← Back to Compliance Insights

September 10, 2026  ·  Jonah Gobah

The Proposed HIPAA Security Rule Update: What It Would Change, and Why It's Delayed to 2027

Short answer: In December 2024, HHS proposed the most significant update to the HIPAA Security Rule since the 2013 Omnibus Rule — removing the "addressable" flexibility that lets practices tailor certain safeguards, and making most safeguards mandatory instead. As of mid-2026, it remains a proposed rule, not final law. HHS's own regulatory agenda has pushed the target for final action to July 2027, after a coalition of more than 100 hospital systems and provider associations formally asked the agency to withdraw or scale back the proposal. If a piece of content tells you what the Security Rule "now requires" based on this update, treat that claim with skepticism — nothing has changed yet.

The timeline so far

  • December 27, 2024: HHS's Office for Civil Rights announced the Notice of Proposed Rulemaking.
  • January 6, 2025: Published in the Federal Register, opening a 60-day public comment period.
  • March 7, 2025: Comment period closed, with more than 4,700 comments received.
  • December 8, 2025: A coalition of over 100 organizations, led by the College of Healthcare Information Management Executives, sent HHS a formal letter urging withdrawal, arguing the compliance costs are underestimated, particularly for smaller and under-resourced providers.
  • Mid-2026: The rule's original spring 2026 finalization target passed with no final rule issued.
  • As of this writing: HHS's Unified Agenda now targets July 2027 for final action — a full year later than originally planned, and federal regulatory timelines like this are not legally binding, so it could shift again in either direction.

What the proposal would actually change

Removing "addressable" safeguards. Under the current rule, many safeguards are labeled "addressable," giving practices flexibility to implement an alternative approach if a specific measure isn't reasonable for their size and situation. The proposal would eliminate that flexibility for most implementation specifications, making them mandatory regardless of practice size.

Mandatory encryption. Encryption of ePHI, both at rest and in transit, would become a required safeguard rather than an addressable one.

Mandatory multi-factor authentication. MFA would be required for any system accessing ePHI, without the case-by-case flexibility the current rule allows.

A 72-hour incident and data restoration requirement. The proposal includes shortened timelines for restoring systems and data following a security incident.

Annual penetration testing and network mapping. Practices would be required to maintain current network maps and asset inventories, and conduct penetration testing on a regular basis — a meaningfully more rigorous technical standard than many small practices currently maintain.

Enhanced business associate oversight. The proposal would tighten requirements around verifying and overseeing the security practices of business associates.

Why the pushback matters

The core dispute is specifically about removing the "addressable" flexibility. Critics argue that converting most safeguards to mandatory requirements, regardless of a practice's size or resources, creates a genuinely difficult compliance burden for small and rural providers in particular — which is directly relevant if you're a small practice trying to gauge how seriously to prepare right now.

What this means if you're a small practice today

Two things are true at once. First, nothing in this proposal is currently required — the existing Security Rule, with its current addressable/required distinction, is still what actually governs your compliance obligations. Second, OCR's enforcement of the existing rule hasn't slowed down at all during this delay, and many of the proposal's specific measures — encryption, MFA, current risk assessments — already reflect what reasonable security looks like today regardless of whether this rule is ever finalized.

The practical takeaway

Waiting for the rule to finalize before addressing these areas isn't a defensible strategy, given both the current rule's existing enforcement and the reasonable likelihood that most of these measures become mandatory eventually in some form. The safer approach is building toward encryption, MFA, and current documentation now, under the existing rule's requirements, rather than treating this as a future problem.

Run the free HIPAA risk assessment →

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles