Status of the HIPAA Security Rule update as of September 27, 2026
As of September 27, 2026, the Federal Register lists only the proposed rule for RIN 0945-AA22. It has not been finalized or withdrawn. The regulation identifier number (RIN) ties the documents in one rulemaking together, so a final rule or a withdrawal would normally carry the same number.
The HHS Office for Civil Rights published the notice of proposed rulemaking, titled "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information," on January 6, 2025, at 90 FR 898. The comment period closed on March 7, 2025.
A proposed rule creates no new obligations. The proposal itself says that regulated entities would have until a compliance date, set by a final rule, to meet any new or changed standards. Until then, the Security Rule as last substantively amended in 2013 remains in force.
What HHS proposed in January 2025
HHS said most existing obligations would not change substantially: the proposal would turn activities it considers critical to protecting electronic protected health information (ePHI) into explicit requirements, with more detail in the regulatory text. Every item below is a proposal, taken from the proposed regulatory text; section numbers refer to the proposed sections, not the rule in force.
The table compares the main proposals with today's rule. A final rule could keep, change, or drop any of them.
- Proposed: written documentation of Security Rule policies and procedures and of each required action, activity, or assessment, reviewed at least once every 12 months (proposed 45 CFR 164.316).
- Proposed: a written technology asset inventory and a network map showing how ePHI moves through your electronic information systems, updated at least once every 12 months and when your environment changes (proposed 164.308(a)(1)).
- Proposed: patching critical risks within 15 calendar days and high risks within 30 calendar days, with documented exceptions (proposed 164.308(a)(4)).
- Proposed: written security incident response plans, reviewed and tested at least once every 12 months (proposed 164.308(a)(12)).
- Proposed: a documented compliance audit at least once every 12 months (proposed 164.308(a)(14)).
- Proposed: business associates would report activation of their contingency plan to the covered entity within 24 hours (proposed 164.314(a)(2)(i)(D)).
| Topic | Rule in force today | As proposed in January 2025 |
|---|---|---|
| Implementation specifications | Required or addressable. Addressable ones are implemented if reasonable and appropriate; if not, the reason is documented and an equivalent alternative used where reasonable and appropriate (164.306(d)) | All would be required, with the flexibility limited to how each is met (proposed 164.306(c)) |
| Encryption | Addressable: a mechanism to encrypt and decrypt ePHI (164.312(a)(2)(iv)), and encryption in transmission whenever deemed appropriate (164.312(e)(2)(ii)) | Required for all ePHI at rest and in transit, with limited documented exceptions (proposed 164.312(b)) |
| Authentication | Verify that a person or entity seeking access is the one claimed; no method named (164.312(d)) | Multi-factor authentication for relevant systems, with limited exceptions (proposed 164.312(f)) |
| Vulnerability scanning | Not named; a periodic technical and nontechnical evaluation is required (164.308(a)(8)) | Automated scans at least every six months, or more often if the risk analysis calls for it (proposed 164.312(h)(2)(i)) |
| Penetration testing | Not named in the rule | At least every 12 months, or more often per the risk analysis, by a qualified person (proposed 164.312(h)(2)(iii)) |
| Risk analysis | Required: an accurate and thorough assessment of risks to ePHI, with no fixed review interval (164.308(a)(1)(ii)(A)) | Written, informed by the asset inventory and network map, and reviewed at least every 12 months and when the environment changes (proposed 164.308(a)(2)) |
| Contingency planning | Data backup, disaster recovery, and emergency mode plans required; testing and revision addressable (164.308(a)(7)) | Procedures to restore critical systems and data within 72 hours of a loss, and plans tested at least every 12 months (proposed 164.308(a)(13)) |
| Business associates | Satisfactory assurances documented in a written agreement (164.308(b), 164.314) | Also written verification, at least every 12 months, that the business associate has deployed required technical safeguards (proposed 164.308(b)) |
What the Security Rule requires today
Today's obligations come from 45 CFR Part 164, Subpart C. Covered entities and business associates must ensure the confidentiality, integrity, and availability of the ePHI they create, receive, maintain, or transmit, protect it against reasonably anticipated threats and impermissible uses or disclosures, and ensure their workforce complies (164.306(a)).
The rule lets you choose security measures that fit your size, complexity, capabilities, technical infrastructure, costs, and the probability and criticality of your risks (164.306(b)). Addressable never meant optional: you assess each addressable specification, implement it if it is reasonable and appropriate, or document why not and implement an equivalent alternative if reasonable and appropriate (164.306(d)(3)).
The risk analysis and risk management specifications are both required (164.308(a)(1)(ii)(A) and (B)), and so is a periodic technical and nontechnical evaluation (164.308(a)(8)). Required documentation is kept for six years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)(i)).
The proposal shows how HHS reads the current rule. It says an accurate and thorough risk analysis already calls for an inventory of technology assets and an understanding of how ePHI moves through your systems, and that it would generally be reasonable and appropriate for regulated entities to encrypt ePHI.
Timing if the rule is finalized
As proposed, a final rule would take effect 60 days after it is published in the Federal Register. Regulated entities would then have until a compliance date, proposed as the standard 180 days after the effective date under 45 CFR 160.105, to meet the new or changed standards.
HHS also proposed a transition for existing business associate agreements in a new 45 CFR 164.318. An agreement that complied with today's rules before publication, and wasn't renewed or modified during a set window, could stay in place for a limited time, ending at the latest one year and 60 days after the final rule is published, or earlier if it is renewed after a set date.
All of this is proposed timing. A final rule could set different dates or stagger them for particular requirements, so plan from the final text rather than from the proposal.
How to plan without over-reacting
The sensible response to the proposed HIPAA Security Rule update is to strengthen what the current rule already asks for, starting with the risk analysis. Many proposed items, such as multi-factor authentication, encryption, asset inventories, regular vulnerability scanning, and tested backups, are reasonable safeguards on their own merits for many organizations.
Keep two lists. The first is your risk management plan under today's rule. The second is a short gap list against the proposal, so you can estimate the effort if a final rule arrives, without rewriting policies for requirements that may change.
- Refresh your risk analysis, and make sure it covers every system, vendor, and data flow that touches ePHI.
- Record a decision for each addressable specification, especially encryption, automatic logoff, and integrity controls.
- Build or update a technology asset inventory and a data flow map; both make the current risk analysis more accurate.
- Review how you authenticate users and administrators, and where multi-factor authentication would reduce real risk now.
- Test your backups and your contingency plan, and note how long restoration actually takes.
- Check what evidence you would need from each business associate, and how you would collect it.
Government resources for the current rule
NIST SP 800-66 Rev. 2, published in February 2024, is a cybersecurity resource guide for implementing the current Security Rule. The HHS/ONC Security Risk Assessment Tool, version 3.7 released September 18, 2026, is designed for small and medium providers; its disclaimer says using it is not required by law and doesn't ensure compliance.
Where to watch for a final rule
Watch the Federal Register for documents under RIN 0945-AA22. A final rule, a withdrawal, or any further proposal would be published there, and the eCFR text of Subpart C would change only once a final rule takes effect.
Treat predictions with care. Until a final rule is published, no one can say which proposals will survive or when they would apply, and any date you plan around should come from the published text.