Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now
Quick answer: No. As of mid-2026, the proposed HIPAA Security Rule overhaul is still just that โ proposed. OCR has not issued a final rule, its informal May 2026 target came and went with nothing published, and a coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the rule altogether. That said, organizations shouldn’t treat “not final” as “not urgentโ as HIPAA’s civil penalty tiers already increased this year under current law, and history shows compliance windows shrink fast once a final rule does land.
What the Proposed Rule Would Actually Change
The HIPAA Security Rule hasn’t seen a substantive update since 2013. The Notice of Proposed Rulemaking published in January 2025 would be the most significant rewrite in the rule’s history, and the headline change is structural: it eliminates the long-standing distinction between “addressable” and “required” safeguards. Today, organizations can implement reasonable alternatives to certain controls and document why. Under the proposal, that flexibility disappears โ nearly every safeguard becomes mandatory.
In practice, that means encryption of electronic PHI at rest and in transit with no documented-alternative exception, multi-factor authentication required for any system that touches ePHI, network segmentation written explicitly into the technical safeguards, and a shift from occasional testing to recurring, scheduled technical assessments such as penetration testing. Business associates would also face tighter, faster incident-reporting obligations to the covered entities they serve.
Where Things Actually Stand
OCR’s own regulatory agenda pointed to a May 2026 finalization, but that window has passed without action. Pushback has been significant: HHS’s own regulatory impact analysis estimated roughly $9 billion in first-year industry compliance costs, climbing toward $34 billion over five years, and that price tag is a big part of why provider groups are lobbying for withdrawal rather than finalization. There’s no confirmed new timeline. If and when a final rule does publish, the expected compliance runway is short โ roughly 60 days until the rule takes effect, then another 180 days to come into full compliance.
The Part That’s Already Real: Penalties Went Up
Separately from the Security Rule fight, OCR’s civil monetary penalty tiers received their routine annual inflation adjustment effective January 28, 2026. The top tier โ willful neglect that goes uncorrected โ now caps at $2,190,294 per calendar-year violation category, with the other tiers adjusted upward as well. This is current law today, independent of whatever happens with the proposed overhaul.
What to Do Now, Regardless of the Final Rule’s Fate
The organizations best positioned aren’t waiting for a final rule to start the clock. Encrypting ePHI everywhere, rolling out MFA, segmenting networks, and testing on a schedule are good security practice today and lower your real exposure under the penalty structure that already exists. A practical starting point: refresh your documented risk analysis, confirm your business associate agreements already require prompt breach notification language, and budget for these controls now rather than scrambling on a 240-day deadline later.
Frequently Asked Questions
Has the HIPAA Security Rule update been finalized? No. As of mid-2026 it remains a proposed rule with no confirmed finalization date.
Will MFA become mandatory under HIPAA? Under the proposed rule, yes โ for any system accessing ePHI. It isn’t legally required yet, though many auditors already treat it as a baseline expectation.
How long would organizations get to comply once it’s final? Industry estimates point to about 240 days total: roughly 60 days until the rule takes effect, then 180 more days to reach full compliance.
Did HIPAA penalties increase in 2026? Yes. The annual inflation adjustment took effect January 28, 2026, raising the maximum penalty tier.
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.
Reviewed on June 18, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
Sources:
- U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” Notice of Proposed Rulemaking, 90 Fed. Reg. 898 (Jan. 6, 2025). federalregister.gov
- HHS.gov, “HIPAA Security Rule NPRM” overview page. hhs.gov
- HHS.gov, Fact Sheet on the HIPAA Security Rule NPRM. hhs.gov
- U.S Department of Health and Human Services, “Annual Civil Monetary Penalties Inflation Adjustment,” Fed. Reg. (Jan. 28, 2026). federalregister.gov
- HHS.gov, “Summary of the HIPAA Security Rule” (current rule in effect). hhs.gov
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.