Medicare & MIPS

MIPS and the security risk analysis: the December 31 rule

Published July 24, 2026

Most HIPAA “deadlines” you’ll read about online are invented. Here is one that’s real, dated, and federal — along with an honest map of exactly who it binds, because it is narrower than the marketing around it suggests.

The rule, plainly

Medicare’s Merit-based Incentive Payment System — MIPS — has a category called Promoting Interoperability, the part that scores how a practice uses its certified EHR. To score in that category at all, the practice must attest “yes” to its Security Risk Analysis measure, and as of 2026 that means two things: a security risk analysis conducted or reviewed, and risk-management work on what it found — the same two duties HIPAA’s Security Rule already assigns. CMS’s spec is explicit about timing: the analysis “must be conducted within the calendar year of the performance period (January 1st – December 31st).”

The spec is equally explicit about the consequence: failure means “no score for the Promoting Interoperability performance category, regardless of whether other measures in this category are reported.” In the standard weighting that category is a quarter of the MIPS final score. You submit the attestation early the following year — but the analysis itself cannot slide past December 31.

Who this actually binds

Fewer practices than the countdown-marketing implies. Walk the gates in order:

  • The low-volume threshold. MIPS is required only if you exceed all three: more than $90,000 a year in Medicare Part B professional services, more than 200 Part B patients, and more than 200 covered services. Many solo practices are out on this gate alone.
  • The small-practice reweighting. Practices with 15 or fewer clinicians get the Promoting Interoperability category automatically reweighted to zero — no EHR reporting expected. But it’s opt-in-then-binding: a small practice that chooses to report the category anyway cancels its own reweighting, and the December 31 rule then applies in full.
  • Clinician type. Counselors and marriage-and-family therapists became able to bill Medicare in 2024 — but they are not MIPS-eligible clinician types, so none of this applies to them. (The eligible list runs physicians, PAs, NPs, psychologists, PTs, OTs, clinical social workers, and a few more.)
  • Certified EHR. Scoring the category requires certified EHR technology in place, with at least 180 continuous days of data in the calendar year.

Put together: this deadline genuinely binds medical groups that report Promoting Interoperability — a real population; per CMS’s published 2023 experience data, roughly 370,000 clinicians attested this measure — and genuinely does not bind most solo practices, therapists, or dentists. If someone uses MIPS to sell you urgency without asking which side of those gates you’re on, they’re selling, not informing.

If it binds you

The analysis has to be your practice’s own, for this calendar year — CMS requires it unique to the performance period and scoped to it. December is also the worst month to start: end-of-year clinical crunch plus an analysis that takes real time is how attestations get signed on hope. Doing it mid-year costs nothing extra and takes the date pressure out.

If it doesn’t bind you

The duty doesn’t vanish — it just loses the date. The security risk analysis requirement comes from the HIPAA Security Rule itself and applies to practices covered by HIPAA, whatever their size, on no particular calendar — federal enforcement has made it a focus since 2024.

A documented, dated analysis is worth having on file either way. The free assessment walks you through it and ends in that paper trail.

Start HIPAAPath free

Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.