What the Proposed HIPAA Security Rule Actually Requires, and Why July 2027 Is Not as Far Away as It Sounds
The proposed HIPAA Security Rule update is currently targeted for final action in July 2027. On paper, that sounds like breathing room. It is not.
The Office for Civil Rights (OCR) is already enforcing the current HIPAA Security Rule, while the Office of Management and Budget (OMB) Unified Agenda lists July 2027 as the target for final action on the proposed update. That date is not legally binding and could shift again. The proposed rule is not yet enforceable, but many of the security weaknesses it addresses, including inadequate risk analysis, access control gaps, and insufficient recovery planning, are already central to OCR investigations and settlements.
Here is what the proposed rule actually requires, why it matters, and what healthcare providers and care delivery organizations should be doing right now.
Why This Rule Update Is Different From Every Other Compliance Update
The HIPAA Security Rule has not had a substantive update since 2013. In the thirteen years since, healthcare has lived through the normalization of ransomware as a service, mass migration to cloud infrastructure, the expansion of connected medical devices, and major healthcare breaches that exposed the operational consequences of weak identity and access controls.
The original HIPAA Security Rule was written for a different technology environment. It predates widespread cloud computing, telehealth at today’s scale, ransomware as a business model, and the current volume of connected medical devices. The gap between the rule’s language and modern healthcare IT reality has been widening for years.
The proposed update closes that gap. It is more specific, technical, and prescriptive. For organizations that have relied heavily on the addressable specification framework for flexibility, the changes are significant.
The End of Required vs. Addressable
The most structurally consequential change in the proposed rule is the elimination of the distinction between required and addressable implementation specifications.
The Notice of Proposed Rulemaking would make almost all implementation specifications required, with specific limited exceptions. Under the current framework, organizations can document why an addressable safeguard is not reasonable and appropriate and implement an equivalent alternative when appropriate. The proposed rule substantially reduces that flexibility for many critical safeguards.
For organizations that have been managing compliance by documenting exceptions rather than implementing controls, this change would require a fundamental shift in approach.
The Five Controls That Matter Most
1. Encryption of ePHI at Rest and in Transit
The proposed rule would require encryption of electronic protected health information both at rest and in transit, with limited exceptions. Organizations should pay particular attention to backups, legacy databases, archived records, removable media, and older systems where unencrypted ePHI may still exist.
2. Multi Factor Authentication for ePHI Access
The proposed rule would require multi factor authentication for access to systems containing ePHI, with limited exceptions. This reaches beyond remote access portals and VPN connections and would require organizations to evaluate internal systems, EHR access, clinical applications, administrative tools, and other access paths.
3. Automated Vulnerability Scanning Every Six Months
Automated vulnerability scanning would be required at least every six months. Results should not simply be filed away. Organizations need a repeatable process to review findings, prioritize them based on risk, assign remediation ownership, and document completion.
4. Annual Penetration Testing
The proposed rule would require penetration testing at least once every twelve months. A penetration test differs from a vulnerability scan because it uses controlled attacker techniques to test whether weaknesses can actually be exploited in the environment.
5. Demonstrated 72 Hour System Restoration
The proposed rule would require written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours. A recovery plan that exists only on paper is not enough. Healthcare providers and care delivery organizations need tested, documented, and repeatable recovery capabilities.
What the Office for Civil Rights (OCR) Is Doing Right Now
It is important to be clear about the current regulatory environment. The proposed HIPAA Security Rule has not been finalized, so the Office for Civil Rights (OCR) is not yet enforcing the proposed requirements. The current HIPAA Security Rule remains in effect.
OCR has continued to use investigations and settlements to highlight common compliance failures, particularly inadequate risk analysis and weaknesses in security controls. Many of the areas emphasized in the proposed rule overlap with the risks OCR already expects regulated entities to identify and manage under the current rule.
Healthcare providers and care delivery organizations that wait for finalization before addressing known gaps in encryption, multi factor authentication, vulnerability management, recovery, and access controls are not standing still. They are carrying risk under the requirements that already exist.
The 240 Day Math Every Healthcare Leader Needs to Understand
Under the proposal, the final rule would generally become effective 60 days after publication, followed by a 180 day compliance period. That creates roughly 240 days from publication to the general compliance deadline if the final rule keeps the proposed timing.
For an organization that has already completed a gap assessment, identified its highest priority control gaps, and begun building a remediation roadmap, that window is much more manageable. The finalization date becomes a milestone rather than a starting gun.
For an organization starting from zero, the same window can create immediate pressure. A thorough gap assessment takes time. Remediation across encryption, multi factor authentication, vulnerability management, recovery, and vendor oversight can take months. Starting early allows technical, policy, budget, and vendor decisions to be made deliberately instead of under deadline pressure.
Know Where ePHI Lives Before You Try to Protect It
One of the most overlooked challenges in HIPAA compliance is understanding exactly where electronic protected health information exists throughout the organization. Most healthcare providers and care delivery organizations can identify their EHR platform. Far fewer maintain a complete inventory of every system, application, database, device, file share, cloud service, backup repository, and vendor connection that stores, processes, or transmits ePHI.
That visibility becomes increasingly important under the proposed rule. Organizations cannot confidently encrypt data, implement access controls, validate multi factor authentication coverage, or manage third party risk if they do not know where sensitive information resides.
A comprehensive ePHI inventory should document:
• Systems that create, receive, maintain, or transmit ePHI
• Network locations where ePHI is stored
• Data flows between applications, vendors, and business associates
• Cloud platforms and hosted environments
• Backup and disaster recovery repositories
• Connected medical devices and operational technologies
Healthcare providers and care delivery organizations should also develop data flow maps showing how ePHI moves through their environment. These maps frequently uncover forgotten systems, legacy applications, unsupported integrations, and vendor dependencies that create security and compliance risk.
Before addressing any technical control requirement, leadership should be able to answer a simple question: Can we clearly identify every location where ePHI exists and every path it takes across our network? If the answer is unclear, that is where a meaningful HIPAA readiness effort should begin.
In HIPAA readiness engagements, DAS Health frequently finds organizations that have strong security technologies in place but lack a complete inventory of ePHI assets and data flows. Establishing that visibility often becomes the foundation for remediation planning, risk analysis, and long term compliance.
What Healthcare Leaders Should Prioritize in the Next 90 Days
Healthcare leaders do not need to wait for a final rule to make meaningful progress. The next quarter can be used to establish visibility, validate foundational controls, and identify the gaps most likely to create security or compliance risk.
1. Inventory systems storing or transmitting ePHI.
2. Identify where multi factor authentication is not deployed.
3. Review backup recovery testing results and confirm critical systems can be restored.
4. Validate vendor security oversight processes and confirm responsibilities are documented.
5. Complete a HIPAA focused security gap assessment and prioritize remediation based on risk.
Vendor Accountability Is Not Optional
Vendor accountability is increasingly important given the role third parties play in healthcare data breaches and operational disruption. The proposed rule would increase expectations for business associates and subcontractors that handle ePHI, including annual verification of certain technical safeguards.
Most healthcare providers and care delivery organizations have Business Associate Agreements in place. Far fewer have a mature process for validating whether vendors are actually implementing the controls those agreements require.
Organizations should maintain a current inventory of business associates, evaluate security questionnaires at least annually, and document remediation plans for identified vendor risks. Leadership should also know which vendors are critical to clinical operations, revenue cycle, communications, and recovery so third party dependencies are visible before an incident occurs.
A strong internal security program does not eliminate third party risk. Vendor oversight has to be part of the broader HIPAA risk management process.
What to Do Before July 2027
The most important step a healthcare provider or care delivery organization can take today is a structured gap assessment mapped against the current HIPAA Security Rule and the direction of the proposed requirements. This should not be a general security review. It should identify where the environment stands today, which gaps create the greatest risk, and what remediation should happen first.
Organizations that begin now have time to implement changes thoughtfully, test recovery capabilities, build documentation that can support an audit or investigation, and strengthen vendor oversight before a new compliance clock begins.
The July 2027 date in the OMB Unified Agenda is a planning target for final action, not a guaranteed deadline. The controls emphasized in the proposed rule, however, address security problems healthcare organizations are already facing today.
We will help you evaluate your current controls, prioritize the gaps that matter most, and identify a practical next step for your organization. Contact DAS Health today.
Q & A
When is the proposed HIPAA Security Rule expected to be finalized?
The Office of Management and Budget (OMB) Unified Agenda currently lists July 2027 as the target for final action. That is a planning target rather than a legally binding deadline, so it may change. The current HIPAA Security Rule remains in effect until a final rule is published and reaches its applicable compliance date.
What are the biggest changes in the proposed HIPAA Security Rule?
The proposed rule would make security requirements more specific and prescriptive. Key changes include eliminating most addressable specifications, requiring encryption of ePHI at rest and in transit with limited exceptions, expanding multi factor authentication, requiring vulnerability scanning at least every six months, requiring annual penetration testing, strengthening asset inventory and network mapping requirements, and requiring written procedures to restore certain critical systems and data within 72 hours.
What happens to the required versus addressable distinction under the proposed HIPAA rule?
The proposed rule removes the long standing distinction between required and addressable safeguards for almost all implementation specifications. Healthcare providers and care delivery organizations would have less flexibility to rely on documentation alone when the proposed rule makes a safeguard mandatory.
Will encryption of ePHI be required under the proposed HIPAA Security Rule?
The proposed rule would require encryption of electronic protected health information both at rest and in transit, with limited exceptions. Organizations should pay particular attention to backups, legacy databases, archived records, removable media, and older systems where unencrypted ePHI may still exist.
Will multi factor authentication be required for systems that access ePHI?
The proposed rule would require multi factor authentication, with limited exceptions. Healthcare providers and care delivery organizations should evaluate EHR access, administrative tools, internal applications, remote access, and other pathways to systems containing ePHI.
How often would healthcare organizations need to run vulnerability scans?
The proposed rule calls for vulnerability scanning at least every six months. Findings should be documented, reviewed, prioritized by risk, and tracked through remediation.
Would annual penetration testing become a HIPAA compliance requirement?
The proposed rule would require penetration testing at least once every twelve months. A penetration test uses controlled attacker techniques to determine whether weaknesses can actually be exploited.
What is the proposed 72 hour restoration requirement?
The proposed rule would require written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours. Organizations should be able to demonstrate that recovery procedures are tested, documented, and repeatable.
How much time would organizations have to comply after the final rule is published?
Under the proposal, the rule would generally become effective 60 days after publication, followed by a 180 day compliance period. If that timing remains in the final rule, the general compliance deadline would be roughly 240 days after publication.
How does the proposed rule affect business associates and vendor risk?
The proposed rule would increase accountability for business associates that handle ePHI. Healthcare providers and care delivery organizations should maintain a current business associate inventory, review vendor security information regularly, document identified risks, and track remediation rather than relying only on signed agreements.
What should healthcare organizations do now to prepare for the proposed HIPAA Security Rule?
Start with visibility. Inventory systems and data flows involving ePHI, identify gaps in multi factor authentication and encryption, review recovery testing, assess vendor oversight, and complete a HIPAA focused security gap assessment that converts findings into a prioritized remediation roadmap.
Ready to Understand Where You Stand?
Start with a HIPAA Security Readiness Conversation. We will help you evaluate your current controls, prioritize the gaps that matter most, and identify a practical next step for your organization. Contact DAS Health today.