Multi-factor authentication must be enforced for every user accessing any system containing PHI — remote or onsite. No exceptions. Practices still relying on passwords alone are out of compliance the moment this rule finalizes.
ePHI must be encrypted at rest and in transit. Previously you could document why you didn't implement it. That flexibility is gone. Every file, every device, every transfer — encrypted.
Your contingency plan must prove the ability to restore critical systems within 72 hours of an incident. Annual testing is required. Written documentation of results is required.