Healthcare IT Compliance
The proposed update to the HIPAA Security Rule is taking longer than many healthcare organizations originally expected. The federal regulatory agenda currently targets July 2027 for final action on the rule. That additional time may sound like a reason to wait. It isn't. The existing HIPAA Security Rule remains in effect today, and the proposed changes give healthcare organizations a valuable preview of where cybersecurity expectations are headed.
The better way to look at the HIPAA Security Rule delay is as additional preparation time. Healthcare organizations now have more runway to identify gaps, strengthen controls, improve documentation, test their response capabilities, and build security practices that can withstand scrutiny before a final rule forces the issue.
In This Article
What the HIPAA Security Rule Delay Actually Means
The proposed HIPAA Security Rule has not been withdrawn. It remains in the federal rulemaking process, with final action currently targeted for July 2027. Until a final rule is published and becomes applicable, healthcare organizations and business associates must continue complying with the Security Rule that is already in effect.
The Proposed Rule Is Still a Proposal
HHS issued the proposed Security Rule update to strengthen cybersecurity protections for electronic protected health information (ePHI). Among other changes, the proposal would make security requirements more specific and place greater emphasis on documented, tested, and regularly reviewed cybersecurity practices.
Because the rule is still proposed, organizations should be careful not to treat every item in the proposal as though it were already a new legal requirement. The final rule could change before publication. At the same time, ignoring the proposal until that happens creates a different kind of risk.
Your Current HIPAA Obligations Did Not Get Delayed
The existing Security Rule still requires covered entities and business associates to protect ePHI through appropriate administrative, physical, and technical safeguards. Requirements around risk analysis, risk management, access controls, security awareness, contingency planning, audit controls, and other safeguards remain relevant today.
In other words, the delay affects the proposed changes. It does not suspend the Security Rule healthcare organizations are already responsible for following.
Why Waiting for the Final Rule Is Risky
Waiting until the final rule is published can turn security improvements that could have been planned over months into urgent remediation projects. Many of the areas emphasized by the proposed rule, including asset visibility, access controls, risk analysis, incident response, recovery planning, and security testing, require time to implement and validate properly.
A healthcare organization may discover that enabling a new security control is relatively easy. Proving that the control works consistently across the organization is much harder.
For example, implementing multi-factor authentication in one application does not answer whether every system containing ePHI is appropriately protected. Having backups does not prove critical information can actually be restored. Maintaining an asset spreadsheet does not mean the inventory accurately reflects every device, application, and system touching ePHI.
Those are not problems most organizations want to discover when a compliance deadline, contract review, security incident, or investigation is already underway.
The Delay Gives You Something Valuable: Time
Healthcare organizations can use the additional runway to make improvements methodically instead of reactively. That means identifying what exists today, determining where gaps remain, assigning responsibility, budgeting for necessary improvements, testing safeguards, and documenting progress.
Organizations that begin now are also in a better position to adapt if the final Security Rule differs from the current proposal. A mature security program is easier to adjust than one built from scratch against a deadline.
What Healthcare Organizations Should Be Doing Now
The goal should not be to predict every detail of the final rule. Instead, use the extra time to strengthen the foundational security practices that protect ePHI today and overlap with the direction HHS has outlined in the proposed rule.
- Update your Security Risk Analysis: Confirm that your assessment accurately covers where ePHI is created, received, maintained, and transmitted. Document threats, vulnerabilities, existing safeguards, likelihood, impact, and resulting risk levels.
- Build an accurate technology asset inventory: Identify systems, applications, devices, cloud services, and other technology components that may interact with ePHI. An incomplete inventory makes it difficult to understand where security controls need to apply.
- Review identity and access controls: Verify who can access systems containing ePHI, whether that access is appropriate for their role, how access is granted and removed, and where stronger authentication controls may be needed.
- Evaluate network and system exposure: Understand how systems handling ePHI connect to the rest of your environment and where segmentation or other safeguards could reduce the impact of a compromised account or device.
- Test backup and recovery capabilities: Do not stop at confirming that backups exist. Validate that critical data and systems can actually be restored and document the results of those tests.
- Review incident response procedures: Make sure responsibilities, escalation paths, communication procedures, and recovery steps are documented. Test the plan through tabletop exercises or other appropriate scenarios.
- Strengthen security testing and monitoring: Review how vulnerabilities are identified, how logs and security events are monitored, how findings are addressed, and whether testing is occurring on an appropriate schedule.
- Document remediation: When a risk or security gap is identified, record the corrective action, responsible owner, target date, and progress toward closure. Identifying a problem without showing how it is being managed leaves an important part of the compliance story unfinished.
Practices that want these controls delivered as an integrated service can start with cybersecurity built for healthcare operations.
Use the Extra Time to Build Proof, Not Just Policies
A stronger HIPAA security program should be able to demonstrate that safeguards exist and are functioning, not simply state that policies or technologies are in place. The extra runway before a final rule is an opportunity to build that evidence while strengthening the controls themselves.
Consider the difference between saying, "We have backups," and producing the results of a successful restore test. Or saying, "Our employees use MFA," and showing which systems require it, which users are enrolled, and how exceptions are handled.
The same principle applies across a security program. A current risk analysis is stronger when identified risks have owners and remediation plans. An incident response plan is stronger when it has been tested. Access policies are stronger when access reviews show that inappropriate permissions are actually being removed.
This is where the delay can work in your favor. Instead of rushing to create documentation after a requirement becomes final, healthcare organizations can spend this time building repeatable processes and collecting evidence as those processes operate.
Don't Build Only for the Proposed Rule
The final regulation may not look exactly like the current proposal. That is another reason not to treat this period as a race to check off a list of proposed requirements.
Focus first on reducing actual risk to ePHI and strengthening the security program you are already required to maintain. Then use the proposed rule as a roadmap for areas that may require greater specificity, documentation, testing, or oversight in the future.
Structured HIPAA compliance support can help organizations evaluate their existing environment, identify gaps, and prioritize improvements without waiting for a final rule to determine where they stand.
Frequently Asked Questions
Has the new HIPAA Security Rule been delayed?
The proposed HIPAA Security Rule remains in the federal rulemaking process. The current federal regulatory agenda targets July 2027 for final action. That date is a regulatory planning target, not a guarantee that a final rule will be published on that exact date.
Does the HIPAA Security Rule delay change what healthcare organizations must do today?
No. The existing HIPAA Security Rule remains in effect. Covered entities and business associates must continue protecting ePHI through the administrative, physical, and technical safeguards required under the current rule while the proposed changes move through the rulemaking process.
Should healthcare organizations wait until the HIPAA Security Rule is finalized before making changes?
Waiting can create unnecessary operational and compliance risk. Organizations can use the additional time to update risk analyses, improve asset visibility, strengthen access controls, test incident response and recovery capabilities, address existing gaps, and improve documentation without assuming every proposed requirement will appear unchanged in the final rule.
Are the cybersecurity requirements in the proposed HIPAA Security Rule already mandatory?
Not simply because they appear in the proposed rule. A proposed rule does not itself change the regulations. However, many areas addressed by the proposal overlap with existing Security Rule obligations and widely used cybersecurity practices, making them valuable areas for organizations to assess now.
What should healthcare organizations prioritize during the additional preparation time?
Start with an accurate Security Risk Analysis and a clear understanding of where ePHI exists. From there, review asset inventories, access controls, authentication, security monitoring, incident response, backup and recovery testing, remediation tracking, and the documentation needed to demonstrate that safeguards are operating as intended.
Don't Wait for the Final Rule to Find Your Gaps
The additional time before final action gives healthcare organizations an opportunity to understand what is already working, identify what is missing or outdated, and prioritize improvements before a deadline, audit, or incident forces the issue.
Get Your HIPAA Security Assessment