HIPAA Security Rule Update Delayed: Why Organizations Should Prepare Now

Healthcare organizations have been given additional time to prepare for major proposed changes to the HIPAA Security Rule.

The U.S. Department of Health and Human Services originally anticipated releasing a final rule in 2026. The federal regulatory agenda now targets July 2027 for final action. This date is not legally binding and could change, but the delay gives covered entities and business associates more time to evaluate their security programs and begin addressing potential gaps.

The delay should not be treated as a reason to pause. Instead, it creates an opportunity to make steady, strategic improvements before new requirements take effect.

Why Is the HIPAA Security Rule Being Updated?

The HIPAA Security Rule was introduced in 2003 and last received a significant update through the HIPAA Omnibus Final Rule in 2013. Since then, healthcare technology and the cybersecurity threat landscape have changed dramatically.

Healthcare organizations now depend on interconnected systems, cloud platforms, remote access tools, third party vendors, and electronic health records. At the same time, ransomware attacks and breaches involving electronic protected health information, or ePHI, have continued to increase.

The proposed update is intended to strengthen the protection of ePHI by replacing broad or optional guidance with clearer, more specific cybersecurity requirements. HHS published the 125 page proposal in the Federal Register on January 6, 2025. The proposal has not been finalized, and organizations must continue complying with the current HIPAA Security Rule while the rulemaking process continues. Read the proposed rule in the Federal Register.

What Changes Are Being Proposed?

If finalized in its current form, the updated Security Rule would introduce several significant requirements for covered entities and business associates.

Key proposals include:

  • Eliminating the distinction between “required” and “addressable” implementation specifications
  • Requiring multifactor authentication, with limited exceptions
  • Requiring encryption of ePHI at rest and in transit, with limited exceptions
  • Conducting vulnerability scans at least every six months
  • Performing penetration testing at least once every 12 months
  • Reviewing and testing the effectiveness of security controls annually
  • Creating and maintaining a complete technology asset inventory and network map
  • Conducting more detailed risk analyses at least annually
  • Implementing network segmentation
  • Establishing separate technical controls for backing up and recovering ePHI
  • Strengthening incident response planning and testing
  • Requiring greater oversight and verification of business associate safeguards
  • Maintaining more extensive documentation to demonstrate compliance

These proposed changes would move HIPAA compliance toward a more measurable and evidence driven model. Organizations would need to do more than establish policies. They would also need to show that security controls have been implemented, tested, monitored, and maintained.

HHS provides a complete overview of the proposed requirements in its HIPAA Security Rule NPRM fact sheet.

Why Has the Proposal Received Pushback?

The proposed update received nearly 5,000 public comments. Many healthcare organizations and industry groups acknowledged the need for stronger cybersecurity protections but raised concerns about the proposal’s cost, complexity, and implementation timeline.

Smaller healthcare providers and rural organizations may face the greatest challenges. New technology, testing, documentation, and staffing requirements could create substantial financial and operational pressure for organizations already working with limited resources.

HHS estimated that implementing the proposed changes could cost the healthcare industry approximately $9 billion during the first year, followed by around $6 billion annually during years two through five.

The additional time before a final rule may allow HHS to review this feedback and give regulated organizations more time to plan. However, there is no guarantee that every proposed requirement will appear in the final rule exactly as written.

Why Waiting for the Final Rule Is Risky

The current delay does not eliminate the need for stronger healthcare cybersecurity. Many of the proposed requirements reflect practices organizations should already consider implementing to protect sensitive information and reduce operational risk.

Waiting until the final rule is published could leave organizations with a large number of controls, policies, assessments, and documentation requirements to implement within a limited compliance window.

Taking action now can help organizations:

  • Identify security and compliance gaps before they become urgent
  • Spread implementation costs across a longer period
  • Improve protection against ransomware and other cyber threats
  • Reduce the disruption caused by future regulatory changes
  • Build a more reliable record of compliance activities
  • Prepare evidence before an auditor, customer, insurer, or regulator requests it

Even if the final requirements change, foundational improvements such as multifactor authentication, asset inventories, risk assessments, network segmentation, vulnerability management, and documented recovery plans can still strengthen an organization’s overall security posture.

How Organizations Can Use the Extra Time

Healthcare organizations and their service providers should use this period to create a structured readiness plan.

1. Assess the Current Compliance Program

Review existing safeguards against both the current Security Rule and the proposed requirements. Document which controls are fully implemented, partially implemented, or missing.

2. Update the Asset Inventory and Network Map

Identify the systems, devices, applications, vendors, and data repositories that create, receive, maintain, or transmit ePHI. Document how ePHI moves throughout the environment.

3. Review High Priority Security Controls

Evaluate multifactor authentication, encryption, network segmentation, vulnerability scanning, penetration testing, backups, and recovery procedures.

4. Strengthen Risk Analysis Processes

Confirm that risk assessments are comprehensive, repeatable, and supported by current evidence. A once a year spreadsheet exercise may not be enough to demonstrate that risks are continuously identified and addressed.

5. Evaluate Business Associates

Review business associate agreements, vendor risk assessments, and the evidence used to verify third party safeguards. Organizations should be able to show how vendors with access to ePHI are evaluated and monitored.

6. Organize Compliance Evidence

Create a consistent process for collecting policies, assessment results, remediation records, testing reports, approvals, and other compliance documentation. Evidence should remain connected to the requirement or control it supports.

Turn the Delay Into a Readiness Advantage

The HIPAA Security Rule update may be delayed, but the cybersecurity risks facing healthcare organizations have not slowed down.

Organizations that use this additional time to assess their environments, strengthen controls, and organize their evidence will be better prepared when the final rule arrives. They will also be in a stronger position to respond to audits, customer requests, insurance reviews, and security incidents today.

Compliance Scorecard helps organizations and service providers manage assessments, document gaps, assign remediation work, organize evidence, and track compliance progress in one place.

Schedule a Compliance Scorecard demo to see how you can begin preparing for evolving HIPAA security requirements.

This article is for informational purposes only and does not constitute legal advice. The proposed HIPAA Security Rule has not been finalized, and its requirements and timing may change.


Tim Golden

Founder & CEO, Compliance Scorecard

Posted in

Related Posts

CS v10 banners (800 x 450 px)

PROVE IT: How Compliance Scorecard Verifies Every Framework Against the Official Source

CS v10 banners (800 x 450 px) (1)

97 C3PAOs. 80,000 Contractors. The CMMC Numbers Don’t Add Up and Your 2027 Contracts Could Be at Risk.

CS v10 banners (800 x 450 px) (1)

HIPAA Security Rule Updates Are Coming