Expected HIPAA Updates Now Postponed to Given More Time

The HHS Office for Civil Rights (OCR) has postponed final action on its proposed overhaul of the HIPAA Security Rule from May 2026 to July 2027, so the existing Security Rule remains the enforceable standard and the proposed mandates for encryption, multi-factor authentication, penetration testing, and vulnerability scanning have not taken effect. The proposal has been delayed, not withdrawn. Covered entities and business associates remain subject to the current rule in full.

Background to the Proposed Security Rule Changes

HHS issued the Notice of Proposed Rulemaking in December 2024, and it was published in the Federal Register on January 6, 2025. The proposal is tracked as RIN 0945-AA22. The Security Rule was first adopted in 2003 and was last materially amended by the 2013 Omnibus Rule. The proposal was issued during the final weeks of the Biden administration and aims to strengthen the cybersecurity of electronic protected health information (ePHI) in response to the growth in cyberattacks and ransomware incidents. The 2024 Change Healthcare attack was one of the incidents cited in the policy debate.

Removal of the Addressable Implementation Specification

The current Security Rule divides implementation specifications into two categories, required and addressable. Addressable does not mean optional. A regulated entity must assess whether an addressable specification is reasonable and appropriate for its environment. If it is not, the entity must document the reason and implement an equivalent alternative measure where reasonable and appropriate.

The proposed rule removes this distinction. With limited exceptions, every implementation specification would become required. Regulators viewed the addressable category as a route some organizations used to avoid implementing safeguards such as encryption, citing cost or complexity without adopting an effective alternative.

Proposed Technical Safeguard Requirements

The most significant proposed changes include mandatory encryption of ePHI at rest and in transit and mandatory multi-factor authentication for all systems that access ePHI. Both would replace the flexible standards in the current rule, subject to narrow exceptions. The proposal does not name specific algorithms. It requires encryption consistent with prevailing cryptographic standards.

The proposal also calls for network segmentation, anti-malware protection, removal of extraneous software, and the disabling of unused network ports. Legacy systems unable to support the required safeguards would need to be upgraded, replaced, or covered by a documented exception where one applies.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Proposed Testing and Documentation Requirements

The proposed rule converts periodic review into scheduled technical testing. Regulated entities would perform vulnerability scanning at least every six months. Penetration testing would be required at least once every 12 months and performed by qualified persons with knowledge of generally accepted cybersecurity principles.

Documentation requirements would expand. Regulated entities would maintain a written technology asset inventory and a network map showing the movement of ePHI through their systems. Both would be reviewed at least every 12 months and whenever a change in the environment affects ePHI. A device used to access patient records that is absent from the inventory would be a compliance failure. The risk analysis would need to be written and contain specified elements, and a compliance audit would be conducted at least every 12 months.

Proposed Business Associate Requirements

Covered entities would obtain written verification from business associates, at least every 12 months, that the required technical safeguards are in place. The verification would include a written analysis by a qualified subject matter expert and a certification by an authorized representative. Business associates would notify covered entities within 24 hours of activating a contingency plan.

Postponement of the Final Rule

In the Fall 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, HHS moved the proposed amendments to its Long-Term Actions agenda and set July 2027 as the anticipated timeframe for final action. HHS has not publicly explained the move, and the Unified Agenda includes no discussion of the agency’s reasoning.

Industry opposition preceded the delay. HHS received nearly 5,000 public comments, and many healthcare organizations and industry groups objected that the requirements were too difficult and costly to implement. A coalition of more than 100 hospital and provider groups asked HHS to withdraw the proposal. The HHS regulatory impact analysis estimated first-year compliance costs of approximately $9 billion. Smaller practices argued the costs would divert funds from patient care. Industry groups also criticized the proposed implementation timeframe as unworkable.

The July 2027 date is not binding. Federal regulatory timeframes carry no legal force, so the date could slip again, and OCR could also release a final rule ahead of July 2027. The proposal may be revised before publication.

Current HIPAA Security Rule Obligations Remain Enforceable

The proposed amendments were never in effect, so no requirement has been suspended. The existing Security Rule applies in full. OCR enforcement continues to focus on accurate and thorough risk analysis, risk management, business associate oversight, workforce training, and remediation of known vulnerabilities. OCR has issued repeated settlements and penalties under its Risk Analysis Initiative for failures to conduct compliant risk analyses.

Encryption remains an addressable specification under the current rule. An organization that has not encrypted ePHI must hold a documented assessment explaining that decision and the equivalent measure implemented in its place. Absent that documentation, the organization is out of compliance today.

Compliance Actions During the Postponement Period

Regulated entities can use the additional time to close gaps between current practice and the proposed framework. Most of the proposed safeguards already reflect accepted cybersecurity practice. Implementing them now reduces breach risk under the current rule and shortens the work required once a final rule is published.

Start with a technology asset inventory. Record every server, workstation, laptop, mobile device, and application that creates, receives, maintains, or transmits ePHI. Confirm the encryption status of each asset holding ePHI, and schedule upgrades or replacements for systems that cannot support encryption.

Verify that multi-factor authentication is enabled for the electronic health record system, email, remote access, and cloud services. Run a vulnerability scan and remediate the findings. Scan reports that are filed without follow-up provide no compliance value.

Obtain quotes for penetration testing and allocate budget for an annual test. Review business associate agreements and request information from vendors on their encryption, MFA, and testing practices. Update the risk analysis to reflect all changes.

Document each decision, assessment, and remediation step. The Security Rule requires regulated entities to retain required documentation for six years from the date of creation or the date it was last in effect, whichever is later.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/