This article was originally published on LinkedIn, here.
The TL;DR: The proposed HIPAA Security Rule update is still not final, and HHS now targets July 2027 for final action. The current Security Rule remains fully enforceable today. Small and mid-sized organizations should use this window to complete an accurate risk analysis, close high-risk gaps like MFA and encryption, and document their work, because those steps satisfy today's rule and prepare you for the new one.
For more than a year, the healthcare leaders I work with have asked me some version of the same question: "Should we act now, or wait for the final rule?"
I understand the hesitation, budgets are tight, IT teams are stretched thin, and nobody wants to spend money on requirements that might change. So let me share where things stand and what I recommend for organizations that don't have a large security department behind them.
In this article:
On December 27, 2024, the HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking to strengthen cybersecurity protections for electronic protected health information (ePHI). You can read the full summary of the proposed Security Rule changes on HHS.gov. The proposal was published in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025.
The proposal would be the biggest change to HIPAA security requirements in two decades. Among its key provisions, it would:
The timeline has shifted more than once. In Spring 2025, OCR released a timetable pointing to a May 2026 release. That date came and went. The Office of Management and Budget has since updated its agenda to show the final rule pushed back a year, with final action now due in July 2027.
Cost concerns explain part of the delay. HHS itself estimated roughly $9.3 billion in combined costs during the first year of implementation, and the proposal drew sharp criticism and industry pushback. The final version could look different from the draft. OCR might also give organizations longer than the standard 180 days after publication to comply.
Some clients have asked me whether the rule might disappear altogether. I don't believe it will. HHS continues to list the Security Rule update on the federal regulatory agenda, and an agency that planned to abandon a rule would simply remove it from that list. The timing is uncertain, but the direction is clear.
I wish I could say yes. The honest answer is that the delay changes your deadline for the new rule and leaves your current obligations exactly where they were. HHS has stated clearly that the current Security Rule remains in effect while the rulemaking continues.
OCR has stayed busy enforcing it. In April 2026 alone, OCR announced settlements with four organizations following separate ransomware investigations, bringing its totals to 19 completed ransomware investigations and 13 completed Risk Analysis Initiative investigations. In March, OCR settled with a Maryland software vendor whose breach exposed data for roughly 15 million people. OCR has also expanded its enforcement focus beyond risk analysis to include risk management, meaning regulators want to see what you actually did about the risks you found.
Attackers also don't wait for rulemaking. When organizations delay security investments, they often pay more later in recovery costs, downtime, and penalties. I explored that pattern in more depth in this piece on why reactive cybersecurity is now the most expensive line item in healthcare.
My advice is to focus on "no-regret" moves. These steps help you meet today's requirements, reduce your real-world risk, and prepare you for whatever version of the new rule arrives.
Many compliance and IT leaders know what needs to happen but struggle to secure the budget. If that sounds familiar, our healthcare cyber risk advocacy kit gives you language and data to bring to your board or executive team.
Small teams often need outside help to close gaps quickly. Before you sign with anyone, review these questions to ask before you hire a HIPAA remediation partner. For a longer-term foundation, a framework like HITRUST already addresses many of the controls in the proposed rule. Our team can help you align with HIPAA and HITRUST at a pace that fits your organization.
The regulatory picture will keep shifting, and I know how hard it is to track all of it while running a practice or a business. My team reads the fine print so you don't have to. Subscribe to The Fine Print for quarterly compliance updates, and we'll let you know the moment this rule moves.