Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA Security Rule Update — guide from Governance Docs

The HIPAA Security Rule Overhaul: What Is Proposed and When

The HIPAA Security Rule update would be the first substantial rewrite of the rule
since 2013, and it is genuinely significant — it proposes to remove the flexibility the rule
has been built on since 2003. It is also not law, and is now not expected until 2027. This guide
separates what is proposed from what applies today.

Where the HIPAA Security Rule update actually stands

The Office for Civil Rights issued a Notice of Proposed Rulemaking on 27 December 2024, published
in the Federal Register on 6 January 2025. The comment period closed on 7 March
2025 and attracted more than 4,000 comments — a volume that reflects how
contested the proposals are, particularly on cost and feasibility for smaller and rural providers.

The final rule has slipped. OMB’s Unified Agenda now targets July
2027
for final action, moved back from an earlier spring 2026 target. A great deal of
commentary still describes these changes as imminent or as taking effect in 2026. They are not.
Until a final rule publishes, the Security Rule as it has stood since 2013 is the rule you
are audited against
.

What the HIPAA Security Rule update proposes to change

The headline change in the HIPAA Security Rule update is structural. Today, implementation specifications are either
required or addressable — and “addressable” means you may
implement an equivalent alternative, or document why the specification is not reasonable and
appropriate for you. The proposal would remove the addressable category entirely,
making the specifications mandatory.

Alongside that, the NPRM proposes explicit technical requirements that the current rule leaves to
judgement:

  • Encryption of ePHI at rest and in transit.
  • Multi-factor authentication.
  • Network segmentation.
  • Anti-malware protection.
  • Annual penetration testing.
  • Vulnerability scanning every six months.
  • An annual audit of Security Rule compliance.
  • A written technology asset inventory and network map, maintained.

Read together, the HIPAA Security Rule update converts a risk-based framework into something much
closer to a prescriptive control baseline. That is the real substance of the debate in those 4,000
comments: whether flexibility was the rule’s strength or the reason healthcare breach numbers keep
climbing.

Documentation that already separates proposed from current.

The HIPAA Toolkit carries a regulatory currency statement in every document — NPRM-aligned content is labelled as proposed, and the vacated 2024 Reproductive Health Privacy Rule amendment is not relied upon. 160+ templates plus the security risk analysis workbook.

Explore the HIPAA Toolkit →

What the HIPAA Security Rule update makes worth doing now

  1. Do not rebuild your documentation against a proposal. The text can change, and
    a two-year lead time makes early rework the most expensive option available.
  2. Record your addressable decisions properly. Where you have chosen an alternative
    to an addressable specification, the rule already requires you to document why. Most organisations
    have not. That is a finding today and a migration headache later.
  3. Get the asset inventory right. Proposed or not, you cannot do a defensible risk
    analysis without it, and it is the foundation the proposed requirements assume.
  4. Treat encryption and MFA as inevitable. Both are already what OCR expects to
    see, and no realistic version of the final rule makes them less important.

The other change the HIPAA Security Rule update overshadows

Separately from this HIPAA Security Rule update, the 2024 Privacy Rule amendment on reproductive
health care was vacated nationwide by the US District Court for the Northern
District of Texas in June 2025, and the appeal was dismissed in September 2025. Its attestation
requirement no longer applies — but plenty of template packs and guidance still include it.

What survived that ruling is the change to the Notice of Privacy Practices concerning substance
use disorder records under 42 CFR Part 2, which took effect on 16 February 2026. If
your notice has not been reviewed since then, it is the more urgent of the two.

How to follow the HIPAA Security Rule update

Track the HIPAA Security Rule update through the Federal Register and OMB’s Unified Agenda rather than vendor blogs, and treat any
specific compliance date you see quoted today as an estimate — including July 2027. Once a
final rule publishes there will be a compliance period, and the organisations that struggle will be
the ones whose asset inventory and risk analysis were never solid to begin with. For the current
position, see our guides to the Security Rule versus the Privacy Rule,
the HIPAA risk assessment template and
HIPAA policies.

References

More on HIPAA

All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.