The HIPAA Security Rule update is still a proposal. Here’s why you should act on it anyway
The overhaul of the HIPAA Security Rule proposed in January 2025 still hasn’t been finalized, and the latest federal regulatory agenda points to 2027. This guide explains what the proposal would require and which parts healthcare organizations should implement now regardless of timing.
In January 2025, the HHS Office for Civil Rights (OCR) published a proposed rule that would make the most significant changes to the HIPAA Security Rule since 2013. Nearly two years later, it remains a proposal. OCR’s regulatory agenda had listed final action for May 2026, that date passed without publication, and the latest federal Unified Agenda now points to 2027. Once a final rule is published, the proposal allows for an effective date plus a 180-day compliance period, so mandatory compliance is likely a year or more away.
It’s tempting to wait. That would be a mistake, for reasons that have nothing to do with the rulemaking calendar.
What the proposed rule would change
No more “addressable” specifications. Today, many Security Rule safeguards are “addressable,” which in practice lets organizations document why they didn’t implement them. The proposal would make nearly all of them required.
Encryption and multi-factor authentication. Encryption of ePHI at rest and in transit, and MFA for access to systems containing ePHI, would become explicit requirements with limited exceptions.
Asset inventory and network map. Covered entities and business associates would need a written inventory of technology assets and a map of how ePHI moves through their environment, reviewed at least annually.
Faster recovery. Organizations would need procedures to restore relevant systems and data within 72 hours of a loss, along with documented, tested contingency plans.
Regular testing. Vulnerability scanning at least every six months, penetration testing at least annually, and a Security Rule compliance audit at least every 12 months.
Business associate verification. Covered entities would need written verification, at least annually, that business associates have the required technical safeguards in place, and business associates would need to notify covered entities promptly when they activate their contingency plans.
Why you shouldn’t wait for the final rule
The threat isn’t waiting. 2025 set another record for large healthcare data breaches reported to OCR. Ransomware groups continue to target hospitals, clinics, and the vendors that serve them because downtime puts direct pressure on patient care.
OCR already enforces risk analysis. The existing Security Rule requires an accurate and thorough risk analysis, and OCR’s ongoing audit program and enforcement actions focus heavily on it. Most of the proposal’s requirements are things a competent risk analysis would already flag.
Insurers and partners expect it now. Cyber insurance applications routinely ask about MFA, encryption, backups, and testing. Larger health systems increasingly push the same expectations onto their vendors through contracts.
The final rule may change, but the direction won’t. The proposal drew heavy industry criticism, and the final version may soften specific deadlines or frequencies. The core controls (MFA, encryption, inventory, tested recovery) reflect baseline practice and are unlikely to disappear.
A practical order of operations
1. MFA everywhere ePHI lives. Start with email, the EHR, remote access, and administrative accounts. This is the highest-impact, lowest-regret control.
2. Build the asset inventory and data-flow map. You can’t encrypt, monitor, or recover what you haven’t listed.
3. Test restores, not just backups. Time a real restore of a critical system. If it takes longer than 72 hours, you’ve found your next project.
4. Close encryption gaps. Laptops, removable media, and database backups are the usual misses.
5. Put testing on a calendar. Schedule the scans, the annual penetration test, and the compliance review so they happen whether or not the rule is final.
6. Review business associate agreements. Identify which vendors touch ePHI and what assurances you actually have from them.
How ThreatGrid helps
ThreatGrid’s healthcare security program combines HIPAA Security Rule gap analysis with ongoing monitoring tuned to clinical environments, and our compliance and risk advisory maps the proposed requirements against what you already have. If you want a clear picture of where you’d stand under the new rule, request a gap analysis.
This article is general information, not legal advice. Sources: HHS OCR Notice of Proposed Rulemaking, HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (Federal Register, January 6, 2025); federal Unified Agenda; HIPAA Journal reporting on rule status.