Back to Blog

HIPAA Security Rule Update Delayed: Why Healthcare Organizations Should Act Now

The HIPAA Security Rule update may now be projected for July 2027, but healthcare organizations should not treat the delay as a reason to wait. Here is what the proposed changes mean, why the risk is immediate, and how to prepare now.

Healthcare cybersecurity is moving faster than regulation. While the U.S. Department of Health and Human Services continues to refine a major update to the HIPAA Security Rule, healthcare organizations are still facing ransomware, phishing, stolen credentials, and other cyber threats every day.

For compliance, IT, operations, and executive leaders across ambulatory care, senior living, and other healthcare settings, the message is clear: the final rule may be delayed, but the expectations around risk analysis, access controls, encryption, testing, and vendor accountability are already shaping enforcement.

  • Cyber threats are increasing, regardless of the regulatory timeline.
  • OCR enforcement already emphasizes accurate, thorough risk analysis.
  • MFA, encryption, vulnerability management, testing, and vendor accountability are becoming baseline expectations.
  • Once finalized, the compliance window may still be relatively short.

What Is Changing with the HIPAA Security Rule?

The HIPAA Security Rule was originally written in 2003 and has not substantially kept pace with how modern healthcare organizations operate. Cloud-based EHRs, remote teams, connected devices, third-party platforms, and increasingly sophisticated cyberattacks have created risks the original rule did not fully anticipate.

In late 2024, the HHS Office for Civil Rights proposed comprehensive updates to strengthen cybersecurity protections for electronic protected health information. The proposal would move the Security Rule from broad, flexible language toward more specific technical and operational requirements. Final action is now projected for July 2027, rather than May 2026.

What this means: the proposed rule is not law today. The current HIPAA Security Rule remains in effect. However, the proposed update provides a clear signal of where federal expectations are headed, especially around documented risk analysis, MFA, encryption, vulnerability management, penetration testing, incident response, and business associate oversight.

  • More specific technical safeguards for systems that contain or connect to ePHI.
  • Stronger documentation expectations for risk analysis, data flows, and mitigation planning.
  • Greater focus on access controls, MFA, encryption, vulnerability scanning, and penetration testing.
  • More scrutiny of business associates and third-party vendors that touch ePHI.

Why Healthcare Organizations Should Not Wait

The delay gives organizations more time, but it does not reduce the risk. Healthcare remains a high-value target for cybercriminals because clinical operations depend on system availability, protected health information is highly sensitive, and many organizations still operate with lean IT resources.

OCR has also continued to emphasize pre-breach compliance. Recent ransomware settlements have focused heavily on whether organizations conducted an accurate and thorough risk analysis before an incident occurred. In other words, enforcement is not limited to what happened during a breach. It also looks at whether the organization had identified, documented, and addressed its risks in advance.

The takeaway is simple: waiting for a final rule is not a cybersecurity strategy. If your organization does not know where ePHI lives, how it moves, who can access it, and where vulnerabilities exist, it is already operating with exposure.

Key Requirements Healthcare Leaders Should Prepare For

The proposed rule would make several cybersecurity practices more explicit and more prescriptive. Healthcare organizations should use the delay to begin building or validating these capabilities now:

  • Multi-factor authentication: MFA would be required for systems that contain or connect to ePHI, helping reduce the risk of credential-based attacks.
  • Encryption: Organizations should be prepared to demonstrate that ePHI is protected both at rest and in transit.
  • Vulnerability scanning: Regular scanning would help identify known weaknesses before attackers can exploit them.
  • Penetration testing: Annual testing would help validate whether security measures work against real-world attack scenarios.
  • Network segmentation: Segmentation can help limit lateral movement if one system or credential is compromised.
  • Risk analysis and documentation: Organizations should maintain a current inventory of ePHI, systems, data flows, threats, vulnerabilities, and mitigation plans.
  • Business associate accountability: Vendors that create, receive, maintain, or transmit ePHI should be reviewed regularly to confirm they maintain appropriate safeguards.

Understanding the Compliance Timeline

Once a final rule is published, healthcare organizations should expect a relatively short implementation period. Under the proposed structure, the rule would become effective 60 days after publication, followed by 180 days to comply.

That creates a total window of approximately 240 days from publication to compliance. If final action occurs in July 2027, full compliance could realistically fall in 2028, depending on the final rule and publication date.

Business associate agreements may receive a longer transition period, but organizations should not assume that vendor readiness can wait. Many healthcare organizations depend on third parties for EHR, billing, infrastructure, security, hosting, and support services, which means vendor gaps can quickly become compliance and operational gaps.

The final rule may change before publication. Even so, the direction is clear: healthcare organizations will be expected to show stronger cybersecurity controls, better documentation, and a more proactive approach to protecting ePHI.

What This Means for Ambulatory Care and Senior Living

The proposed rule would apply broadly to covered entities and business associates, but the operational impact will vary by organization type, resources, system complexity, and vendor dependence.

Ambulatory care organizations often operate withwith lean IT teams, multiple locations, tight budgets, and a mix of cloud-based and legacy systems. A realistic readiness plan should prioritize:includeePHIvalidation, and vendor reviewsite and system

  • Asset inventory and ePHI mapping across every site and system.
  • MFA rollout for EHR access, email, VPNs, and administrative tools.
  • Encryption validation, vulnerability scanning, and penetration testing.
  • Vendor review for systems and partners that touch ePHI.

Senior living communities may manage large volumes of resident data while relying heavilyheavily on third-party technology vendors, managed services, and legacy infrastructure. Priorities should include:includephishing-resistant access controls, incident response planning, and  that reflects the realities of care operations

  • MFA and phishing-resistant access controls.
  • Encryption for resident data, clinical systems, backups, and shared files.
  • Vendor accountability for managed services, EHR, billing, and infrastructure partners.
  • Incident response planning and staff training that reflects daily care operations.

Six Steps to Take Now

The organizations that start now will be in the strongest position when a final rule arrives. Use the delay to close the most common gaps before they become regulatory, operational, or reputational issues.

  1. Conduct or refresh your risk assessment. Document where ePHI lives, how it moves, which systems and vendors touch it, and which risks require mitigation.
  2. Implement MFA wherever ePHI can be accessed. Prioritize EHR access, email, remote access, VPNs, administrative consoles, and third-party platforms.
  3. Confirm encryption coverage. Validate that ePHI is encrypted at rest and in transit, especially across cloud systems, backups, file sharing, mobile devices, and vendor-supported environments.
  4. Build a testing cadence. Establish regular vulnerability scanning and annual penetration testing, then document findings, remediation plans, and completed fixes.
  5. Review business associate readiness. Identify all vendors that touch ePHI, confirm current agreement status, and create a repeatable process to verify security safeguards.
  6. Update and test your incident response plan. Define how your team will detect, contain, investigate, communicate, and recover from a security incident before one occurs.

Frequently Asked Questions

Has the HIPAA Security Rule been finalized?

No. As of July 2026, the proposed rule is still under review by HHS, with finalization targeted for July 2027. Until a final rule is published in the Federal Register, the current HIPAA Security Rule remains in effect. However, the proposed rule’s direction signals where OCR enforcement is headed, so organizations should treat it as planning input, not law, but plan accordingly.

Does the 240 day compliance timeline start immediately when the rule is finalized?

Yes. The timeline is fixed: 60 days for the rule to take effect, then 180 days to comply. There is no additional grace period beyond the 240 days. Business associate agreements receive a longer transition period (roughly one year from the effective date).

What is the biggest change in the proposed HIPAA Security Rule?

The shift from flexible, addressable safeguards to mandatory technical controls. The current rule allows organizations to decide whether specific security measures are reasonable and appropriate for their environment. The proposed rule eliminates that flexibility for critical controls like MFA and encryption, making them non negotiable.

Does this apply to small healthcare providers and care delivery organizations?

Yes. The proposed rule applies to any covered entity or business associate that creates, receives, maintains, or transmits ePHI, regardless of size. HHS explicitly declined to create a small healthcare provider and care delivery organization exemption. Small healthcare providers and care delivery organizations face the same requirements as large health systems within the same 240 day timeline.

What if my organization isn’t ready in 240 days?

OCR does not typically grant extensions. The compliance deadline is fixed. If you are not ready, you will be out of compliance and exposed to enforcement action. Starting now gives you 18+ months of preparation. Starting when the rule finalizes gives you less than one year, and you’ll be starting under pressure, often after you’ve experienced a breach.

Take the Next Step

The HIPAA Security Rule update may be delayed, but the need for stronger cybersecurity readiness is not. Healthcare organizations that use this time wisely can reduce risk, improve resilience, and enter the next regulatory phase with greater confidence.

DAS Health helps ambulatory care providers, senior living communities, and healthcare organizations assess current-state readiness, identify practical security gaps, and build a roadmap toward stronger HIPAA Security Rule preparedness.

Ready to Understand Where You Stand?

Start with a HIPAA Security Readiness Conversation. We will help you evaluate your current controls, prioritize the gaps that matter most, and identify a practical next step for your organization. Contact DAS Health today.