methods and push notifications with number-matching [F10].

If a user can be tricked into typing in their username and password, they can be tricked into typing a code from their phone.

On encryption, the standard is just as direct: covered businesses must encrypt customer data both on their systems and in transit, or document effective alternative controls approved by a Qualified Individual if encryption isn't feasible [F11]. For wealth management and financial services firms in West Palm Beach, where credential theft remains a persistent risk given the sensitivity of client financial data, this isn't abstract policy — it's the baseline clients now expect.

Employee completing multi factor authentication requirements using a hardware security key

PCI DSS 4.0.1: Universal MFA for Cardholder Data

If your business takes card payments — a restaurant in Delray Beach, a retail shop in Boca Raton, a service business anywhere in between — PCI DSS applies to you, and it just got stricter. The previous standard only required MFA for administrators accessing the cardholder data environment. Under PCI DSS 4.0.1, MFA is now required for all access to that environment, regardless of role [F12].

The transition period ended March 31, 2025, so this isn't a future deadline — full compliance is enforceable now [F13]. Any business that stores, processes, or transmits cardholder data on their own networks is in scope. While micro-businesses using isolated, standalone payment terminals may avoid these specific MFA requirements, any business running integrated POS systems or back-office accounting networks must comply. This is a common gap our team sees during cybersecurity compliance services engagements: businesses that locked down admin accounts years ago but never extended MFA to the front-line staff and systems that also touch cardholder data.

Florida's Own Rules: FIPA Breach Notification and the Encryption Safe Harbor

Even businesses outside healthcare, finance, and card processing aren't off the hook. Florida's Information Protection Act (FIPA) requires notifying affected individuals within 30 days of discovering a breach [F14]. If 500 or more Florida residents are affected, you also have to notify the Florida Attorney General within that same 30-day window [F14].

Here's the part worth building your whole encryption strategy around: FIPA's definition of "personal information" excludes data that's encrypted, secured, or otherwise rendered unusable [F15]. That's a genuine legal safe harbor. If the data a breach exposes was properly encrypted, it may not trigger notification obligations at all. Encryption in Florida isn't just a technical safeguard — it's liability protection with a real statutory basis. That matters especially in the midst of hurricane season, when Miami-Dade and Broward infrastructure — ports, hospitals, utilities, schools rebuilding after storm-related outages — face a higher risk of systems being exposed or improperly restored under pressure. Encryption key management, done right, is as much a disaster-recovery issue as a security one.

Building Your 2026 Cybersecurity Compliance Checklist

With four different frameworks potentially in play, the fastest way to get ahead of all of them is a straightforward audit, not a scramble once a rule finalizes.

  1. Inventory which frameworks actually apply to you — HIPAA, FTC Safeguards, PCI DSS, and FIPA all have different triggers, and most businesses fall under more than one.
  2. Deploy phishing-resistant MFA across critical systems, avoiding SMS and one-time passcodes where possible.
  3. Encrypt data at rest and in transit, including full-disk encryption on endpoints, and rotate database or API encryption keys on a regular schedule.
  4. Schedule vulnerability scans and penetration tests on a recurring cadence now, ahead of any mandate that makes it official.
  5. Document offboarding procedures so departing employees lose system access quickly and consistently.
  6. Identify systems that can't support modern MFA and decide whether to replace, isolate, or formally accept that risk — don't let it sit undocumented.

This checklist also matters for reasons beyond regulators. Our guide on implementing IAM in modern offices covers how identity and access management ties these pieces together day to day, and our cyber insurance requirements checklist walks through how insurers now expect many of these same controls before they'll even write a policy.


Frequently asked questions

What MFA requirements apply to Florida businesses in 2026?

It depends on your industry: non-bank financial businesses must follow the FTC Safeguards Rule's MFA mandate, card-processing businesses must meet PCI DSS 4.0.1's universal MFA requirement, and healthcare entities are watching HIPAA's proposed overhaul. Most Florida businesses are already subject to at least one of these frameworks even if they don't realize it.

Do I need to implement multi-factor authentication for my company?

If you handle card payments, financial data, or health information, MFA is already required or effectively unavoidable under current or pending rules. Even outside strict regulatory triggers, MFA is considered baseline due diligence for cyber insurance and breach liability protection.

Are there full-disk encryption requirements for South Florida small businesses?

There's no single blanket law mandating full-disk encryption for every small business, but FIPA's safe harbor exempts encrypted data from breach notification requirements, and the FTC Safeguards Rule requires encryption for covered financial data. Practically, encryption has become the default expectation across nearly every framework.

What security standards apply to my Miami or South Florida business in 2026?

You'll likely fall under some combination of FIPA (all Florida businesses), PCI DSS 4.0.1 (if you accept cards), the FTC Safeguards Rule (financial-adjacent services), and HIPAA (healthcare and business associates). A cybersecurity compliance checklist tailored to your industry is the fastest way to identify your actual obligations.

How much does MFA and encryption implementation cost for a small business?

Costs vary widely depending on how many systems and users are involved, but the typical cost drivers are consistent: ongoing SaaS licensing for an MFA or identity platform billed per user, plus the one-time labor to configure it, roll it out to staff, and retire weaker methods like SMS codes. Encryption adds similar line items — endpoint and disk-encryption tooling plus the implementation time to deploy it across devices and servers. For an individual small business, working with an MSP typically brings these costs down by bundling the licensing and labor into managed security services rather than buying and configuring each piece separately.

What are the penalties for not having MFA and encryption in Florida?

Penalties range from FIPA breach notification liability and Florida Attorney General enforcement to loss of the FTC's safe harbor protections and PCI non-compliance fines from payment processors. Beyond regulatory penalties, missing controls can also void cyber insurance claims after a breach.

Is there a hard deadline for the MFA and encryption mandate in South Florida?

PCI DSS 4.0.1's universal MFA requirement is already enforceable as of March 31, 2025. HIPAA's broader overhaul remains unfinalized, with federal timelines now pointing to 2027, but the FTC Safeguards Rule and Florida's FIPA already impose real, current obligations.


Waiting for a final rule before you act on MFA and encryption is the same bet that got a lot of businesses in trouble under "addressable" — and the frameworks that are already enforceable today won't wait. If you're not sure which of these rules apply to your business, schedule a free IT assessment and we'll walk through it with you.

cybersecurity complianceMFAdata encryptionHIPAA
Back to all posts

Have a question about your business technology?

Start with a free IT assessment — a clear, no-pressure look at where things stand and what managed IT could do for you.