
Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.
What Actually Happened
In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:
- Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
- Mandatory multi-factor authentication on all systems touching ePHI
- 72-hour incident reporting timelines
- Annual penetration testing
- Tighter oversight and contractual obligations for business associates
More than 100 hospital systems and provider associations โ including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.
HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.
What the Delay Does Not Change
This is the part that gets lost in the headlines:
- The current Security Rule is still active and enforceable. Every requirement already on the books โ risk analysis, access controls, audit controls, transmission security, business associate agreements โ remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
- OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
- State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
- The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.
“We Have More Time” Is the Wrong Read
The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:
- Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
- A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
- Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ that risk doesn’t disappear because the paperwork is delayed.
What Compliance Teams Should Do With the Extra Time
Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.
- Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ these are the two changes most likely to survive the rulemaking process largely intact.
- Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
- Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ this is the kind of internal capability that takes real time to build.
- Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.
Frequently Asked Questions
Is the HIPAA Security Rule update dead?
No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.
Do I still have to comply with HIPAA Security Rule requirements right now?
Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.
When will the new HIPAA Security Rule requirements take effect?
HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.
What should healthcare organizations do now?
Use the additional time to close gaps against the proposed requirements โ especially encryption, MFA, business associate oversight, and incident response โ rather than waiting for a final rule to start preparing.
Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To
The safest move during this delay isn’t waiting โ it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.
Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.
Schedule Your Free HIPAA Risk Review โ
Source
U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.