Technology Resources for Cybersecurity, IT, + Cloud | CompassMSP

The HIPAA Security Rule Delay Gives Small Healthcare Teams More Time. Here Is How to Use It.

Written by Emily Zaczynski | Oct 1, 2026, 11:03:33 PM

This article was originally published on LinkedIn, here.

The TL;DR: The proposed HIPAA Security Rule update is still not final, and HHS now targets July 2027 for final action. The current Security Rule remains fully enforceable today. Small and mid-sized organizations should use this window to complete an accurate risk analysis, close high-risk gaps like MFA and encryption, and document their work, because those steps satisfy today's rule and prepare you for the new one. 

For more than a year, the healthcare leaders I work with have asked me some version of the same question: "Should we act now, or wait for the final rule?" 

I understand the hesitation, budgets are tight, IT teams are stretched thin, and nobody wants to spend money on requirements that might change. So let me share where things stand and what I recommend for organizations that don't have a large security department behind them. 

In this article: 

What is the proposed HIPAA Security Rule update?

On December 27, 2024, the HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking to strengthen cybersecurity protections for electronic protected health information (ePHI). You can read the full summary of the proposed Security Rule changes on HHS.gov. The proposal was published in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025.

The proposal would be the biggest change to HIPAA security requirements in two decades. Among its key provisions, it would:

  • Eliminate the difference between "required" and "addressable" specifications, so nearly every specification becomes mandatory. Many small practices have relied on that flexibility for years.
  • Require a technology asset inventory and a network map showing how ePHI moves through your systems, updated at least every 12 months.
  • Require encryption of ePHI at rest and in transit, plus multi-factor authentication, each with limited exceptions.
  • Require vulnerability scans at least every six months and a penetration test at least once a year.
  • Require written procedures to restore certain systems and data within 72 hours.
  • Require an annual compliance audit, along with a yearly written verification from business associates that their technical safeguards are in place.

Why is there still no final rule?

The timeline has shifted more than once. In Spring 2025, OCR released a timetable pointing to a May 2026 release. That date came and went. The Office of Management and Budget has since updated its agenda to show the final rule pushed back a year, with final action now due in July 2027.

Cost concerns explain part of the delay. HHS itself estimated roughly $9.3 billion in combined costs during the first year of implementation, and the proposal drew sharp criticism and industry pushback. The final version could look different from the draft. OCR might also give organizations longer than the standard 180 days after publication to comply.

Some clients have asked me whether the rule might disappear altogether. I don't believe it will. HHS continues to list the Security Rule update on the federal regulatory agenda, and an agency that planned to abandon a rule would simply remove it from that list. The timing is uncertain, but the direction is clear.

Does the delay reduce your risk?

I wish I could say yes. The honest answer is that the delay changes your deadline for the new rule and leaves your current obligations exactly where they were. HHS has stated clearly that the current Security Rule remains in effect while the rulemaking continues.

OCR has stayed busy enforcing it. In April 2026 alone, OCR announced settlements with four organizations following separate ransomware investigations, bringing its totals to 19 completed ransomware investigations and 13 completed Risk Analysis Initiative investigations. In March, OCR settled with a Maryland software vendor whose breach exposed data for roughly 15 million people. OCR has also expanded its enforcement focus beyond risk analysis to include risk management, meaning regulators want to see what you actually did about the risks you found.

Attackers also don't wait for rulemaking. When organizations delay security investments, they often pay more later in recovery costs, downtime, and penalties. I explored that pattern in more depth in this piece on why reactive cybersecurity is now the most expensive line item in healthcare.

What should small and mid-sized organizations do now?

My advice is to focus on "no-regret" moves. These steps help you meet today's requirements, reduce your real-world risk, and prepare you for whatever version of the new rule arrives.

  1. Complete an accurate, enterprise-wide risk analysis. Risk analysis remains the requirement OCR cites most often. Make sure yours covers every system that touches ePHI, including cloud apps, medical devices, and vendor connections, and then document how you are addressing each finding. 

  2. Build an asset inventory and map your ePHI. You can't protect what you can't see. This work is foundational for your risk analysis today and would become an explicit requirement under the proposed rule. 

  3. Turn on MFA and encrypt ePHI. These controls deliver some of the highest security value for the cost, and cyber insurers increasingly expect them already.
     
  4. Set up data loss prevention (DLP) now. DLP tools help stop ePHI from leaving your organization through email, cloud file sharing, or removable drives. I expect DLP to become a required safeguard, so I encourage every client to deploy it while it remains optional. Your employees get time to adjust to new prompts and blocked actions before an auditor is looking, and your team gets time to tune the policies so they catch real risks without slowing down patient care. 

  5. Test your backups and plan your recovery. Ask your team how long it would take to restore critical systems after a ransomware attack. If the answer is "we're not sure," start there and work toward the proposed 72-hour target. 

  6. Review your business associates. Confirm that your vendors are protecting your data and that your agreements reflect current expectations. Business associates should prepare to show their safeguards in writing. 

  7. Put your policies in writing and review them yearly. Documentation is often the difference between a manageable OCR inquiry and a costly one.

How do you make the case to leadership?

Many compliance and IT leaders know what needs to happen but struggle to secure the budget. If that sounds familiar, our healthcare cyber risk advocacy kit gives you language and data to bring to your board or executive team.

How do you choose the right remediation partner?

Small teams often need outside help to close gaps quickly. Before you sign with anyone, review these questions to ask before you hire a HIPAA remediation partner. For a longer-term foundation, a framework like HITRUST already addresses many of the controls in the proposed rule. Our team can help you align with HIPAA and HITRUST at a pace that fits your organization.

Stay ahead of the next update

The regulatory picture will keep shifting, and I know how hard it is to track all of it while running a practice or a business. My team reads the fine print so you don't have to. Subscribe to The Fine Print for quarterly compliance updates, and we'll let you know the moment this rule moves.