Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Guide

Proposed HIPAA Security Rule changes: status and impact

The HIPAA Security Rule update that HHS proposed in January 2025 is still only a proposal. As of September 27, 2026, the Federal Register lists only the proposed rule for RIN 0945-AA22; it has not been finalized or withdrawn. This guide explains what HHS proposed, what the rule requires today, and how to plan without guessing at a final version.

Compliance9 min read

By Security Inspect · Sources checked

Key takeaways

  • As of September 27, 2026, the only Federal Register document under RIN 0945-AA22 is the proposed rule published January 6, 2025 (90 FR 898); it has not been finalized or withdrawn.
  • Nothing in the proposal applies today. Covered entities and business associates must meet 45 CFR Part 164, Subpart C as it stands, including an accurate and thorough risk analysis.
  • HHS proposed ending the split between required and addressable specifications, and requiring encryption, multi-factor authentication, vulnerability scans at least every six months, and penetration tests at least every 12 months.
  • As proposed, a final rule would take effect 60 days after publication, with compliance due 180 days after that, and a limited transition for existing business associate agreements.
  • Many proposed items are already sound risk decisions. A current risk analysis shows which ones matter most in your environment.

Status of the HIPAA Security Rule update as of September 27, 2026

As of September 27, 2026, the Federal Register lists only the proposed rule for RIN 0945-AA22. It has not been finalized or withdrawn. The regulation identifier number (RIN) ties the documents in one rulemaking together, so a final rule or a withdrawal would normally carry the same number.

The HHS Office for Civil Rights published the notice of proposed rulemaking, titled "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information," on January 6, 2025, at 90 FR 898. The comment period closed on March 7, 2025.

A proposed rule creates no new obligations. The proposal itself says that regulated entities would have until a compliance date, set by a final rule, to meet any new or changed standards. Until then, the Security Rule as last substantively amended in 2013 remains in force.

What HHS proposed in January 2025

HHS said most existing obligations would not change substantially: the proposal would turn activities it considers critical to protecting electronic protected health information (ePHI) into explicit requirements, with more detail in the regulatory text. Every item below is a proposal, taken from the proposed regulatory text; section numbers refer to the proposed sections, not the rule in force.

The table compares the main proposals with today's rule. A final rule could keep, change, or drop any of them.

  • Proposed: written documentation of Security Rule policies and procedures and of each required action, activity, or assessment, reviewed at least once every 12 months (proposed 45 CFR 164.316).
  • Proposed: a written technology asset inventory and a network map showing how ePHI moves through your electronic information systems, updated at least once every 12 months and when your environment changes (proposed 164.308(a)(1)).
  • Proposed: patching critical risks within 15 calendar days and high risks within 30 calendar days, with documented exceptions (proposed 164.308(a)(4)).
  • Proposed: written security incident response plans, reviewed and tested at least once every 12 months (proposed 164.308(a)(12)).
  • Proposed: a documented compliance audit at least once every 12 months (proposed 164.308(a)(14)).
  • Proposed: business associates would report activation of their contingency plan to the covered entity within 24 hours (proposed 164.314(a)(2)(i)(D)).
The HIPAA Security Rule in force compared with the January 2025 proposal
TopicRule in force todayAs proposed in January 2025
Implementation specificationsRequired or addressable. Addressable ones are implemented if reasonable and appropriate; if not, the reason is documented and an equivalent alternative used where reasonable and appropriate (164.306(d))All would be required, with the flexibility limited to how each is met (proposed 164.306(c))
EncryptionAddressable: a mechanism to encrypt and decrypt ePHI (164.312(a)(2)(iv)), and encryption in transmission whenever deemed appropriate (164.312(e)(2)(ii))Required for all ePHI at rest and in transit, with limited documented exceptions (proposed 164.312(b))
AuthenticationVerify that a person or entity seeking access is the one claimed; no method named (164.312(d))Multi-factor authentication for relevant systems, with limited exceptions (proposed 164.312(f))
Vulnerability scanningNot named; a periodic technical and nontechnical evaluation is required (164.308(a)(8))Automated scans at least every six months, or more often if the risk analysis calls for it (proposed 164.312(h)(2)(i))
Penetration testingNot named in the ruleAt least every 12 months, or more often per the risk analysis, by a qualified person (proposed 164.312(h)(2)(iii))
Risk analysisRequired: an accurate and thorough assessment of risks to ePHI, with no fixed review interval (164.308(a)(1)(ii)(A))Written, informed by the asset inventory and network map, and reviewed at least every 12 months and when the environment changes (proposed 164.308(a)(2))
Contingency planningData backup, disaster recovery, and emergency mode plans required; testing and revision addressable (164.308(a)(7))Procedures to restore critical systems and data within 72 hours of a loss, and plans tested at least every 12 months (proposed 164.308(a)(13))
Business associatesSatisfactory assurances documented in a written agreement (164.308(b), 164.314)Also written verification, at least every 12 months, that the business associate has deployed required technical safeguards (proposed 164.308(b))

What the Security Rule requires today

Today's obligations come from 45 CFR Part 164, Subpart C. Covered entities and business associates must ensure the confidentiality, integrity, and availability of the ePHI they create, receive, maintain, or transmit, protect it against reasonably anticipated threats and impermissible uses or disclosures, and ensure their workforce complies (164.306(a)).

The rule lets you choose security measures that fit your size, complexity, capabilities, technical infrastructure, costs, and the probability and criticality of your risks (164.306(b)). Addressable never meant optional: you assess each addressable specification, implement it if it is reasonable and appropriate, or document why not and implement an equivalent alternative if reasonable and appropriate (164.306(d)(3)).

The risk analysis and risk management specifications are both required (164.308(a)(1)(ii)(A) and (B)), and so is a periodic technical and nontechnical evaluation (164.308(a)(8)). Required documentation is kept for six years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)(i)).

The proposal shows how HHS reads the current rule. It says an accurate and thorough risk analysis already calls for an inventory of technology assets and an understanding of how ePHI moves through your systems, and that it would generally be reasonable and appropriate for regulated entities to encrypt ePHI.

Timing if the rule is finalized

As proposed, a final rule would take effect 60 days after it is published in the Federal Register. Regulated entities would then have until a compliance date, proposed as the standard 180 days after the effective date under 45 CFR 160.105, to meet the new or changed standards.

HHS also proposed a transition for existing business associate agreements in a new 45 CFR 164.318. An agreement that complied with today's rules before publication, and wasn't renewed or modified during a set window, could stay in place for a limited time, ending at the latest one year and 60 days after the final rule is published, or earlier if it is renewed after a set date.

All of this is proposed timing. A final rule could set different dates or stagger them for particular requirements, so plan from the final text rather than from the proposal.

How to plan without over-reacting

The sensible response to the proposed HIPAA Security Rule update is to strengthen what the current rule already asks for, starting with the risk analysis. Many proposed items, such as multi-factor authentication, encryption, asset inventories, regular vulnerability scanning, and tested backups, are reasonable safeguards on their own merits for many organizations.

Keep two lists. The first is your risk management plan under today's rule. The second is a short gap list against the proposal, so you can estimate the effort if a final rule arrives, without rewriting policies for requirements that may change.

  • Refresh your risk analysis, and make sure it covers every system, vendor, and data flow that touches ePHI.
  • Record a decision for each addressable specification, especially encryption, automatic logoff, and integrity controls.
  • Build or update a technology asset inventory and a data flow map; both make the current risk analysis more accurate.
  • Review how you authenticate users and administrators, and where multi-factor authentication would reduce real risk now.
  • Test your backups and your contingency plan, and note how long restoration actually takes.
  • Check what evidence you would need from each business associate, and how you would collect it.

Government resources for the current rule

NIST SP 800-66 Rev. 2, published in February 2024, is a cybersecurity resource guide for implementing the current Security Rule. The HHS/ONC Security Risk Assessment Tool, version 3.7 released September 18, 2026, is designed for small and medium providers; its disclaimer says using it is not required by law and doesn't ensure compliance.

Where to watch for a final rule

Watch the Federal Register for documents under RIN 0945-AA22. A final rule, a withdrawal, or any further proposal would be published there, and the eCFR text of Subpart C would change only once a final rule takes effect.

Treat predictions with care. Until a final rule is published, no one can say which proposals will survive or when they would apply, and any date you plan around should come from the published text.

Where our work fits

  • HIPAA Security Rule readiness — risk analysis support, safeguards review, and remediation planning.
  • Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

Questions

Is the new HIPAA Security Rule in effect?

No. As of September 27, 2026, the January 2025 proposal (90 FR 898, RIN 0945-AA22) has not been finalized or withdrawn, and it creates no obligations. The rule in force is 45 CFR Part 164, Subpart C, as last substantively amended in 2013, which still requires a risk analysis, risk management, and the other safeguards it sets out.

Will penetration testing be required under HIPAA?

Under the proposal, yes: at least once every 12 months, or more often if the risk analysis calls for it, by a qualified person. The rule in force doesn't name penetration testing, but it requires a risk analysis and a periodic technical and nontechnical evaluation, which may lead you to test. Customers and contracts can also require a test regardless of the rule.

Do our business associate agreements need to change now?

Not because of the proposal. Today's requirements for business associate agreements in 45 CFR 164.314(a) still apply. If a final rule keeps the proposal, agreements would need new terms, such as reporting contingency plan activation within 24 hours, and proposed 164.318 would give compliant existing agreements a limited transition. Ask counsel to review once a final rule is published.

Is there a compliance deadline for the proposed rule today?

No. A deadline would come only from a final rule. As proposed, a final rule would take effect 60 days after publication, and entities would have 180 days after the effective date to comply. A final rule could change that timing, so don't plan around dates that haven't been published.

Should we start meeting the proposed requirements anyway?

Where your risk analysis supports them, yes. Multi-factor authentication, encryption, asset inventories, regular scanning, and tested restores reduce real risk under today's rule as well. Document each decision as a response to your own risk analysis rather than to the proposal, so the reasoning holds whatever the final rule says.

Primary sources

Related guides

Terms in this guide

More on this site

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Talk through your situation with a practitioner

Every engagement begins with a written scope and proposal.

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.