Why is HHS modifying the HIPAA Security Rule?
The HIPAA Security Rule NPRM (Notice of Proposed Rulemaking) is the most significant overhaul of the Security Rule since 2013. Specifically, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued it on December 27, 2024. Moreover, it targets the gap between 2013-era cybersecurity expectations and today’s threat landscape. The final rule is currently expected in May 2026, with a compliance window of 180 to 240 days after publication.
In practice, four forces drive the update:
- A healthcare environment that is now deeply interconnected, cloud-based, and API-driven
- A sharp rise in ransomware, hacking, and supply chain attacks targeting providers, payers, and their vendors
- Persistent compliance gaps OCR identified in enforcement investigations, particularly around risk analysis and access control
- Recent court decisions that clarified how OCR enforces the Security Rule
What are the new MFA and encryption requirements in the HIPAA Security Rule NPRM?
The HIPAA Security Rule NPRM moves multi-factor authentication (MFA) and encryption from flexible specifications to mandatory technical controls. Specifically, every regulated entity must encrypt all electronic protected health information (ePHI) at rest and in transit. Furthermore, every entity must deploy MFA to verify the identity of users and technology assets that access systems processing ePHI.
The NPRM carves out narrow exceptions:
- Emergencies where enforcing MFA or encryption would be infeasible
- Certain FDA-authorized legacy medical devices that cannot technically support modern controls
- Temporary operational situations that the entity must resolve as soon as practicable
What are the new asset inventory and risk analysis requirements?
The NPRM promotes risk analysis from an implementation specification to a standard in its own right. Specifically, two new foundational requirements support it. First, every regulated entity must maintain an accurate, written inventory of its technology assets and keep it current as systems change. Second, each entity must produce a network map showing how ePHI moves through its information systems, including connections to business associates and third-party platforms.
Moreover, the NPRM formalizes four recurring disciplines:
- Annual risk analyses
- Biannual vulnerability scans
- Annual penetration testing
- Network segmentation as a baseline architectural control
When will the HIPAA Security Rule update become final?
OCR placed the final rule on its regulatory agenda for May 2026. However, HHS has not guaranteed that date. The public comment period closed on March 7, 2025, with nearly 5,000 comments submitted. As a result, OCR continues to work through substantial industry feedback on cost and feasibility.
Once the final rule publishes, compliance will be required within 180 to 240 days. In practice, that places initial compliance deadlines in late 2026 or early 2027. Furthermore, the final text may differ from the proposed version due to industry pushback, but the direction is clear: stricter technical controls, more documentation, and less flexibility on core safeguards.
What should healthcare organizations do now to prepare?
Healthcare organizations should treat the NPRM as a near-certain future state and start closing the biggest gaps now. Specifically, waiting for the final rule before acting compresses the compliance window and drives up remediation costs. Moreover, many of the proposed requirements reflect controls that OCR already expects to see during enforcement investigations.
In practice, the highest-leverage preparations are:
- Build or refresh your technology asset inventory and ePHI data flow map
- Enforce MFA across electronic health records, patient portals, administrator accounts, and remote access paths
- Encrypt ePHI at rest and in transit wherever technically feasible, and document any residual gaps
- Run a gap assessment against the NPRM requirements, then tie each gap to an owner, a target date, and a compensating control
- Audit your Business Associate Agreement (BAA) portfolio and identify contracts that need amendment before enforcement begins
- Update the incident response plan to meet the proposed 72-hour response and restoration window