Businessman reviewing HIPAA policy documents with 2026 security update graphics and compliance book stack on desk.

2026 HIPAA Security Rule Update: Key Changes, Compliance Steps, and What's Next

2026 HIPAA Security Rule Update: Key Changes, Compliance Steps, and What's Next

Author Nicole Statley at Healthcare Compliance Pros

If you've been hearing about a major HIPAA Security Rule overhaul and you're not totally sure what's actually changed versus what's still just a proposal, you're not alone. It's a confusing time. HHS proposed sweeping cybersecurity updates back in December 2024, and as of this writing, the rule still hasn't been finalized. But that doesn't mean you should wait to prepare. Here's where things stand, what's likely coming, and what your organization should be doing right now.

What Is the 2026 HIPAA Security Rule Update?

The HIPAA Security Rule has governed how covered entities and business associates protect electronic protected health information (ePHI) since 2003. It requires administrative, physical, and technical safeguards, but much of it has always been flexible. Organizations got to decide what was "reasonable and appropriate" for their size and risk level, and many requirements were labeled "addressable," meaning you could implement an alternative or even skip them if you documented why.

That flexibility is exactly what regulators now say is the problem.

On December 27, 2024, the HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) to strengthen the Security Rule. It was published in the Federal Register on January 6, 2025, and the public comment period closed March 7, 2025. OCR pointed to the surge in healthcare cyberattacks and ransomware incidents, along with the Biden administration's National Cybersecurity Strategy, as the driving force behind the rulemaking.

Here's the part that trips people up: this rule is still proposed, not final. The current Security Rule remains fully in effect, and organizations are not yet legally required to meet the new standards. But HHS's own regulatory agenda has consistently signaled that a final rule is coming, so treating this as a "someday" problem is risky.

Where things stand as of September 2026

  • NPRM published: January 6, 2025
  • Public comment period: closed March 7, 2025
  • Original target for final rule: May 2026
  • Current OMB target for final action: July 2027, per the federal Unified Agenda
  • Status right now: proposed only, current rule still enforceable

That July 2027 date isn't a guarantee either. It's HHS's own working estimate, and these timelines have already shifted once. Once a final rule is published, regulated entities would likely get a 180-day compliance window, based on how OCR has structured past rule changes.

Major Changes in the 2026 Update

The proposal is the most significant rewrite of the Security Rule since it was written. The biggest structural shift: OCR wants to eliminate the "required" versus "addressable" distinction entirely. If finalized, nearly everything becomes mandatory, with only narrow, specific exceptions.

Here's a breakdown of the major provisions, straight from the official OCR fact sheet:

Technical safeguards that would become mandatory:

  • Encryption of ePHI at rest and in transit, with limited exceptions
  • Multi-factor authentication (MFA) for accessing systems with ePHI
  • Network segmentation
  • Anti-malware protection
  • Removal of extraneous software from systems
  • Vulnerability scanning at least every six months
  • Penetration testing at least once every 12 months

Administrative and documentation requirements:

  • Written documentation of all Security Rule policies, procedures, plans, and analyses
  • A technology asset inventory and network map, updated at least every 12 months
  • A more detailed, prescriptive risk analysis process, including threat and vulnerability identification with documented risk levels
  • Annual compliance audits
  • Business associate verification of technical safeguards at least once every 12 months, backed by written certification

Contingency and incident response:

  • Written procedures to restore critical systems within 72 hours of a loss
  • Written incident response plans with defined reporting procedures
  • Notification within 24 hours when a workforce member's access to ePHI is terminated or changed
  • Business associates notifying covered entities within 24 hours of activating a contingency plan

A quick note on scope: this would also touch group health plans, requiring plan documents to obligate sponsors to follow the same administrative, physical, and technical safeguards.

Status check: proposed vs. current requirement

Requirement

Current Security Rule

2026 Proposal (not yet final)

Encryption of ePHI

Addressable

Mandatory, limited exceptions

Multi-factor authentication

Not specifically required

Mandatory, limited exceptions

Risk analysis

Required, general standard

Required, with detailed written components

Asset inventory/network map

Not explicitly required

Required, updated annually

Incident response plan

General requirement

Detailed written plan and testing required

Compliance audits

Not required

Required annually

Business associate verification

Not required

Required annually with certification

Compliance Timelines: What to Do Now vs. What to Watch

Because nothing is final yet, there's no legal deadline to hit today. But "no deadline" doesn't mean "no action."

Do now, regardless of final rule timing:

  • Update your risk analysis to reflect current threats, even if it's not yet in the exact format OCR is proposing
  • Start building or refining a technology asset inventory and network map
  • Evaluate your current use of encryption and MFA, and start closing gaps
  • Review contingency and incident response plans against the proposed 72-hour restoration standard

Monitor, but don't panic about yet:

  • The exact final compliance deadline (expect roughly 180 days after a final rule publishes)
  • Whether OCR extends or shortens that window in the final version
  • Any changes to specific provisions based on public comments received

Given that the final action date has already slipped from May 2026 to July 2027, it's smart to assume there's more runway than the original headlines suggested, while still using this time productively.

How Organizations Are Preparing

Recent OCR enforcement actions keep landing on the same weak spots: missing or outdated risk analyses, no MFA on remote access, and unencrypted devices or data. These aren't new HIPAA problems, but the proposed rule would make them non-negotiable rather than judgment calls.

Practical steps organizations are taking:

  • Technology upgrades: rolling out MFA across email, EHR access, and remote connections; encrypting laptops, servers, and backup systems
  • Policy updates: rewriting risk analysis templates and incident response plans to match the more detailed proposed structure
  • Staff training: refreshing workforce training on phishing, password hygiene, and reporting suspected incidents
  • Vendor management: reviewing business associate agreements and starting the habit of documenting BA safeguard verification annually

Special considerations by organization type:

  • Small practices often lack in-house IT staff, so third-party managed security providers become essential for tasks like vulnerability scanning and penetration testing
  • Hospitals and health systems tend to have more complex network environments, making the network mapping and segmentation requirements a heavier lift
  • Business associates face new direct verification obligations to covered entities, which means documentation processes need to exist even before the rule is final

Common Pitfalls and How to Avoid Them

OCR investigations tend to uncover the same handful of mistakes, over and over.

  • Treating the risk analysis as a one-time checkbox instead of an ongoing, documented process
  • Assuming a firewall and antivirus software satisfy "reasonable and appropriate" safeguards
  • Failing to track where ePHI actually lives and moves within the organization's systems
  • Skipping documentation, even when the right safeguard is technically in place
  • Not verifying that business associates and vendors are actually following through on their security commitments

This is where Healthcare Compliance Pros steps in. Instead of generic templates, we work with your organization to build a risk analysis and documentation process that actually reflects your systems and workflows, so you're not scrambling when a final rule drops or an audit request lands on your desk.

How Healthcare Compliance Pros Can Help

Preparing for a rule that isn't final yet is a balancing act. You don't want to over-invest in requirements that could still shift, but you also don't want to be caught flat-footed once they lock in.

Our team supports organizations through:

  • Comprehensive HIPAA risk analysis and gap assessments measured against both current requirements and the proposed 2026 changes
  • Policy and procedure development, including incident response plans and contingency planning documentation
  • Technology asset inventory and network mapping support
  • Business associate agreement review and verification process design
  • Staff training programs tailored to your organization's actual risk profile
  • Ongoing compliance monitoring so you're not starting from scratch every time a regulation changes

Whether you're a solo practice or a multi-site health system, we tailor our approach to your size, resources, and current compliance maturity rather than handing you a one-size-fits-all binder.

FAQ: HIPAA Security Rule Update 2026

Is the 2026 HIPAA Security Rule Update currently enforceable?
No. It remains a proposed rule. The current HIPAA Security Rule, unchanged, is what OCR enforces today.

When will the final rule be published?
There's no confirmed date. HHS's Unified Agenda currently targets July 2027 for final action, pushed back from an earlier May 2026 estimate. This is a planning estimate, not a binding deadline.

How much time will organizations get to comply once it's final?
Based on how OCR has structured past rule changes, expect a compliance window of roughly 180 days after the final rule's effective date, though OCR could adjust this.

Will small practices get any exceptions?
The proposal includes "specific, limited exceptions" to the new mandatory requirements, but OCR hasn't detailed a blanket small-practice carve-out. Organizations should assume most requirements will apply broadly.

What penalties apply if my organization isn't ready?
Since the rule isn't final, there are no penalties tied to the proposed provisions yet. Current HIPAA Security Rule penalties, which range based on violation tier and willfulness, still apply for existing requirements.

Does this apply to business associates too?
Yes. The proposal explicitly includes new obligations for business associates, including annual verification of technical safeguards and contingency plan notifications.

Should we wait for the final rule before making changes?
Not recommended. Building strong risk analysis practices, documentation, and safeguards now protects you under current law and puts you ahead of the curve regardless of the final rule's exact timing.

Resources and Further Reading

This article is for informational purposes and does not constitute legal advice. Consult qualified legal counsel for guidance specific to your organization.