Proposed HIPAA Security Rule Update for 2026

Proposed HIPAA Security Rule Update for 2026

What Healthcare Organizations Need to Know Now

I.  Introduction

The healthcare sector is facing a cybersecurity crisis of historic proportions. In 2023 alone, more than 167 million individuals were affected by large breaches reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) — a figure that reflects just how dramatically the threat landscape has shifted since the HIPAA Security Rule was last meaningfully updated in 2013. Ransomware gangs have made hospitals a preferred target. Hacking incidents now account for the overwhelming majority of large breach reports. And yet the foundational federal standard governing the security of electronic protected health information (ePHI) has remained largely static for over a decade.

That is about to change. On January 6, 2025, HHS published in the Federal Register a Notice of Proposed Rulemaking (NPRM) proposing the most comprehensive overhaul of the HIPAA Security Rule since the rule was first issued in 2003. The proposed modifications would strengthen cybersecurity standards across the board — increasing specificity, mandating controls that are currently optional, imposing new obligations on business associates, and requiring annual compliance audits, among other significant changes.

A final rule is anticipated in summer 2026, though the path forward carries some regulatory uncertainty, as discussed below. What is not uncertain is the direction of travel: healthcare organizations that treat cybersecurity compliance as a checkbox exercise are on borrowed time. This post walks through what is proposed, what remains unclear, and what covered entities and business associates should be doing right now.

II.  Why Now? The Case for Updating the Security Rule

To understand why HHS is proposing these changes, it helps to appreciate the scale of the problem they are designed to address. The Security Rule was first published in 2003 and last revised in 2013, primarily through the HITECH Act Omnibus Rule. In the intervening years, the healthcare industry has been transformed by digital technology — and so has the threat environment.

Between 2018 and 2023, large breach reports to OCR more than doubled, and the number of individuals affected by such breaches increased more than tenfold in the same period, largely driven by hacking and ransomware attacks. Today, nearly every aspect of modern healthcare delivery — appointment scheduling, prescription management, telehealth visits, clinical decision support, medical device communication, and insurance claims processing — relies on networked digital systems. Each of those systems is a potential attack surface.

OCR has also observed through its enforcement investigations that regulated entities are inconsistently complying with existing Security Rule requirements. In particular, OCR is concerned that the rule’s current structure — which distinguishes between “required” and “addressable” implementation specifications — has been used by some organizations as a license to forgo important security controls on cost grounds, rather than as the genuine flexibility mechanism it was designed to be.

The NPRM also responds to a significantly changed federal policy environment. The President has designated healthcare as a critical infrastructure sector. States have been enacting their own cybersecurity regulations. The National Institute of Standards and Technology (NIST), the Federal Trade Commission (FTC), and the Cybersecurity and Infrastructure Security Agency (CISA) have all published frameworks reflecting current best practices. OCR’s view is that the Security Rule has fallen behind, and that a comprehensive update is both necessary and overdue.

III.  The Most Significant Proposed Change: Eliminating the Required/Addressable Distinction

Perhaps the single most consequential structural change proposed in the NPRM is the elimination of the distinction between “required” and “addressable” implementation specifications — a distinction that has defined the Security Rule’s compliance framework since its inception.

Under the current rule, certain implementation specifications are “required”, meaning a covered entity must implement them regardless of circumstances. Others are “addressable”, meaning a covered entity must assess whether the specification is a reasonable and appropriate safeguard in its particular environment. If the entity concludes it is not, it may either implement an equivalent alternative or document why no implementation is reasonable and appropriate. OCR is concerned that regulated entities have consistently treated “addressable” as synonymous with “optional”, prioritizing cost savings over security.

The proposed rule would eliminate the required/addressable distinction entirely, making all standards and implementation specifications mandatory — the most significant structural change to the Security Rule in over two decades.

The proposed change would eliminate this distinction entirely. All standards and implementation specifications would become mandatory. This does not mean every organization must implement security controls in precisely the same way — the proposal retains some flexibility for entities to tailor the method of implementation based on their size, complexity, and capabilities. But it removes the ability to decline implementing a specification altogether.

The practical implications are profound. Controls that many small and mid-sized organizations have lawfully treated as optional — including encryption of ePHI and multi-factor authentication (MFA) — would become non-negotiable. Organizations that have documented their addressable specification assessments and concluded that certain controls are not reasonable or appropriate for their environment will need to revisit those conclusions entirely, and will need to begin planning and budgeting for implementation well before the compliance deadline.

IV.  Proposed Administrative Safeguards

The NPRM proposes significant enhancements to the administrative safeguard requirements under Section 164.308 of Title 45 of the Code of Federal Regulations. These changes substantially increase the ongoing compliance burden for regulated entities, both in terms of documentation requirements and operational processes.

The proposal would require all covered entities and business associates to maintain a technology asset inventory and a network map showing the movement of ePHI within their electronic information systems. This inventory must be updated at least annually and whenever changes in the environment may affect ePHI. While the concept is sound and reflects industry best practice, the proposal does not clearly define which devices or systems must be included, leaving significant ambiguity for organizations operating in hybrid or cloud environments, or using emerging technologies such as AI-driven clinical tools, IoT-connected medical devices, or virtual reality platforms.

The risk analysis requirement — already mandatory under the existing rule, and already one of the most frequently cited areas of noncompliance in OCR enforcement actions — would be substantially strengthened. The proposed enhanced risk analysis must be conducted in writing, at least annually, and must include: a review of the technology asset inventory and network map; identification of all reasonably anticipated threats to the confidentiality, integrity, and availability of ePHI; identification of vulnerabilities; and a formal risk-level assessment for each identified threat and vulnerability based on the likelihood that it will be exploited.

Other new administrative safeguards include formal patch management and system update policies and procedures; a 24-hour notification requirement when workforce member access to ePHI or certain electronic information systems is changed or terminated; comprehensive contingency planning obligations (including written restoration procedures targeting a 72-hour recovery window, criticality analysis of systems and assets, written incident response plans, and regular testing of those plans); and an annual compliance audit to verify adherence to all Security Rule requirements. The annual audit requirement represents a particularly significant new burden. The NPRM provides limited guidance on what methodology or documentation will satisfy OCR — an area that will require clarification in the final rule or subsequent agency guidance.

V.  Proposed Technical Safeguards

The proposed changes to the technical safeguard requirements under Section 164.312 are equally significant, and in several respects more immediately consequential for IT operations and infrastructure planning.

On encryption, the proposal would require covered entities and business associates to encrypt ePHI both at rest and in transit, with only limited exceptions. This is a major departure from the current rule, under which encryption is an addressable specification. Many organizations have lawfully documented a decision not to implement full encryption, often on the grounds of cost or technical complexity. Under the proposed rule, that flexibility would disappear. The proposal does not, however, clearly define what circumstances would qualify as exceptions, which creates compliance uncertainty for organizations with complex legacy systems, vendor dependencies, or specialized clinical environments.

Network segmentation would be required to isolate systems containing ePHI from the broader network environment, reducing the potential blast radius of a breach. Like the encryption requirement, the proposal leaves implementation standards largely to the regulated entity, which creates the risk of inconsistent interpretation across the industry.

Multi-factor authentication would be required for access to all systems containing ePHI, with limited and as-yet undefined exceptions. This requirement aligns with universal cybersecurity best practice, but formalizing it as a mandatory HIPAA standard with potential civil money penalty exposure is a significant shift for organizations that have not yet completed MFA deployment. The criteria for exceptions are not specified in the NPRM — a gap that leaves meaningful uncertainty about when, if ever, it would be permissible to bypass MFA.

Additional proposed technical controls include vulnerability scanning at least every six months; penetration testing at least annually; consistent configuration management (including anti-malware protection, software minimization to reduce the attack surface, and disabling unused network ports); and separate technical controls for backup and recovery of ePHI and critical electronic information systems. Taken together, these requirements represent a substantial increase in both the technical sophistication and the ongoing resource commitment required for Security Rule compliance.

VI.  Proposed Changes to Business Associate Requirements

The NPRM also proposes meaningful changes to the requirements governing business associate agreements (BAAs), which have long been an area of compliance weakness across the healthcare industry. Under the current framework, established largely through the 2013 Omnibus Rule, covered entities are not required to verify that their business associates are actually implementing the Security Rule’s requirements. OCR has observed significant compliance gaps among business associates through its enforcement activities, and the proposed changes are designed to close them.

Most significantly, the proposal would require business associates to provide covered entities with written verification, at least once every 12 months, that they have implemented all required technical safeguards under the Security Rule. This verification must include a written analysis of the relevant electronic information systems conducted by a subject matter expert, along with a written certification that the analysis was performed and is accurate. The proposal does not specify what qualifications a “subject matter expert” must have, nor does it specify the level of responsibility covered entities bear for verifying the accuracy of those certifications — both of which are notable gaps that will need to be addressed in the final rule.

Business associates and their subcontractors would also be required to notify covered entities without unreasonable delay — and no later than 24 hours after activation — when they activate contingency plans. This requirement may prove particularly challenging for smaller business associates with limited IT resources, and it is currently unclear whether it applies to all contingency plan activations or only those involving significant data breaches.

On transition, the NPRM proposes that existing BAAs may continue to operate until the earlier of the next renewal date or one year after the final rule’s effective date. For covered entities managing large and complex BA ecosystems — including multiple subcontractor tiers — the operational work of identifying, reviewing, and updating BAAs to reflect new verification and notification requirements will be considerable.

VII.  The Regulatory Landscape: Uncertainty Ahead

Any analysis of the proposed HIPAA Security Rule changes must acknowledge a layer of regulatory uncertainty that has developed since the NPRM’s publication. The public comment period closed on March 7, 2025. Shortly after the NPRM was submitted to the Federal Register, an Executive Order imposed a regulatory freeze requiring additional review of pending proposed rules. The impact of this order on the final rule’s timeline and content is not yet clear.

OCR also sought comment on the application of the Security Rule to new and emerging technologies, including quantum computing, artificial intelligence, and virtual and augmented reality. How that feedback will shape the final rule is unknown. The current version of the proposed rule does not clearly address compliance requirements for organizations that rely on these technologies, creating significant uncertainty about future regulatory expectations for AI-enabled clinical systems and other cutting-edge applications.

There are also potential overlap and consistency issues with other federal cybersecurity frameworks. The FTC Safeguards Rule (16 CFR Part 314) imposes similar — but not identical — cybersecurity requirements on financial institutions, including many healthcare-adjacent businesses. NIST’s Cybersecurity Framework is widely adopted by healthcare organizations but does not carry the force of law. Organizations operating in multiple regulated spaces may face overlapping and potentially inconsistent requirements that will require careful legal navigation.

Regulatory uncertainty is not a legitimate reason to stand still. The direction of travel is unmistakable — and the underlying security risks that motivated this rulemaking are real and growing regardless of the final rule’s timeline.

VIII.  What Covered Entities and Business Associates Should Do Now

Given the scope of the proposed changes and the anticipated summer 2026 effective date, the time to begin preparing is now. Organizations that wait for publication of the final rule before taking action will face enormous pressure to comply within a compressed timeline. The following priorities should be at the top of every healthcare compliance agenda.

Conduct a gap assessment against the proposed requirements. This means identifying which currently addressable specifications your organization has chosen not to implement, and mapping your existing controls against the proposed mandatory requirements. Many organizations will find significant gaps in encryption coverage, MFA deployment, and the formality and frequency of their risk analysis process. Understanding where those gaps are — and what it will cost in time, technology, and personnel to close them — is the essential first step.

Update your risk analysis process to align with the enhanced requirements. This means ensuring that your risk analysis is conducted in writing at least annually, is supported by a current technology asset inventory and network map, and includes formal threat and vulnerability identification with documented risk-level ratings. Organizations that have relied on informal, infrequent, or narrowly scoped risk assessments will need to build a more rigorous and systematic process.

Review and strengthen your incident response program. The proposed 72-hour restoration requirement and the 24-hour access-change notification obligation will require most organizations to materially enhance their incident response capabilities. If you do not currently have a written, tested incident response plan, drafting and testing one should be an immediate priority. Organizations should also evaluate whether their current IT staffing and vendor relationships can support the proposed requirements.

Audit your business associate relationships. Identify all business associates and subcontractors, review existing BAAs, and begin planning for the annual verification process the proposed rule would impose. For covered entities with large BA ecosystems — particularly those relying on cloud service providers, IT vendors, or clinical technology companies — this is a significant operational undertaking that cannot be left until a final rule is published.

Plan your budget now. The proposed changes will require investment in technology upgrades (encryption infrastructure, MFA deployment, network segmentation tools), third-party security services (penetration testing, vulnerability scanning, compliance audits), and legal and compliance resources (BAA review and renegotiation, policy updates, workforce training). Budget cycles in large healthcare organizations are typically planned one to two years in advance, and the time to build these costs into 2026 and 2027 planning processes is now.

Finally, engage experienced legal and compliance counsel to interpret the proposed requirements in the context of your specific organization and operating environment, map HIPAA obligations against other applicable cybersecurity frameworks and state law requirements, and ensure that your compliance program is designed and documented to withstand OCR scrutiny. The increased specificity of the proposed rule will make it harder for organizations to demonstrate that their approach was reasonable in the absence of thorough, contemporaneous documentation — and building that documentation trail starts today.

IX.  Conclusion

The proposed HIPAA Security Rule overhaul is not a marginal adjustment to an existing framework. It represents a fundamental rethinking of the federal government’s approach to healthcare cybersecurity — one driven by a decade of escalating breach statistics, evolving technology, and a recognition that the current rule, drafted for a different era, is no longer adequate to protect the confidentiality, integrity, and availability of electronic protected health information.

The elimination of the required/addressable distinction, combined with new mandatory technical and administrative controls and materially strengthened business associate obligations, will demand significant investment and operational change from virtually every covered entity and business associate in the healthcare ecosystem. Smaller organizations and rural providers will face particular challenges in meeting requirements that were designed with large, sophisticated systems in mind, and OCR will need to provide additional guidance and flexibility for those entities as the rulemaking process progresses.

The final rule has not yet been published, and its ultimate form may differ from the NPRM in important respects. But the fundamental direction is clear: healthcare cybersecurity standards are getting stricter, more prescriptive, and more rigorously enforced. Organizations that wait for a final rule to begin preparing will find themselves under enormous pressure to comply within a compressed timeframe.

The organizations best positioned to navigate this transition successfully are those that begin their preparation today — with a clear-eyed assessment of where they stand, a realistic and well-resourced plan for closing compliance gaps, and experienced legal and compliance counsel to guide them through what promises to be one of the most consequential regulatory changes in the history of HIPAA. We are ready to help.