< BACK

The New HIPAA Rule Is Stuck. That Doesn’t Let You Off the Hook.

HIPAA Security Rule Emerge IT Solutions

The biggest proposed overhaul of the HIPAA Security Rule in two decades has stalled, and it may not arrive on schedule or intact. The controls it proposed are still worth adopting now.

Key Takeaways

  • The proposed HIPAA Security Rule overhaul, the first major update in more than 20 years, has not been finalized. A targeted May 2026 date passed with nothing published.
  • Its future is uncertain. Industry groups have asked HHS to withdraw or scale it back, and the timeline may slip into 2027 or change substantially.
  • The existing Security Rule is still in force, with incomplete risk analysis a recurring finding.
  • Most of the proposed controls, including MFA, encryption, network segmentation, asset inventory, and tested backups, are simply strong security worth adopting regardless of the outcome.
  • Waiting for certainty is the costliest option, since a rushed compliance scramble always costs more than a planned program.

Where Things Actually Stand

For most of the past year, healthcare IT teams braced for a hard deadline. In January 2025, the HHS Office for Civil Rights (OCR) proposed a sweeping overhaul of the HIPAA Security Rule, the first serious update since 2013, and its own regulatory agenda pointed to a final rule around May 2026. Then that date came and went. As the HIPAA Journal has reported, no final rule has been published, and the timeline has been pushed back, with some tracking suggesting final action could slip toward 2027.

Why it Stalled

The proposal drew thousands of comments and significant pushback. A coalition of more than a hundred hospital and provider groups formally asked HHS to withdraw or substantially scale back the rule, arguing that the compliance costs were underestimated, especially for smaller and under-resourced providers. Combine that with shifting federal priorities, and the honest answer about what happens next is that nobody knows. The rule could be finalized close to as proposed, trimmed down, or set aside. Betting your security program on any one of those outcomes is a gamble.

The Trap of Waiting

Here’s the mistake that tends to follow news like this: teams hear “no deadline” and quietly move HIPAA down the priority list. That’s a costly read. The current Security Rule is still fully in force, and OCR continues to enforce it. Incomplete or missing risk analysis remains one of the most common findings in its investigations, and the penalties are real today, with or without a new rule. The absence of a future deadline doesn’t create a present exemption.

The Proposed Controls are Just Good Security

Step back from the regulatory drama and look at what the proposal asked for: multi-factor authentication, encryption of electronic protected health information, network segmentation, a real asset inventory, regular vulnerability scanning, and tested backups. Strip the HIPAA label off that list, and you’re left with a description of basic modern security hygiene. As the law firm Alston & Bird put it, stakeholders should prepare for these changes regardless of the final rule’s exact shape. Every one of those controls maps directly to how breaches happen in healthcare: stolen credentials, unpatched systems, and flat networks that let an intruder roam. Adopting them now reduces real risk this year and positions you for whatever gets finalized later.

A Sensible Place to Start

The foundation is a current risk analysis, which is both the existing rule’s core requirement and the starting point for everything the proposal contemplates. HHS and OCR offer a free Security Risk Assessment Tool built specifically for small- and mid-sized practices, a practical first step for a lean team. From there, the priorities write themselves: turn on MFA everywhere, confirm ePHI is encrypted at rest and in transit, inventory what you actually run, and test that your backups restore.

Where a Partner Fits

Most mid-market healthcare organizations don’t have a dedicated security team to run risk analyses, implement segmentation and MFA, and keep evidence audit-ready. That’s ordinary, everyday work for a co-managed partner. The real value goes beyond deadline monitoring and, instead, building a steady program now, so that whenever the final rule arrives, in 2026, 2027, or in some altered form, you’re adjusting rather than scrambling. The organizations that treat this as a preview rather than a warning shot will be the ones that barely notice when the rule finally lands.

Scroll to Top