7 Key Changes Coming to the HIPAA Security Rule

Practical guidance for healthcare teams and business associates

Important Disclaimer

These changes are based on the Notice of Proposed Rulemaking (NPRM) published in the Federal Register on January 6, 2025. As of July 2026, the final rule has not been published. Requirements may change in the final version. Nothing in this article should be construed as legal advice.

Key Definitions

  • NPRM (Notice of Proposed Rulemaking) - A formal proposal published in the Federal Register that describes a rule the agency intends to adopt. It invites public comment before finalization.
  • ePHI (Electronic Protected Health Information) - Any protected health information that is created, stored, transmitted, or received in electronic form. Defined in 45 CFR 160.103.
  • MFA (Multi-Factor Authentication) - An access control method requiring two or more verification factors: something you know (password), something you have (authenticator app or hardware key), or something you are (biometric).
  • Encryption at Rest - Protecting stored data by converting it into unreadable code. Applies to servers, laptops, backup drives, USB devices, and cloud storage containing ePHI.
  • Encryption in Transit - Protecting data as it moves across networks using protocols such as TLS. Applies to email, EHR data transfers, and any network communication containing ePHI.
  • Network Segmentation - Dividing a computer network into separate zones so that a breach in one segment does not automatically expose systems in another.
  • Patch Management - The process of regularly updating software and systems to fix known security vulnerabilities. The NPRM would require documented patch management procedures.

The HIPAA Security Rule last saw a major update in 2013. In cybersecurity terms, that feels like a geological era. At that time, iPhones did not have fingerprint readers. Ransomware was still a curiosity, not the major threat it poses to healthcare today. Most healthcare groups were still learning how to go paperless.

NPRM Timeline

December 27, 2024HHS announces proposed Security Rule overhaul
January 6, 2025NPRM published in the Federal Register
March 7, 202560-day comment period closed
~5,000 commentsSubmitted by industry groups, providers, and associations
Mid-2026 (expected)Final rule publication (not yet confirmed)
240 days after final ruleCompliance deadline for all covered entities and business associates

On December 27, 2024, HHS announced the largest proposed overhaul of the Security Rule to date. The Notice of Proposed Rulemaking (NPRM) appeared in the Federal Register on January 6, 2025. The 60-day comment period closed March 7, 2025, with nearly 5,000 comments submitted. OCR has kept finalization on its rule-based agenda for May 2026.

Once the final rule publishes, you get 240 days to comply. If it lands in mid-2027 as the Unified Agenda projects, your deadline falls around early 2028.

That is not a lot of time for what they are asking.

The Headline Change: Addressable Is Dead

If you have spent time with HIPAA compliance, you know the difference between required and addressable implementation specifications. Required means you do it. Addressable means you assess whether it is reasonable and appropriate for your group.

In theory, addressable meant flexibility. In practice, it became a loophole. Many groups wrote that encryption or automatic logoff was not reasonable for their situation and moved on. OCR saw this pattern across years of enforcement actions and breach reviews. We explain why this matters in our deep dive on why addressable does not mean optional.

The proposed rule eliminates the required/addressable distinction entirely. Every specification becomes required, with only narrow, clearly defined exceptions. If you see a safeguard in the rule, you must implement it.

This single change cascades through everything else in the rule.

The 7 Major HIPAA Security Rule Changes You Need to Know

1. MFA Required for All ePHI Access - No Exceptions

Current Requirement: MFA is an addressable specification. Organizations can document why it is not reasonable and implement an alternative measure.

Proposed Change: MFA would become required for all ePHI access - no exceptions, no alternative measures, no small-practice carve-out.

Compliance Action Required (if finalized): Deploy MFA on every system containing ePHI - EHR, email, billing software, cloud storage. App-based authenticators (Microsoft Authenticator, Google Authenticator, Duo) are recommended over SMS.

Multi-factor login checks would change from a recommended practice to a legal requirement. Under the proposed rule, every system containing digital health data would require MFA for access. This includes remote and on-site access, clinical users, and admin users. The proposal does not create a small-group exception.

MFA means at least two of: something you know (password), something you have (authenticator app, hardware key), or something you are (fingerprint, face scan). SMS-based codes technically qualify but are the weakest option - SIM-swapping attacks have made them unreliable. Both OCR and NIST recommend app-based authenticators like Microsoft Authenticator, Google Authenticator, or Duo.

Here is the number that should convince anyone still on the fence: MFA blocks 99.9% of automated account compromise attacks, according to Microsoft's security research.

The practical impact: if anyone in your group accesses ePHI with just a username and password today, that is a gap once this rule takes effect. We wrote a full setup walkthrough in our plain-English MFA guide.

2. Encryption Required: At Rest and In Transit

Current Requirement: Encryption is addressable. Organizations can document compensating controls if they determine encryption is not reasonable.

Proposed Change: Encryption would be required for all ePHI at rest and in transit. Narrow exceptions exist only where encryption is technically impossible, with documented compensating controls.

Compliance Action Required (if finalized): Encrypt all servers, workstations, laptops, backup drives, USB drives, and cloud storage. Ensure all network transmissions of ePHI use TLS or equivalent encryption.

Encryption of ePHI is no longer addressable (see our detailed guide on mandatory encryption standards under the updated Security Rule). It is required for data at rest and data in transit. Data at rest includes servers, workstations, laptops, backup drives, USB drives, and cloud storage. Data in transit means data moving across any network.

The in transit piece is where many groups have gaps. If your practice emails patient records without encryption, that is noncompliant. If your EHR sends data to a clearinghouse over an unencrypted connection, that is noncompliant. If a staff member texts patient information, that is noncompliant.

Some exceptions may apply when encryption is not possible. The group must document compensating controls. Meeting that exception will be difficult.

3. Risk Analysis Every 12 Months - With Teeth

Current Requirement: Risk analysis is required (45 CFR 164.308(a)(1)(ii)(A)) but no specific frequency is mandated.

Proposed Change: The NPRM would require a complete risk analysis every 12 months, with specific documentation requirements for the technology asset inventory, network map, and threat assessment.

Compliance Action Required (if finalized): Establish a 12-month risk analysis cycle with written records of all identified threats, vulnerability levels, and existing controls for each risk.

The current rule requires a risk analysis but does not specify frequency. Most groups do one at onboarding and update it sporadically. The proposed rule changes that - and incomplete risk reviews are already the number-one reason practices get fined.

Every 12 months, you would need to complete:

  • A complete risk analysis identifying all reasonably anticipated threats
  • A review and update of your technology asset list
  • A review and update of your network map
  • written records of every identified threat and weak spot with an assessed risk level
  • An check of existing controls against each identified risk

This is not checking boxes on a template. The NPRM would require the risk analysis to reflect your actual setting - your specific systems, your specific vendors, your specific threat space. Cookie-cutter reviews that do not reference your group's real systems would not pass muster.

4. Technology Asset Inventory and Network Mapping

Current Requirement: No specific asset inventory or network mapping requirement exists in the current Security Rule.

Proposed Change: The NPRM would require a written technology asset inventory and a network map showing how ePHI moves through systems. Both would need to be reviewed and updated every 12 months.

Compliance Action Required (if finalized): Document every device, system, and application that touches ePHI. Create a diagram showing ePHI data flows including business associate connections.

Two new written records rules that would support the risk analysis:

Technology asset list: Written records identifying every technology asset that creates, receives, maintains, or transmits ePHI. Each entry must include the asset's location, the person accountable for it, and its current version. Reviewed and updated at least every 12 months.

Network map: A diagram showing how ePHI moves through your digital systems - how it enters, exits, and is accessed from outside. This must include technology assets used by your business associates. Also reviewed annually.

A five-physician medical practice might find this manageable. A hospital system with thousands of endpoints faces a much larger records challenge. Either way, you cannot do it in a weekend.

5. 72-Hour System Restoration After a Cyberattack

Current Requirement: The current rule requires a contingency plan (45 CFR 164.308(a)(7)) but does not specify a restoration timeframe.

Proposed Change: The NPRM would require documented procedures to restore critical systems within 72 hours of a disruption, plus an analysis of system criticality to determine restoration priority.

Compliance Action Required (if finalized): Develop and test a recovery plan with a 72-hour restoration target. Conduct recovery drills and document results.

The proposed rule would require written steps to restore key digital information systems and data within 72 hours of a disruption. You would also need to perform an analysis of which systems are most key to determine restoration priority.

This is a direct response to the ransomware epidemic. When Change Healthcare went down in February 2024, claims processing across the country ground to a halt for weeks - ultimately affecting 190 million patients and costing UnitedHealth Group over $2.9 billion. When hospitals get hit with ransomware, patient care suffers. HHS wants proof that you can get back on your feet in three days.

Meeting this proposed rule means tested backups, documented recovery steps, and - in key ways - actually running recovery drills. A backup you have never tested is not a backup. If you want to know what the first three days after an attack actually look like, read our ransomware response guide.

6. Annual Compliance Audits

Current Requirement: The current rule requires evaluation (45 CFR 164.308(a)(8)) but does not mandate annual audits or specify audit scope.

Proposed Change: The NPRM would require a formal annual compliance audit assessing conformity with the Security Rule, separate from the risk analysis.

Compliance Action Required (if finalized): Conduct an annual audit that checks whether your organization is actually following its own policies and meeting Security Rule requirements. Document findings.

The proposed rule would require an annual compliance audit assessing conformity with the Security Rule. This is separate from the risk analysis. The risk analysis asks what threats exist? The compliance audit asks are we actually doing what we are supposed to?

For groups that have been running informal self-reviews, this formalizes the process and creates written records that OCR can request during a review.

7. Business Associates Must Verify Compliance Annually

Current Requirement: Business associates must comply with the Security Rule and maintain BAAs (45 CFR 164.308(b)), but there is no annual verification mandate.

Proposed Change: The NPRM would require BAs to provide annual written verification that required safeguards are in place, certified by a subject matter expert. A 24-hour notification requirement would apply when a BA activates disaster recovery.

Compliance Action Required (if finalized): Build an annual BA verification process into your vendor management program. Update BAAs to include the 24-hour disaster recovery notification clause.

Business associates would get significantly clearer ownership under the proposed rule:

  • Annual written verification: Every 12 months, BAs would need to provide written confirmation that required tech protections are deployed. This analysis must be prepared by a subject matter expert and certified as accurate. A generic "we are HIPAA compliant" letter would not satisfy this.
  • 24-hour backup notice: If a BA activates their disaster recovery or business continuity plan in a way that affects your ePHI, they would need to notify you within 24 hours.

If you have 15 business associates, that is 15 annual verifications you need to collect, review, and file. Start building that into your vendor management process now - and make sure you are not making the common BAA mistakes that trip up many practices.

How Much Will HIPAA Security Rule Compliance Cost?

HHS estimates first-year compliance costs at about $9 billion across the industry, with a five-year estimate of about $33 billion for years two through five.

Those are industry-wide numbers. What does it mean for an individual practice?

For a small practice that already has MFA, encryption, and a current risk analysis, the incremental cost may be modest - primarily written records, asset list, and updated BAAs. Maybe $5,000-$15,000 in consulting and IT support.

For a practice that has been skating by with minimal tech protections, the cost is significantly higher. Deploying MFA across all systems, encrypting all endpoints, implementing network segmentation, and building a documented recovery plan could run $25,000-$75,000 or more depending on practice size and existing systems.

Industry groups including CHIME and NHCA have pushed back hard on the cost burden, especially for smaller groups. HHS acknowledged the financial impact but maintains the rules are needed given the scale of healthcare cybersecurity failures - 710 large breaches were reported to OCR in 2025 alone, affecting tens of millions of patients.

No federal funds are set aside for HIPAA compliance. The expense comes from your operating budget. But consider the alternative: the average healthcare data breach cost $9.77 million in 2024, and HIPAA fines increased again in 2026. Compliance is the cheaper option.

What This Means for Small Practices

If you run a small practice - a few physicians, one office manager handling compliance, a limited IT budget - these proposed changes can feel overwhelming. Here is a plain-language breakdown of what each major change would mean for a practice your size, if finalized:

  • MFA everywhere: Every person who logs into your EHR, email, or billing system would need a second verification step. Most EHR platforms already support this. The cost is minimal - authenticator apps are free. The effort is training your staff to use it.
  • Full encryption: Every laptop, desktop, and USB drive in your office that touches patient data would need to be encrypted. Most modern operating systems include built-in encryption (BitLocker on Windows, FileVault on Mac). The gap is usually old machines and portable devices.
  • Annual risk analysis: You would need a documented review of your specific threats and vulnerabilities every year - not a generic checklist, but one that names your actual systems and vendors. This is where a structured risk assessment process pays for itself.
  • Asset inventory: You would need to list every device and system that touches ePHI - including that old printer in the back office. For a small practice, this might be 15-30 items. Manageable, but it must be written down and updated annually.
  • 72-hour recovery: If ransomware hits, can you be back up in three days? For small practices, this usually means cloud-based backups and a written plan for what to restore first. Test the backup at least once before you need it.
  • Vendor verification: Your business associates - EHR vendor, billing company, IT support, shredding service - would each need to provide annual written proof of their security controls. Start asking now so it is not a scramble later.

The good news: most of these steps are things a well-run small practice should already be doing. The proposed rule would formalize them and remove the gray area. If you start now, you will be ahead regardless of when the final rule lands.

The Political Variable

One important caveat: this NPRM was published in the final days of the Biden administration. The current administration has the authority to modify, delay, or withdraw the proposed rule.

However, as of early 2026, OCR has kept finalization on its official rule-based agenda. Healthcare cybersecurity has bipartisan support - ransomware attacks on hospitals do not have a political party. Industry observers and legal analysts widely expect the rule to be finalized, potentially with some modifications based on the comment period feedback.

The smart play is to prepare as if it is happening. If it gets delayed, you have strengthened your security posture. If it does not, you are ready.

What to Start Doing This Month

You do not need to wait for the final rule. Everything on this list is either already required under current HIPAA rules or directly aligned with where the rule is headed:

Deploy MFA everywhere. Start with your EHR, then email, then billing software. Most platforms support it natively. Authenticator apps are free. This is the single highest-impact step you can take. Our MFA setup guide walks you through it step by step.

Audit your encryption. Find every place ePHI lives and moves. Verify it is encrypted at rest and in transit. Document any gaps and fix them.

Build your asset list. List every device, system, and application that touches ePHI. Include location, owner, and version. This becomes a living record you update at all times.

Draw your network map. Show how ePHI flows through your systems and out to vendors. If you cannot draw it, you do not understand it - and you cannot secure it.

Update your BAAs. Add the 24-hour backup notice clause and annual verification rule. Start with your most key vendors. Do not make the BAA mistakes that leave you exposed when a vendor gets hacked.

Test your backups. Run an actual recovery drill. Time it. Can you restore key systems within 72 hours? If not, that is your priority.

Budget now. Whatever this costs, it costs less than a breach. The compliance investment is the cheaper option compared to a $6.6 million fine year like 2025.

The Bottom Line

The proposed 2026 HIPAA Security Rule update would be the most significant healthcare cybersecurity rule in over a decade. If finalized, it would eliminate the addressable loophole, mandate MFA and encryption, require annual risk analyses and compliance audits, and hold business associates to documented verification standards.

The timeline is tight: final rule expected mid-2026, compliance deadline approximately 240 days after publication. Organizations that start preparing now will be better positioned to meet the deadline. Organizations that wait will have less time to close gaps.

The rules are catching up to the threats. Make sure your practice keeps up with both.


Key stat: The proposed 2026 Security Rule changes include mandatory encryption for all ePHI, 72-hour system restoration requirements, annual penetration testing, and technology asset inventories. If finalized, these would represent the most significant expansion of HIPAA technical requirements since the Security Rule was first published in 2003.

Sources

Regulatory Updates


Need help preparing for the new Security Rule? One Guy Consulting offers compliance reviews, risk analysis services, and setup support for practices of all sizes. Get started risk assessment tool

Related: What Is HIPAA Certification? Why It Does Not Exist Under Federal Law

FAQ

Frequently Asked Questions

What are the major HIPAA Security Rule changes in 2026?

The 2026 update includes seven significant changes: mandatory multi-factor authentication, defined encryption standards, required risk assessments every 12 months, network segmentation requirements, asset inventory obligations, enhanced incident response timelines, and stronger vendor oversight requirements.

Is MFA now required under the 2026 HIPAA Security Rule?

Yes. Multi-factor authentication is no longer addressable under the 2026 update. Covered entities and business associates must implement MFA for all systems that access ePHI by the compliance deadline.

How often must a HIPAA risk assessment be conducted under the new rules?

The 2026 Security Rule update requires a documented risk assessment at least every 12 months, as well as following significant operational or environmental changes.

When do the 2026 HIPAA Security Rule changes take effect?

The final rule was published in 2025 and most covered entities have 180 days to comply. Small health plans may have up to 240 days. Organizations should review their current safeguards against the updated requirements immediately.

What happens if an organization does not comply with the 2026 HIPAA Security Rule updates?

Non-compliance exposes organizations to OCR enforcement actions, which can result in fines ranging from hundreds to millions of dollars per violation category, depending on the tier and whether the violation reflects willful neglect.