top of page

HIPAA Security Rule Update Status (August 2026): Still Proposed, Delayed to 2027

  • Writer: Author: Venus Caruso
    Author: Venus Caruso
  • Jan 13, 2025
  • 3 min read

Updated: 6 days ago

Last Updated: August 13, 2026


As of August 2026, the HIPAA Security Rule update status remains unchanged in one critical respect: the major cybersecurity overhaul first proposed in January 2025 has not been finalized and is now targeted for final action in July 2027. Covered entities and business associates continue to operate under the existing Security Rule, which remains fully enforceable.

Current Status (as of August 2026)

The proposal has generated nearly 5,000 public comments, many of them critical of the projected compliance costs and implementation timelines. In mid-2026, HHS moved the rulemaking to the long-term actions category of the Unified Agenda with a projected final action date of July 2027. Agency timetable dates are not binding. This means the OCR could still finalize earlier, revise the proposal, or withdraw it. Until a final rule is published and becomes effective, the existing HIPAA Security Rule continues to govern.

Key Proposed Changes (Still Under Consideration)

If finalized in substantially the same form, the rule would:

  • Eliminate the distinction between “required” and “addressable” implementation specifications, making nearly all specifications mandatory subject only to limited exceptions.

  • Require comprehensive written documentation of all Security Rule policies, procedures, plans, and analyses.

  • Mandate development and regular updating (at least annually or upon significant change) of technology asset inventories and network maps showing the movement of ePHI.

  • Require encryption of ePHI at rest and in transit (with limited exceptions).

  • Mandate multi-factor authentication (with limited exceptions).

  • Require vulnerability scanning at least every six months and penetration testing at least annually.

  • Require annual review and testing of the effectiveness of certain security measures.

  • Mandate anti-malware protection and removal of unnecessary software from relevant systems.

  • Strengthen backup, recovery, and contingency planning requirements.

  • Enhance incident response obligations, including written plans, regular testing, and tighter timelines for certain notifications and system restoration activities.

  • Impose new obligations on business associates and their subcontractors, including annual subject-matter-expert verification and written certification of technical safeguards, plus 24-hour notification requirements when contingency plans are activated.

These proposals remain subject to potential revision based on the comments received.

Recommendations for Covered Entities and Business Associates

The delay provides additional runway, but it is not a reason for inaction. OCR’s enforcement posture under the existing Security Rule already emphasizes risk analysis, risk management, encryption, access controls, and incident response. Many of the proposed requirements reflect cybersecurity practices that OCR and industry guidance (including NIST) have long encouraged.

HIPAA regulated entities should consider the following practical steps:

  1. Conduct or update a thorough Security Rule risk analysis and gap assessment that maps current controls against both the existing rule and the key proposed requirements.

  2. Maintain accurate, current technology asset inventories and data-flow/network maps for ePHI.

  3. Evaluate encryption (at rest and in transit), multi-factor authentication deployment, vulnerability management cadence, and backup/recovery capabilities.

  4. Review and test incident response and contingency plans.

  5. Strengthen business associate oversight and contractual provisions.

  6. Document decisions and risk-management rationales thoroughly.

These actions position organizations to comply with the current rule, reduce breach risk, and adapt more efficiently if and when a final rule is issued.

What’s Next

Covered entities and business associates should remain attentive to any developments. Until a final rule is published and becomes effective, the existing Security Rule governs. If a final rule is issued, it is expected to provide a compliance period (the NPRM contemplated an effective date 60 days after publication with most requirements due 180 days thereafter, subject to change in any final rule).


If you would like to explore how Venus Caruso can assist you, reach out to schedule a complimentary consultation using the contact form or by emailing venus@carusolawoffice.com.

This post is for informational purposes only and does not constitute legal advice. Laws and regulations can change, and specific situations may require different approaches. Covered entities and business associates should consult qualified counsel regarding their specific compliance obligations and risk posture.

Back to Top

BACK TO TOP

The information contained on this website is provided for informational purposes only. Nothing stated in or contained on this website should be taken as legal advice or a legal opinion for any individual matter. Your use of this website, review of information on this website, sending or receiving mail from carusolawoffice.com, or contacting the firm via the website's contact form or by email does not create an attorney-client relationship with Caruso Law PLLC or Venus Caruso. 

Hiring a lawyer is an important decision and should not be solely based on advertisements. 

CARUSO LAW PLLC

1645 Palm Beach Lakes Blvd.

West Palm Beach, FL 33401

Available by Appointment

E: contact@carusolawoffice.com
T: (561) 437-2972

Caruso Law Favicon White+Blue _edited.pn
Gold colored badge logo with black text saying "Florida Trend's Florida Legal Elite"
  • X
  • LinkedIn

© 2023-2026 Caruso Law PLLC

bottom of page