The HIPAA
Security Rule Is Changing. Here Is Where Things Actually Stand.
The Garlick Group | July 2026
Healthcare
compliance officers have spent eighteen months preparing for a rule that has
not yet arrived. On December 27, 2024, the Department of Health and Human
Services Office for Civil Rights released the first substantial overhaul of the
HIPAA Security Rule since 2013, publishing it formally in the Federal Register
on January 6, 2025.
The proposal is
not modest. It would eliminate the long-standing distinction between “required”
and “addressable” implementation specifications, converting nearly every
safeguard on the list into a mandatory obligation. 1 Encryption of
electronic protected health information, both in transit and at rest, would no
longer be a matter of documented risk judgment. Multi-factor authentication
would become standard. Organizations would need to maintain a current
technology asset inventory and a network map showing how ePHI moves through
their systems, updated annually. Vulnerability scans would run twice a year,
penetration testing once. Security incidents would require containment and
reporting within seventy-two hours. 2
Business
associates absorb a disproportionate share of the new burden. The proposal
introduces the term “HIPAA-regulated entity” to describe covered entities and
business associates under a single standard, extends direct liability to
subcontractors of business associates, and requires annual written verification
that a business associate's safeguards remain in place. A covered entity that
once relied on a signed agreement would need ongoing documentation instead.
None of this is
law yet. That distinction matters more than the trade press coverage sometimes
suggests. HHS's Spring 2025 regulatory agenda targeted a final rule for May
2026. That date has now passed without a final rule. 3 As of early
July 2026, HHS has pushed final action to at least July 2027, treating the
delay as a postponement rather than an abandonment. Separately, the department
has signaled it will move ahead with changes to the HIPAA Privacy Rule as early
as August 2026, on a track independent of the Security Rule proceeding. 4
The comment
record explains some of the delay. OCR received roughly 4,745 public comments
during the period that closed March 7, 2025, and officials have said at
industry conferences that each one is being read. A coalition led by the
College of Healthcare Information Management Executives, joined by more than
one hundred hospital systems and provider organizations, sent HHS a letter in
December 2025 urging withdrawal of the proposal outright. The coalition's
argument centers on cost: HHS itself estimated first-year compliance at
approximately nine billion dollars industry-wide, a figure the coalition
considers unworkable for small and rural providers operating on thin margins.
The political
backdrop adds its own uncertainty. The proposal was among the final regulatory
acts of the prior administration, and the current administration's general
posture toward deregulation leaves open the possibility that a final rule, if
it comes at all, looks considerably lighter than what was proposed. 5
There is also a countervailing pressure: bipartisan concern about healthcare
cybersecurity has not diminished. Large HIPAA breaches affected more than 286
million individuals in 2024, and hacking or IT incidents caused 76 percent of
large breaches in 2025. Those numbers give OCR a continuing rationale for
finalizing something, even if the something is narrower than the current draft.
6
What this means
operationally is worth stating plainly. The current Security Rule remains fully
in force and fully enforced. OCR has continued to cite deficient risk analysis
as the most common finding in its investigations, and the agency's enforcement posture
under existing law has not softened while the proposed rule sits in review.
Waiting for finalization before improving a risk management program mistakes a
drafting delay for a compliance holiday.
Organizations
that began closing gaps against the proposed standard in 2025, rather than
waiting for a published final rule, are better positioned regardless of how
this resolves. A completed technology asset inventory, a documented network
map, encryption at rest and in transit, and a current, evidence-backed risk
analysis are defensible investments under the rule as it exists today. They
also happen to be the exact controls most likely to survive into whatever
version of the rule eventually gets published, whether that happens in 2027 or
later still.
If the rule is
finalized largely as proposed, the compliance runway will be short: OCR has
floated a 240-day window from publication to compliance, with business
associate agreements given a full year to update. 7 A 240-day sprint
to build a risk analysis, asset inventory, and network map from a standing
start is a difficult undertaking for a large health system and a punishing one
for a small practice. The lesson from the 2013 Omnibus Rule, and from every
major HIPAA update since, is that the organizations caught flat-footed are
rarely the ones that lacked warning. 8
Endnotes
1. Bill Toulas [HIPAA Journal], “The Impact of
Proposed Changes to the HIPAA Security Rule for Business Associates,” HIPAA
Journal, May 19, 2026,
https://www.hipaajournal.com/hipaa-security-rule-business-associates/.
2. RubinBrown, “HIPAA Security Rule Changes:
2025 & 2026 HIPAA Updates,” February 19, 2026,
https://www.rubinbrown.com/insights-events/insight-articles/hipaa-security-rule-changes-2025-2026-hipaa-updates/.
3. Alston & Bird, “HIPAA Security Rule:
Still on Track for Finalization,” November 4, 2025,
https://www.alston.com/en/insights/publications/2025/11/hipaa-security-rule-overhaul.
4. Clearwater, “HIPAA Security Rule Enforcement:
Where Things Stand in 2026,” July 2026,
https://clearwatersecurity.com/blog/hipaa-security-rule-enforcement-2026/.
5. HIPAA Journal, “New HIPAA Regulations in
2026,” accessed July 12, 2026,
https://www.hipaajournal.com/new-hipaa-regulations/.
6. Clearwater, “HIPAA Security Rule Enforcement:
Where Things Stand in 2026,” July 2026,
https://clearwatersecurity.com/blog/hipaa-security-rule-enforcement-2026/.
7. Medcurity, “HIPAA Security Rule Changes in
2026: What You Need to Know (and Do) Now,” updated June 6, 2026,
https://medcurity.com/hipaa-security-rule-changes-2026/.
8. Compliancy Group, “The Proposed HIPAA
Security Rule Update: What It Would Change and How to Prepare,” May 28, 2026,
https://compliancy-group.com/proposed-hipaa-security-rule-update-2026/.
No comments:
Post a Comment