← Back to Blog

The HIPAA Security Rule Overhaul Just Slipped to 2027. Here's What That Actually Changes

A Deadline Everyone Was Planning Around Just Moved

If you have attended a compliance webinar in the last eighteen months, you have heard some version of this: the HIPAA Security Rule is being rewritten for the first time since 2003, encryption and multi-factor authentication are becoming mandatory, and you need to be ready this year. That advice was reasonable when it was given. It is now out of date in one important respect.

The proposed rule — published in the Federal Register in January 2025 — is still a proposal. The comment period closed in March 2025. The Office for Civil Rights has not issued a final rule, and the federal government's own Unified Agenda, which tracks where every pending regulation stands, now points to 2027 for final action rather than the spring 2026 target it carried earlier. If you built a compliance calendar around "the new Security Rule takes effect in 2026," that calendar is wrong.

Why It Slipped

Two reasons, and both matter for predicting what comes next.

The first is volume. OCR received roughly 4,745 public comments on the proposal. Every substantive comment has to be read, categorized, and addressed in the preamble of the final rule — that is not a formality, it is how a rule survives legal challenge. A comment file that size is a multi-year project on its own.

The second is opposition, and it is unusually broad. More than 100 hospital systems and provider associations formally asked the Department to withdraw the proposal outright — not amend it, withdraw it. Their argument is essentially about cost and feasibility: that mandating specific technical controls across organizations ranging from two-provider rural clinics to academic medical centers ignores how differently those organizations are resourced. Whether or not you find that persuasive, opposition at that scale usually produces either a significantly softened final rule or a much longer runway. Sometimes both.

What the Delay Does Not Change

Here is where practices make an expensive mistake. A delayed rule is not a cancelled expectation, because the things the proposal would require are mostly things OCR already treats as reasonable practice under the existing rule.

The current Security Rule, written in 2003, already requires you to implement encryption and other safeguards or document why you reasonably chose not to. That second half is the part practices skip. The proposal would remove the choice; today you still have it, but you have to justify it in writing, and "we never got around to it" has never been a justification. Read OCR's recent enforcement actions and you will notice the agency citing organizations for missing controls the proposal would mandate — under the rule as it exists right now. The enforcement posture has effectively moved ahead of the regulation.

So the honest framing is this: the deadline moved, the direction did not. An organization that uses the extra time to implement encryption, multi-factor authentication, and a current asset inventory will be ready whenever the rule lands and will be defensible in the meantime. An organization that treats the delay as permission to wait will be exposed on both counts.

What to Do With an Extra Year

A longer runway is genuinely useful if you spend it. Here is where the time goes furthest, in order:

  • Build the asset inventory first. Almost every other requirement depends on knowing what you have. You cannot encrypt, patch, or segment systems you have not enumerated. This is also the single most common gap we see, and it is the cheapest one to close.
  • Turn on multi-factor authentication everywhere it is exposed. Remote access, email, and your EHR, at minimum. Not all MFA is equal — see our breakdown of phishing-resistant authentication before you pick a method.
  • Encrypt what leaves the building. Laptops, backups, portable media, and anything synced to a phone. Lost-device breaches are still a meaningful share of reported incidents, and an encrypted lost laptop is generally not a reportable breach at all.
  • Refresh the risk analysis, and act on it. A current risk analysis is already required. As we cover in the signs your risk assessment is worthless, most of the ones we see fail because nothing happened afterward.
  • Tighten business associate oversight. The proposal would require more of you here, and the breach data already does. More on that below.

The Trap: Vendors Selling a Deadline That Moved

Expect to keep hearing "the 2026 Security Rule" in sales material for a while, because urgency sells and updating marketing copy is nobody's priority. When a vendor tells you a federal deadline is forcing a purchase, ask them one question: what is the citation, and what is the compliance date? A real deadline has both. If the answer is vague, you are being sold a timeline rather than a control.

The reverse trap is just as costly. Some practices will read "delayed to 2027" and close the file for a year. The organizations OCR has penalized recently were not penalized for missing a future rule — they were penalized under the rule that has been in force since 2003.

Where This Leaves You

Treat the proposed rule as a published statement of what the regulator considers adequate security in 2026, because functionally that is what it is. You now have more time to get there, and less excuse for not starting. The controls are the same either way; only the enforcement date is uncertain, and betting on a slow regulator has never been a durable compliance strategy.

Related Reading

Call to Action

Want to know which of the proposed requirements you would already pass today? Take the 3-minute readiness quiz for a plain-language answer, or schedule a walkthrough to see how risk analysis, asset inventory, policies, and training stay current in one place — whatever year the rule finally lands.

Ready to simplify your HIPAA compliance?

See how HIPAA Security Suite can protect your organization.

Request a Demo