The new HIPAA Security Rule is still a proposal, not a deadline
If you run a practice, you have probably been told there are new HIPAA security requirements arriving this year, possibly with a countdown attached. There are not. A significant update to the Security Rule was proposed in January 2025, and as of today it is still exactly that: a proposal. This guide covers where it stands, what it would change if it is finalised, what binds your practice in the meantime, and how to check a compliance deadline for yourself before anyone sells you one.
Where the rule actually stands
The Department of Health and Human Services published a notice of proposed rulemaking on 6 January 2025, titled HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information. It runs to 125 pages. The public comment period closed on 7 March 2025, and the department has been working through the responses since.
A proposed rule is a question, not an instruction. It exists so that anyone affected can tell the government what it got wrong, and it binds nobody while it is open. It becomes enforceable only when a final rule is published, with its own compliance dates, and that has not happened.
The schedule has also moved. Final action was targeted for May 2026 and is now listed for July 2027. A year of slippage on a rule this size is unremarkable, and it may move again. What it means for you is simpler: there is no 2026 HIPAA deadline, because there is no 2026 rule.
What the proposal would change
Worth understanding, and worth keeping in the conditional. Every item below is what the proposal would require if finalised in its current form, which is not something anyone can promise.
- The addressable category would go away. Safeguards that practices currently document their way around would simply apply. This is the biggest single change for a small office, and it has a section below to itself.
- Multi-factor sign-in would be required rather than strongly advisable, for practices of every size.
- Encryption would become a standard, covering patient data both stored and in transit.
- You would have to write down what you own. A technology asset inventory and a map of how patient data moves through your systems, reviewed at least annually and after any material change.
- Testing would be on a clock. Vulnerability scanning at least every six months and penetration testing at least annually.
- Recovery would have a target. Plans capable of restoring systems that hold patient data within 72 hours of a disruption.
Read that list as a picture of where the regulator's thinking is going, because it is a reliable one. Read it as a bill of work due this year and you have been sold something.
The change that would land hardest on a small practice
Today the Security Rule labels each safeguard required or addressable. Addressable has never meant optional; it means you either implement the safeguard or write down why it is not reasonable in your practice and what protects you instead. In real offices that second path is where a great deal of small-practice compliance lives, and often it lives there legitimately.
Removing the category removes the second path. That is a meaningful shift for a five-person office, and it is the part of the proposal worth watching. It is also the part most likely to be argued over between now and whenever a final rule appears, which is precisely why nobody can tell you today what you will owe.
The word itself trips practices up long before any rule changes. There is more on that in what a HIPAA security risk analysis is, including why skipping an addressable item without the written reasoning is already a gap under the rule you are under now.
What binds you today
The noise about future requirements buries something simpler. The obligation practices are penalised for is not new and is not proposed. It is the risk analysis, and it has been required for years.
In the resolution agreements the Office for Civil Rights publishes, failure to conduct an accurate and thorough risk analysis appears again and again as the first item of covered conduct, ahead of the breach that triggered the investigation. A practice worrying about a 2027 proposal while carrying no current risk analysis has its attention in the wrong decade.
How to check a compliance deadline yourself
You should not have to take our word for any of this, and the check takes about two minutes. Both sources are free and official.
- Look for a Federal Register citation. Rules are published there and nowhere else. A page announcing a requirement without one is describing something other than a requirement. On federalregister.gov every document is labeled, and a proposed rule keeps that label until a final rule replaces it.
- Check the government's own target date. The Unified Agenda at reginfo.gov lists when agencies expect to act. It is where the July 2027 date in this guide comes from, and it is the same page anyone selling you a deadline could have read.
- Watch the verb. Careful writing about a proposal says would. Marketing about a proposal says will, or must, or counts down days. That single word is the fastest tell there is.
What to do between now and whenever it lands
Nothing urgent, and nothing wasted. Get a current risk analysis, because that is the live obligation and the one with an enforcement record behind it. Then work through the proposal's list at your own pace, because multi-factor sign-in, encrypted laptops, knowing what equipment you own and a recovery plan you have actually tested are all worth having on their own merits. A practice that does those because they are sensible will find any final rule an administrative exercise. A practice that waits to be frightened into them will pay more and get less.
And when the final rule does appear, it will arrive with its own compliance dates, published in the Federal Register, giving everyone the same notice at the same time. That is how this works. Nobody gets an early copy to sell you.
FAQ
Are there new HIPAA security requirements I have to meet this year?
No. The Security Rule that binds your practice today is the same one that has bound it for years. A substantial update was proposed in January 2025 and it is still a proposal. Nothing in it is enforceable, no compliance date has been set, and the government's own schedule now points at July 2027 for final action. Anything selling you a 2026 deadline is selling you a deadline that does not exist.
So can I ignore the proposed rule entirely?
Ignore the deadline, not the direction. Most of what the proposal would require is already ordinary good practice, and several items are things a security-conscious office would want regardless: knowing what equipment you own, multi-factor sign-in, encrypted laptops, and a tested plan for getting back up after an outage. Doing those now is sensible. Buying them in a panic against a date somebody invented is not.
What would change about addressable safeguards?
This is the change with the most consequence for a small practice. Today the rule splits safeguards into required and addressable, where addressable means you either implement the safeguard or document in writing why it is not reasonable and what you do instead. The proposal would remove that category, so specifications that practices have been documenting their way around would simply apply. It is worth understanding for that reason alone, but again: it would apply, not it does apply.
How do I check any of this myself?
Two free places, both official. federalregister.gov holds the proposed rule, and a proposed rule stays labeled a proposed rule until a final one is published. The Unified Agenda at reginfo.gov holds the government's own current target date for final action. If a page tells you a HIPAA deadline is coming, look for a Federal Register citation on it. Real requirements always have one, because that is where rules are published.
What actually gets practices fined right now?
The risk analysis, over and over. In the resolution agreements OCR publishes, failure to conduct an accurate and thorough risk analysis is repeatedly the first item of covered conduct, ahead of the breach that started the investigation. That obligation is current, it is not new, and it does not depend on any proposed rule being finalised.
Not sure where your practice stands? The risk analysis guide covers the obligation that is live today, and the free Security Check is a one-page report on what your office shows the outside world, prepared without installing anything or touching a system you own. How an engagement starts is on the practices page. None of this is legal advice, and what your practice owes is a question for qualified healthcare counsel.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
