Tuesday, July 14, 2026

The HIPAA Security Rule Is Changing.

 

The HIPAA Security Rule Is Changing. Here Is Where Things Actually Stand.

The Garlick Group | July 2026

Healthcare compliance officers have spent eighteen months preparing for a rule that has not yet arrived. On December 27, 2024, the Department of Health and Human Services Office for Civil Rights released the first substantial overhaul of the HIPAA Security Rule since 2013, publishing it formally in the Federal Register on January 6, 2025.

The proposal is not modest. It would eliminate the long-standing distinction between “required” and “addressable” implementation specifications, converting nearly every safeguard on the list into a mandatory obligation. 1 Encryption of electronic protected health information, both in transit and at rest, would no longer be a matter of documented risk judgment. Multi-factor authentication would become standard. Organizations would need to maintain a current technology asset inventory and a network map showing how ePHI moves through their systems, updated annually. Vulnerability scans would run twice a year, penetration testing once. Security incidents would require containment and reporting within seventy-two hours. 2

Business associates absorb a disproportionate share of the new burden. The proposal introduces the term “HIPAA-regulated entity” to describe covered entities and business associates under a single standard, extends direct liability to subcontractors of business associates, and requires annual written verification that a business associate's safeguards remain in place. A covered entity that once relied on a signed agreement would need ongoing documentation instead.

None of this is law yet. That distinction matters more than the trade press coverage sometimes suggests. HHS's Spring 2025 regulatory agenda targeted a final rule for May 2026. That date has now passed without a final rule. 3 As of early July 2026, HHS has pushed final action to at least July 2027, treating the delay as a postponement rather than an abandonment. Separately, the department has signaled it will move ahead with changes to the HIPAA Privacy Rule as early as August 2026, on a track independent of the Security Rule proceeding. 4

The comment record explains some of the delay. OCR received roughly 4,745 public comments during the period that closed March 7, 2025, and officials have said at industry conferences that each one is being read. A coalition led by the College of Healthcare Information Management Executives, joined by more than one hundred hospital systems and provider organizations, sent HHS a letter in December 2025 urging withdrawal of the proposal outright. The coalition's argument centers on cost: HHS itself estimated first-year compliance at approximately nine billion dollars industry-wide, a figure the coalition considers unworkable for small and rural providers operating on thin margins.

The political backdrop adds its own uncertainty. The proposal was among the final regulatory acts of the prior administration, and the current administration's general posture toward deregulation leaves open the possibility that a final rule, if it comes at all, looks considerably lighter than what was proposed. 5 There is also a countervailing pressure: bipartisan concern about healthcare cybersecurity has not diminished. Large HIPAA breaches affected more than 286 million individuals in 2024, and hacking or IT incidents caused 76 percent of large breaches in 2025. Those numbers give OCR a continuing rationale for finalizing something, even if the something is narrower than the current draft. 6

What this means operationally is worth stating plainly. The current Security Rule remains fully in force and fully enforced. OCR has continued to cite deficient risk analysis as the most common finding in its investigations, and the agency's enforcement posture under existing law has not softened while the proposed rule sits in review. Waiting for finalization before improving a risk management program mistakes a drafting delay for a compliance holiday.

Organizations that began closing gaps against the proposed standard in 2025, rather than waiting for a published final rule, are better positioned regardless of how this resolves. A completed technology asset inventory, a documented network map, encryption at rest and in transit, and a current, evidence-backed risk analysis are defensible investments under the rule as it exists today. They also happen to be the exact controls most likely to survive into whatever version of the rule eventually gets published, whether that happens in 2027 or later still.

If the rule is finalized largely as proposed, the compliance runway will be short: OCR has floated a 240-day window from publication to compliance, with business associate agreements given a full year to update. 7 A 240-day sprint to build a risk analysis, asset inventory, and network map from a standing start is a difficult undertaking for a large health system and a punishing one for a small practice. The lesson from the 2013 Omnibus Rule, and from every major HIPAA update since, is that the organizations caught flat-footed are rarely the ones that lacked warning. 8

Endnotes

1. Bill Toulas [HIPAA Journal], “The Impact of Proposed Changes to the HIPAA Security Rule for Business Associates,” HIPAA Journal, May 19, 2026, https://www.hipaajournal.com/hipaa-security-rule-business-associates/.

2. RubinBrown, “HIPAA Security Rule Changes: 2025 & 2026 HIPAA Updates,” February 19, 2026, https://www.rubinbrown.com/insights-events/insight-articles/hipaa-security-rule-changes-2025-2026-hipaa-updates/.

3. Alston & Bird, “HIPAA Security Rule: Still on Track for Finalization,” November 4, 2025, https://www.alston.com/en/insights/publications/2025/11/hipaa-security-rule-overhaul.

4. Clearwater, “HIPAA Security Rule Enforcement: Where Things Stand in 2026,” July 2026, https://clearwatersecurity.com/blog/hipaa-security-rule-enforcement-2026/.

5. HIPAA Journal, “New HIPAA Regulations in 2026,” accessed July 12, 2026, https://www.hipaajournal.com/new-hipaa-regulations/.

6. Clearwater, “HIPAA Security Rule Enforcement: Where Things Stand in 2026,” July 2026, https://clearwatersecurity.com/blog/hipaa-security-rule-enforcement-2026/.

7. Medcurity, “HIPAA Security Rule Changes in 2026: What You Need to Know (and Do) Now,” updated June 6, 2026, https://medcurity.com/hipaa-security-rule-changes-2026/.

8. Compliancy Group, “The Proposed HIPAA Security Rule Update: What It Would Change and How to Prepare,” May 28, 2026, https://compliancy-group.com/proposed-hipaa-security-rule-update-2026/.

No comments:

Post a Comment