The HIPAA Security Rule update would be the first substantial rewrite of the rule
since 2013, and it is genuinely significant — it proposes to remove the flexibility the rule
has been built on since 2003. It is also not law, and is now not expected until 2027. This guide
separates what is proposed from what applies today.
Where the HIPAA Security Rule update actually stands
The Office for Civil Rights issued a Notice of Proposed Rulemaking on 27 December 2024, published
in the Federal Register on 6 January 2025. The comment period closed on 7 March
2025 and attracted more than 4,000 comments — a volume that reflects how
contested the proposals are, particularly on cost and feasibility for smaller and rural providers.
The final rule has slipped. OMB’s Unified Agenda now targets July
2027 for final action, moved back from an earlier spring 2026 target. A great deal of
commentary still describes these changes as imminent or as taking effect in 2026. They are not.
Until a final rule publishes, the Security Rule as it has stood since 2013 is the rule you
are audited against.
What the HIPAA Security Rule update proposes to change
The headline change in the HIPAA Security Rule update is structural. Today, implementation specifications are either
required or addressable — and “addressable” means you may
implement an equivalent alternative, or document why the specification is not reasonable and
appropriate for you. The proposal would remove the addressable category entirely,
making the specifications mandatory.
Alongside that, the NPRM proposes explicit technical requirements that the current rule leaves to
judgement:
- Encryption of ePHI at rest and in transit.
- Multi-factor authentication.
- Network segmentation.
- Anti-malware protection.
- Annual penetration testing.
- Vulnerability scanning every six months.
- An annual audit of Security Rule compliance.
- A written technology asset inventory and network map, maintained.
Read together, the HIPAA Security Rule update converts a risk-based framework into something much
closer to a prescriptive control baseline. That is the real substance of the debate in those 4,000
comments: whether flexibility was the rule’s strength or the reason healthcare breach numbers keep
climbing.
Documentation that already separates proposed from current.
The HIPAA Toolkit carries a regulatory currency statement in every document — NPRM-aligned content is labelled as proposed, and the vacated 2024 Reproductive Health Privacy Rule amendment is not relied upon. 160+ templates plus the security risk analysis workbook.
What the HIPAA Security Rule update makes worth doing now
- Do not rebuild your documentation against a proposal. The text can change, and
a two-year lead time makes early rework the most expensive option available. - Record your addressable decisions properly. Where you have chosen an alternative
to an addressable specification, the rule already requires you to document why. Most organisations
have not. That is a finding today and a migration headache later. - Get the asset inventory right. Proposed or not, you cannot do a defensible risk
analysis without it, and it is the foundation the proposed requirements assume. - Treat encryption and MFA as inevitable. Both are already what OCR expects to
see, and no realistic version of the final rule makes them less important.
The other change the HIPAA Security Rule update overshadows
Separately from this HIPAA Security Rule update, the 2024 Privacy Rule amendment on reproductive
health care was vacated nationwide by the US District Court for the Northern
District of Texas in June 2025, and the appeal was dismissed in September 2025. Its attestation
requirement no longer applies — but plenty of template packs and guidance still include it.
What survived that ruling is the change to the Notice of Privacy Practices concerning substance
use disorder records under 42 CFR Part 2, which took effect on 16 February 2026. If
your notice has not been reviewed since then, it is the more urgent of the two.
How to follow the HIPAA Security Rule update
Track the HIPAA Security Rule update through the Federal Register and OMB’s Unified Agenda rather than vendor blogs, and treat any
specific compliance date you see quoted today as an estimate — including July 2027. Once a
final rule publishes there will be a compliance period, and the organisations that struggle will be
the ones whose asset inventory and risk analysis were never solid to begin with. For the current
position, see our guides to the Security Rule versus the Privacy Rule,
the HIPAA risk assessment template and
HIPAA policies.
References
- HHS fact sheet on the Security Rule NPRM — the proposed rule explained by HHS.
- HHS: HIPAA Security Rule — the rule as it stands today.
More on HIPAA
- HIPAA risk assessment template
- HIPAA Security Rule update — you are here
- HIPAA risk assessment
- HIPAA compliance checklist
- HIPAA policies
- HIPAA business associate agreement
- Security Rule vs Privacy Rule
- HIPAA compliance explained
All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.