The HIPAA Security Rule hasn’t had a substantive update since 2013. In December 2024, HHS’s Office for Civil Rights proposed the first real overhaul since then — and it would have changed how healthcare organizations are expected to protect electronic PHI. That overhaul is now delayed to at least mid-2027. Here’s what actually happened, what didn’t change, and what to do about it while you wait.

What happened

On December 27, 2024, OCR published a Notice of Proposed Rulemaking to modernize the Security Rule, citing a 102% increase in large breach reports and a staggering rise in the number of people affected — over 167 million in 2023 alone, driven largely by ransomware and hacking. The proposed rule went out for public comment in 2025.

The response was significant: covered entities, business associates, and industry groups raised concerns that the proposed requirements were too costly and, for many organizations — particularly small practices and rural providers — not realistic on the proposed timeline. HHS’s own regulatory agenda now lists the rule’s timetable as a January 2025 proposal with final action not expected until around July 2027. Nothing is finalized, and that date could move again.

What hasn’t changed

The current Security Rule — the one from 2013 — remains fully in effect and fully enforced. OCR has been clear on this point: the rulemaking process doesn’t pause enforcement of existing obligations. If your risk analysis, safeguards, and documentation aren’t already solid against the 2013 rule, that’s the gap that matters today, not the one that might exist in 2027.

The change that matters most: “addressable” is going away

The single biggest shift in the proposed rule is structural, not technical: it would eliminate the distinction between “required” and “addressable” implementation specifications.

Under the current rule, a handful of safeguards — including encrypting ePHI — are labeled “addressable,” which does not mean optional. It means an organization has to assess whether the safeguard is reasonable and appropriate for its environment, implement it if so, or document a reasonable alternative if not. In practice, a lot of organizations have treated “addressable” as a synonym for “optional,” which is exactly the misreading OCR called out in the proposed rule’s preamble as weakening the sector’s cybersecurity posture.

The proposed rule would close that loophole by making nearly everything required, with only narrow, documented exceptions. Specifications that are addressable today — and new ones the proposal would add — would become baseline expectations, including:

  • Encryption of ePHI, at rest and in transit
  • Multi-factor authentication across systems that touch ePHI
  • Network segmentation
  • Vulnerability scanning and periodic penetration testing
  • A current technology asset inventory and network map
  • Written disaster recovery procedures, including restoring critical systems within 72 hours of a loss
  • Regular, documented risk analyses and annual compliance audits

Why the delay doesn’t mean you can wait

It’s tempting to read “final action pushed to 2027” as “nothing to do until 2027.” That’s the wrong takeaway, for a few reasons:

  1. OCR already treats these controls as effectively required. The preamble to the proposed rule states plainly that compliance with addressable specifications “is not — and should not be — optional.” Investigations and audits under the current rule increasingly reflect that view.
  2. Cyber insurance underwriters and business associate agreements are moving faster than the rule. Many carriers already require MFA, encryption, and tested backups as a condition of coverage, independent of what HIPAA mandates.
  3. A delayed implementation is exactly the time to close gaps without scrambling. Organizations that wait until a final rule is on the books tend to do so under a compliance deadline, at a rushed pace and a rushed budget.

Don’t forget the state law layer

HIPAA sets a floor, not a ceiling. Depending on where your patients and business associates are located, state law can layer additional obligations on top of HIPAA — stricter breach notification timelines, state health-data-specific statutes, or comprehensive privacy laws like California’s CCPA if you handle data tied to California residents. An organization operating in multiple states needs a security and compliance posture built around the strictest applicable requirement, not just HIPAA’s floor. That’s a legal question as much as a technical one, and worth involving counsel alongside your security program.

What we recommend now

Treat the proposed rule as a preview of where enforcement is headed, and use the delay as runway rather than a reprieve:

  • Get a real gap assessment against both the current 2013 rule and the proposed rule’s likely direction — not a checklist review, but one that covers your actual EHR configuration, medical devices, remote access, and business associate relationships.
  • Prioritize the controls named above (MFA, encryption, segmentation, tested backups, asset inventory) even though several are still technically “addressable” today.
  • Build an ongoing program, not a one-time project — the compliance bar for healthcare security is only going to get more explicit from here.

Our HIPAA & NIST assessment is built around exactly this: finding the gaps that matter before an auditor — or OCR — finds them for you. For organizations that want ongoing ownership of the program rather than a point-in-time review, our Virtual CISO service covers HIPAA program leadership on a predictable quarterly model. You can also read more about how we work with healthcare organizations generally.

If you want to talk through what the proposed rule means for your organization specifically, contact us or call (608) 448-6075 — no sales pitch, just an honest conversation about where you actually stand.