Proposed HIPAA Security Rule update: 7 major changes for small practices
The first major Security Rule update since 2013 has slipped to 2027. Here is what is actually proposed, what is law today, and what to do with the extra time.
By Kristen Sherrill, MCSP, SCA, PMP, CSPO — Stag Compliance
7-minute read
On January 6, 2025, the U.S. Department of Health and Human Services (HHS) published a Notice of Proposed Rulemaking (NPRM) in the Federal Register. It is titled HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, and you can find it at 90 Fed. Reg. 898.1 The public comment period closed on March 7, 2025, and the agency received 4,745 comments. As of today there is still no final rule.
This would be the first substantial update to the Security Rule since 2013, when the HIPAA Omnibus Final Rule last revised it. The original rule dates back to 2003. The proposal is a very big deal, but the most important thing to understand is that none of it is law yet, and the timeline just got much longer.
What this is, and what it is not
This is a proposal and it has not been finalized. In fact, in July 2026 the Office of Management and Budget (OMB) updated its regulatory tracking page and moved the projected final action date all the way out to July 2027. It also reclassified the rulemaking as a "long-term action," which is government shorthand meaning a final rule is well over a year away.2 The agency had originally floated May 2026, so this is roughly a 14-month slip, and observers who follow the process closely would not be surprised by further delay.
Here is why that matters for your planning. The existing 2013 Security Rule is still the law, and you have to comply with it right now. The proposal tells you where the Office for Civil Rights (OCR) wants to go, but it does not change your current obligations. And OCR has not slowed down enforcement while it works through the rulemaking. All through 2025 and into 2026 the agency has continued bringing settlements under its Risk Analysis Initiative, every one of them resting on the current rule, and it has signaled that its attention now extends past whether a risk analysis exists to whether the practice actually acted on what the analysis found. Missing or incomplete risk analysis remains the single most cited problem OCR finds when it investigates.
The one change that drives everything else
For more than two decades, the Security Rule has sorted its safeguards into required specifications and addressable specifications. Required specifications had to be implemented, while addressable specifications gave you a choice. You could implement the control, adopt an equivalent alternative, or document why the control was not reasonable or appropriate for your practice and then move on without it.
Over time, many practices treated addressable as optional. The proposal ends that. It would remove the split between required and addressable and make nearly every specification mandatory, with only a few narrow exceptions. In plain terms, the era of writing a paragraph explaining why you skipped a control would be over. What would ultimately matter is whether the control is actually in place.
What the proposal would require
The proposal is much larger than a short list. It contains dozens of new or strengthened controls.1 For small practices, here are the proposed updates that would be most impactful.
- You would need a documented risk analysis, reviewed at least once every 12 months and again whenever something meaningful changes in your environment. That analysis would have to be built from two new documents: a written inventory of every technology asset that touches electronic protected health information, and a network map showing how that information moves through your systems. Both would need review at least once every 12 months.
- You would need to encrypt electronic protected health information both while it is stored and while it is being sent. The proposal turns encryption into its own standalone requirement rather than an option you can document your way around.
- You would need multifactor authentication on systems that handle electronic protected health information. The proposal allows a small set of exceptions, mainly for legacy systems and for certain medical devices the U.S. Food and Drug Administration (FDA) authorized before March 2023, and even then only when you have a written plan to move that information onto supported technology.
- You would need network segmentation, which means separating the systems that handle patient information from general business or guest traffic so an intruder cannot move freely across your network. This is a firm requirement in the proposal, not a suggestion.
- You would need vulnerability scans at least every six months and a penetration test at least once every 12 months. You would need to apply patches for critical risks within 15 days and for high risks within 30 days, or document a compensating control when a patch is not available. You would need written procedures to restore your critical systems and data within 72 hours of a loss, along with a separate written incident response plan that you test at least once a year.
- You would need to run a compliance audit at least once every 12 months. And you would need written verification, at least once every 12 months, that each of your business associates has actually deployed the technical safeguards the rule requires, backed by an analysis from someone qualified and a signed certification. A signed agreement on file would no longer be enough by itself.
There is no small practice carve-out
The proposal would apply to a solo dentist or a two-person clinic exactly as it applies to a large hospital system. There is no exemption based on head count, no lighter tier for small offices, and no extra time for smaller entities. HHS actually declined to give smaller organizations a longer runway. The difference is simply that a hospital has a security team and a large budget, while most independent practices have neither, which is why groups representing providers have pushed back hard. HHS itself estimates the proposal would cost the industry roughly $9 billion in the first year and about $6 billion a year after that, close to $34 billion over five years.3
What is not changing
The overall shape of the Security Rule stays the same. It still rests on administrative, physical, and technical safeguards, and it still requires a risk analysis, a risk management plan, and business associate agreements. The proposal builds on that framework rather than replacing it.
The Privacy Rule, which governs who may see and use patient information, is not touched by this proposal. A separate update to the Privacy Rule, proposed back in 2021, is moving on its own track and is currently expected to be finalized much sooner. That is a different rulemaking with different implications, and we will cover it when there is final text.
What to do before any final rule arrives
You do not need to wait for a final rule to benefit from this work, because most of it protects you under the rule that already exists. Start here.
- Finish your current-year risk analysis under today's rule. This is your biggest real risk right now, since OCR is still enforcing and still citing weak risk analysis more than anything else.
- Audit your multifactor authentication across every system that touches patient information. This tends to be the hardest change to make quickly. Many electronic health record systems already offer it, and the gaps often sit in email, remote access, billing software, and cloud backup. Getting a vendor to turn it on or moving email to a compliant platform takes time, so start early.
- Build your technology asset inventory as part of that risk analysis. The same document serves your current obligation and the proposed future one.
- Review your business associate agreements with your main vendors. Confirm they are current and that they include real security commitments, not just boilerplate.
- Watch the Federal Register for a final rule. Remember that the compliance window would start from the date a final rule publishes, not from today, and right now that date is projected for 2027 at the earliest.
Sources
Footnotes
-
U.S. Department of Health and Human Services, Office for Civil Rights, "HIPAA Security Rule NPRM" (proposed rule issued December 27, 2024; published in the Federal Register January 6, 2025, at 90 Fed. Reg. 898). https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html ↩ ↩2
-
Office of Management and Budget, Office of Information and Regulatory Affairs, Unified Agenda entry for RIN 0945-AA22 (HIPAA Security Rule modifications), listing a projected final action of July 2027 and classifying the rulemaking as a long-term action. https://www.reginfo.gov/public/do/eAgendaViewRule?RIN=0945-AA22 ↩
-
Regulatory impact analysis in the proposed rule, 90 Fed. Reg. 898 (estimated first-year compliance cost of approximately $9 billion, with approximately $6 billion in each of years two through five). https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information ↩