top of page

HHS Just Gave You An Extra Year On The HIPAA Security Rule. Here's What To Do With It.

  • Jul 27
  • 4 min read



The HIPAA Security Rule Delay Isn’t a Pause. It’s a Head Start.

The Department of Health and Human Services (HHS) just handed the healthcare industry something it rarely gets: more time. The Office of Management and Budget’s regulatory agenda now shows a final action date of July 2027 for the updated HIPAA Security Rule, a full year later than the May 2026 target HHS had originally set. For compliance teams staring down a 125-page proposed rule with mandatory encryption, multi-factor authentication, network segmentation, and annual audits, that news probably landed as a relief.


It should not land as permission to slow down.


What Changed (and What Didn’t)

The delay affects the calendar, not the substance. The Office for Civil Rights’ (OCR’s) December 2024 Notice of Proposed Rulemaking, published in the Federal Register in January 2025, is still the baseline HHS is working from. That proposal would eliminate the “addressable” classification that has let organizations treat some safeguards as that it has allowed organizations to defer implementation of some safeguards, and replace it with a set of hard requirements, including encryption, multi-factor authentication, network segmentation, malware protection, annual penetration testing, vulnerability scans every six months, and annual audits of Security Rule compliance. It would also require risk analyses at least annually, grounded in a detailed, up-to-date technology asset inventory and a network map showing how ePHI moves through your environment, along with dedicated backup and recovery controls and shorter verification timelines for business associates.


None of that has been withdrawn. HHS moved the release date because nearly 5,000 public comments, many from hospitals, health systems, and provider associations, argued the original timeline was unworkable and the compliance cost, compliance cost for the industry, estimated at $9 billion in year one and $6 billion in years 2-5 after that, would strain organizations already operating on thin margins. HHS listened to the timing complaint. It has not signaled it is backing off the substance.


Why the Rule Exists in the First Place

It is worth remembering why OCR proposed these changes at all. The current Security Rule was written in 2003 and last meaningfully updated in 2013. In the years since, healthcare has become one of the most targeted sectors for ransomware and data theft, and the consequences have gotten bigger, not smaller.


The Change Healthcare attack in February 2024 is the clearest example. Attackers got in through a Citrix remote access portal, using stolen credentials, on a system with no multi-factor authentication enabled. The fallout touched roughly one in three patient records in the country, disrupted billing and care delivery for weeks, and ultimately exposed the ePHI of an estimated 192.7 million Americans. Multi-factor authentication and network segmentation, two of the proposed rule’s core requirements, are the kinds of controls that make attacks like this harder to pull off and less catastrophic when they succeed.


What We’re Telling Clients

Regulatory timelines like this one are not legally binding, and HHS has said as much itself. OCR could finalize the rule before July 2027 if it chooses to. Waiting for the ink to dry on a final rule before doing anything is a bet that the requirements will soften between now and then. Given the direction of every recent healthcare breach headline, that is not a bet we would recommend making.


Our position is straightforward: treat this extra year as implementation time, not a grace period. Organizations that start now, working through a comprehensive risk analysis, building an accurate asset inventory and network map, rolling out multi-factor authentication and segmentation, and testing backup and recovery plans, will not be scrambling when the final rule lands. They will also be measurably harder to breach in the meantime, which is the point of the rule to begin with.


Two other things worth knowing. First, OCR has not slowed down across the board. It is pressing ahead with a separate update to the HIPAA Privacy Rule, with a final rule targeted for August 2026, so compliance teams shouldn’t assume a quiet year ahead. Second, the requirements getting the most pushback, like eliminating “addressable” safeguards and mandating specific technical controls, are also the ones most closely tied to how recent breaches actually happened. That is not a coincidence, and it is a strong signal about where OCR’s priorities will lie in the final rule.


Where to Start

If your organization has been waiting for a final rule to justify the budget and effort, this is the moment to make the case internally instead. A gap assessment against the proposed requirements, an updated risk analysis, and a network map of where ePHI lives and moves are useful regardless of what the final rule ultimately says word for word. They are also the three things most healthcare organizations we work with are missing today.


The deadline moved. The risk didn’t. Use the year.

 

Ready to see where your organization stands against the proposed HIPAA Security Rule requirements? Securance’s HIPAA risk assessments and technical compliance audits identify the gaps that matter most before a regulator, or an attacker, finds them for you.


Contact Securance to schedule an assessment at: www.securanceconsulting.com/contact-us.


 
 
 

Comments


bottom of page