HIPAA Security Rule Modernisation (Proposed Rule)

HHS proposal to remove the addressable/required distinction, mandate MFA, encryption, asset inventories, network segmentation, annual audits and 72-hour restoration plans for ePHI. Final rule now projected for July 2027.

JurisdictionUnited States
CategoryHealthcare
StatusProposed
Latest development

Recent developments

  • — HHS moved the proposed HIPAA Security Rule amendments to the Long-Term Actions agenda, with July 2027 now listed as the anticipated timeframe for final action. This is the clearest recent signal that the rulemaking has been delayed rather than finalized. (source)
  • — A legal update reports that OCR pushed finalization of the HIPAA Security Rule amendments from May 2026 to July 2027. The article frames this as a significant regulatory delay for healthcare organizations waiting on cybersecurity compliance requirements. (source)
  • — This industry update says OCR had targeted May 2026 for final action, but that date passed without a final rule and no new timeline was confirmed at the time of publication. It reinforces that the proposed rule remained unresolved in early July 2026. (source)
  • — The HIPAA Journal reported that the final rule had been pushed back a year, with July 2027 shown as the new due date for final action. The piece also notes the original proposed rule was issued in late 2024 and published in January 2025. (source)
  • — Holland & Knight reported that the HIPAA Security Rule amendments were now projected for July 2027. The update indicates OCR had not released a final rule and that the regulatory timeline had shifted materially. (source)
  • — BankInfoSecurity reported that HHS received nearly 5,000 public comments, many of them negative, on the proposed rule. The article also said more than 100 hospital systems and provider organizations signed a letter urging HHS to withdraw the update, reflecting substantial industry resistance. (source)
  • — This industry commentary says OCR was still reviewing the 4,700-plus public comments from the proposed rule. It also argues the proposal would significantly raise the compliance floor by making many safeguards mandatory rather than addressable. (source)
  • — This compliance-focused update explains that the rule was still in proposed status as of late May 2026. It notes that if finalized as proposed, compliance would be required 180 days after publication in the Federal Register. (source)
  • — A healthcare association update said OCR was expected to announce significant changes in May 2026, including encryption and multi-factor authentication requirements. The article also described added operational requirements such as an inventory of systems handling patient data and procedures to restore critical systems within 72 hours. (source)
  • — This cybersecurity industry update described the proposal as requiring encryption of ePHI, multi-factor authentication, and written recovery procedures for critical systems within 72 hours. It also stated that, as of August 2026, the current HIPAA Security Rule remained in effect while the proposal awaited final action. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates