HIPAA 2026 Security Rule Changes: What Healthcare Organizations Need to Know
OCR's proposed HIPAA Security Rule overhaul targets May 2026. All safeguards would become mandatory; encryption and MFA would be required. Here's what's changing and how to prepare.
What Are the Proposed HIPAA 2026 Security Rule Changes?
The HIPAA Security Rule is facing its most significant proposed overhaul since 2013. On December 27, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) to strengthen cybersecurity protections for electronic protected health information (ePHI), published in the Federal Register on January 6, 2025 (90 FR 898). OCR's regulatory agenda targets finalization around May 2026 — though that timeline may shift.
Important: Proposed Rule — Not Yet Final
The proposed rule is not yet final. The current HIPAA Security Rule remains in effect while rulemaking is underway. But the direction of these changes is clear enough that healthcare organizations should be preparing now. This article summarizes a proposed rule and should not be interpreted as current regulatory requirements.
What Is Changing in the Proposed HIPAA Security Rule?
The NPRM represents a fundamental shift in how HIPAA treats cybersecurity requirements. The proposed 2026 rule changes respond to a threat environment that has shifted faster than compliance frameworks can — some frontier AI models have now demonstrated autonomous vulnerability-discovery capabilities, a capability class that shifts how security leaders must think about vulnerability management and defense-in-depth. Here are the most consequential proposed changes.
"Addressable" Safeguards Going Away
Under the current rule, many security measures are classified as "addressable" — meaning organizations must implement them if reasonable and appropriate, or document an equivalent alternative. In practice, some entities have treated "addressable" as "optional." The proposed rule would eliminate this distinction and require implementation of security specifications, subject to defined exceptions and documented alternatives in limited cases.
Encryption of ePHI Required in Most Cases
The NPRM proposes that encryption must meet "prevailing cryptographic standards" for ePHI at rest and in transit, subject to defined exceptions and documentation requirements. Organizations that have relied on the current rule's flexibility around encryption would need to close this gap. The NPRM intentionally does not codify specific algorithms or protocol versions — the standard is designed to evolve with the technology landscape.
Multi-Factor Authentication Across Relevant Systems
MFA would need to be deployed across technology assets in "relevant electronic information systems" for authentication, including for privileged actions. The NPRM includes defined exceptions — for example, legacy assets that cannot support MFA may be exempt with a written migration plan and compensating controls.
72-Hour System Restoration for Critical Systems
Organizations would need to establish procedures to restore critical relevant electronic information systems and data within 72 hours of loss — whether from a ransomware attack, hardware failure, or natural disaster. Other systems would follow a criticality-based restoration timeline. This requires documented and tested contingency plans, not just policies on paper.
24-Hour Contingency-Plan Activation Notice
Business associate agreements would need to require BAs to notify covered entities within 24 hours of activating their contingency plan. This is a contractual requirement in BA agreements — OCR has stated it would not change existing breach notification obligations under the Breach Notification Rule.
Prescriptive Security Testing Cadences
The NPRM proposes minimum vulnerability scanning every six months and penetration testing at least annually by a "qualified person," or more frequently based on risk analysis. The proposal also includes defined patch management timeframes — 15 days for critical risks and 30 days for high risks where patches are available.
Technology Asset Inventories and Network Maps
Every covered entity and business associate would need to maintain a current, written inventory of all technology assets and a network map showing how ePHI flows through their environment, reviewed and updated at least annually.
What's the Expected Timeline?
OCR's regulatory agenda lists a target finalization date of May 2026, though this is a planning estimate and may change. If finalized, the proposed timeline works as follows:
Effective Date
60 days
after final rule publication
Compliance Date
180 days
after effective date
Total Window
~240 days
from publication
If finalization happens as targeted, organizations would need to achieve compliance by approximately early 2027. The NPRM also proposes transition provisions for certain existing business associate agreements. For organizations that have not yet invested heavily in cybersecurity infrastructure, that timeline is tight.
What Does This Mean for Your Organization?
HHS estimates first-year compliance costs at approximately $9 billion across the healthcare industry, with roughly $6 billion annually thereafter (per the NPRM's economic analysis — these estimates may change in the final rule). For individual organizations, the impact depends entirely on your current security posture. Telehealth providers face particular pressure: the proposed changes would apply to workflows that expanded rapidly during the PHE, and many of these providers are still working through the compliance gap that remained after OCR's telehealth enforcement discretion expired and the transition period closed.
Mature Security Program
You may find that many proposed requirements align with what you're already doing. The shift from "addressable" to "required" may simply formalize existing practices.
Gaps in Current Safeguards
If your organization has treated certain safeguards as optional, the gap could be significant. Implementing encryption, deploying MFA broadly, and establishing 72-hour restoration takes time, budget, and expertise.
Business Associates
Pay close attention to the contingency-plan activation notice requirement and expanded security obligations. The proposed rule applies equally to BAs and covered entities.
How Healthcare Organizations Should Prepare Now
The final rule may look different from the NPRM, but the direction is clear. Organizations that wait for finalization to begin preparing will face a compressed timeline.
Conduct a Comprehensive Security Risk Assessment
If you haven't done one recently, or if your last assessment didn't inventory all technology assets and map ePHI data flows, now is the time. The proposed rule would make these foundational activities explicit requirements.
Evaluate Your Encryption Posture
Identify where ePHI is stored and transmitted without encryption. Prioritize closing those gaps, especially for data at rest — this is where many organizations have the largest exposure.
Deploy Multi-Factor Authentication
If MFA isn't standard for users with ePHI access, build a deployment plan. Include vendor and remote access in your scope. Identify any legacy systems that would need migration plans.
Test Your Recovery Capabilities
Can you actually restore critical systems within 72 hours? Run a tabletop exercise or partial failover test. Document the results and identify gaps.
Establish Vulnerability Scanning and Pen Testing Cadences
The proposed rule would require scanning every six months and pen testing annually. If you don't have a regular program, start building one now.
Review Business Associate Agreements
Ensure your BAAs can accommodate the proposed 24-hour contingency-plan activation notice requirement and the expanded security obligations.
Where a Virtual CISO Fits In
Many healthcare organizations — particularly those without a dedicated security executive — find the scope of regulatory changes like this difficult to navigate internally. A virtual CISO (vCISO) provides the strategic security leadership needed to interpret evolving regulations, assess organizational readiness, and prioritize remediation — without the cost of a full-time hire.
At Cloud Solutions Consulting, our vCISO services help healthcare organizations understand where they stand against current and proposed HIPAA requirements. We start with a comprehensive cybersecurity risk assessment that evaluates your security posture, identifies compliance gaps, and produces a prioritized remediation roadmap.
Assess where your organization stands today with our free HIPAA Security Rule Readiness Checklist — an interactive self-assessment covering current requirements and proposed NPRM items.
Key Takeaways
OCR has proposed the most significant HIPAA Security Rule overhaul since 2013 (90 FR 898). The rule is not yet final — the current Security Rule remains in effect.
The proposal would eliminate the "addressable" vs. "required" distinction, requiring implementation of security specifications subject to defined exceptions.
Encryption meeting "prevailing cryptographic standards" and MFA across relevant electronic information systems would become required (with limited exceptions).
72-hour critical system restoration and 24-hour BA contingency-plan activation notice would create new operational obligations.
Semiannual vulnerability scanning and annual penetration testing would be minimum mandated cadences.
OCR's regulatory agenda targets May 2026 finalization, with a proposed ~240-day compliance window from publication.
Organizations should begin gap assessments now rather than waiting for the final rule.
Frequently Asked Questions
No. The proposed rule (NPRM, 90 FR 898) was issued December 27, 2024 and published in the Federal Register on January 6, 2025. OCR's regulatory agenda targets finalization around May 2026, but that timeline may shift. The current HIPAA Security Rule remains in effect while rulemaking is underway.
If finalized as proposed, the effective date would be 60 days after publication of the final rule, with a compliance date 180 days after the effective date — approximately 240 days from publication. If finalization happens around May 2026, organizations would need to achieve compliance by approximately early 2027.
Yes. The NPRM proposes eliminating the distinction between "addressable" and "required" implementation specifications. All security specifications would require implementation, subject to defined exceptions and documented alternatives in limited cases.
The NPRM proposes that encryption must meet "prevailing cryptographic standards" for ePHI at rest and in transit. The rule intentionally does not codify specific algorithms or protocol versions — the standard is designed to evolve with the technology landscape. Defined exceptions and documentation requirements apply.
A virtual CISO (vCISO) provides the strategic security leadership needed to interpret evolving HIPAA regulations, assess organizational readiness, and prioritize remediation — without the cost of a full-time hire. This is particularly valuable for small and mid-sized healthcare organizations that need expert guidance through the compliance process.
Need HIPAA Security Leadership?
A healthcare vCISO supports your designated HIPAA security official with risk assessment leadership, policy development, and audit response preparation.
Healthcare vCISO Services