The Proposed HIPAA Security Rule: Get Ahead of It

If you run a medical practice, you have probably seen both headlines by now. One says the biggest HIPAA Security Rule overhaul in twenty years is coming with a hard deadline. The other says the whole thing may be withdrawn. Both are selling you something, and neither is quite the truth.

The truth is quieter: the rule is still proposed, its timeline just slipped by a year, and the safeguards it describes are worth having anyway. For a Santa Clarita Valley practice handling electronic protected health information, the right question is not when the rule lands. It is whether your environment would be ready on any date at all, and getting ahead of it before it gets ahead of you.

Overview

In January 2025, the federal government proposed the first major update to the HIPAA Security Rule since 2013. The proposal is sweeping: the old distinction between "required" and "addressable" safeguards would largely disappear, and controls that many offices have treated as optional would become obligations. Multi-factor authentication. Encryption of ePHI at rest and in transit. Network segmentation. A written inventory of every system that touches patient data. Restoration of critical systems on a defined clock after an incident. Regular technical testing, verified vendor safeguards, and more.

Then the timeline did what timelines do. The proposal drew more than 4,700 public comments. Over a hundred hospital systems and provider associations formally asked for it to be withdrawn or reworked, arguing that one set of requirements cannot fit both a hospital network and a three-provider office. The government's own spring 2026 finalization target came and went with nothing published, and the federal regulatory agenda now projects final action in mid-2027, a projection that is not binding and can move again. Meanwhile, the current Security Rule remains fully in force, and regulators keep enforcing it, with the missing security risk analysis still the deficiency they cite most often.

The Challenge

Picture a three-provider practice in Santa Clarita. The office manager's inbox has been collecting compliance-vendor emails for a year, several of them selling urgency against a May 2026 deadline that no longer exists. The practice's own reading turns up the opposite story: major health systems pushing back, the rule possibly shrinking or stalling. Faced with a loud "act now" and a plausible "maybe never," most busy practices land on the same default: wait and see.

Wait-and-see gets the situation exactly backwards. The parts of the proposal that are genuinely uncertain, like whether a small office will ever owe an annual penetration test, are the parts that matter least to a practice's actual safety. The parts that are effectively certain, that patient data should be encrypted, that logins should need more than a password, that backups should be tested and restorable, are already how regulators evaluate the current rule, already what cyber insurers require on their applications, and already the difference between a lost laptop being a non-event and a reportable breach. The deadline is uncertain. The direction has not wavered in years.

Why It Matters

The proposal deserves attention for what it reveals, not just what it requires:

"Addressable" was never "optional," and the proposal makes that explicit. Practices have long read the current rule's addressable safeguards as suggestions. They are not: the rule requires implementing them or documenting an equivalent, and for something like encryption there is no equivalent. The proposal would retire the misreading entirely by making the core safeguards plainly required.

Enforcement already points where the proposal points. Regulators investigating practices today, under the current rule, keep citing the same gaps: no current risk analysis, no encryption, weak access control. The proposal is less a new direction than the existing direction written down. A practice that closes those gaps is safer under the rule in force now, whatever happens in 2027.

Your insurer got there first. Cyber-insurance applications already ask about multi-factor authentication, encryption, and tested, isolated backups, and answering no is increasingly answering "decline to cover." For most practices the proposal's core is not a future obligation. It is a present-tense condition of being insurable.

Readiness is cheap on your schedule and expensive on a regulator's. If and when a final rule lands, every practice that waited enters the same compliance window at the same time, competing for the same help at scramble prices. The identical work, done calmly over months on your own calendar, costs less, disrupts nothing, and is simply good security in the meantime.

What Organizations Should Watch For

  • Deadlines that do not exist. Any pitch built on a hard compliance date is selling urgency, not accuracy. The spring 2026 target passed unmet; the current projection is mid-2027 and not binding. Check the date on everything you read about this rule, including this article, which is dated on this page.
  • "HIPAA certified" claims. There is no such thing as HIPAA certification, no government body issues one, and no vendor can certify your practice compliant. Anyone claiming otherwise has told you something important about their other claims.
  • Panic pricing. A risk analysis and remediation plan has a calm-market price. If a quote only makes sense under deadline pressure, the deadline is doing the selling.
  • Advice to wait. The opposite trap. The current rule is enforced today, and the risk analysis it already requires is the single item most practices are missing right now.
  • The contested edges dressed as certainties. Provisions like annual penetration testing for every covered entity are exactly what the industry pushback targets and the kind most likely to be scaled to entity size or softened. Plan on the durable core, not the edges still being argued.

Recommended Actions

  • Get a current, documented security risk analysis. Required under the rule in force today, the most-cited gap in enforcement today, and the foundation every other decision builds on. If your practice has never had one, this is the first move regardless of any rulemaking.
  • Inventory every system that touches ePHI. The EHR, the imaging systems, the shared front-desk machines, the connected devices nobody thinks of as computers. You cannot protect, encrypt, or segment what you have not counted, and the proposal would make the inventory a written obligation anyway.
  • Turn on multi-factor authentication everywhere that matters. Email, remote access, and anything privileged, at minimum. It is the control attackers work hardest to bypass because it works, and your insurer is already asking about it.
  • Encrypt data at rest and in transit, on your own schedule. An encrypted lost laptop is an inconvenience; an unencrypted one is a reportable breach. This single control changes what your worst ordinary day means.
  • Plan the segmentation. Patient data should not share a flat network with the waiting-room TV and the cameras. Separating them limits how far any single compromise can travel, and it is core managed IT work, not a research project.
  • Test the restore, not just the backup. The proposal talks about restoring critical systems within seventy-two hours. Whatever number a final rule lands on, find out what your restore actually takes now, while the answer is a planning fact instead of an emergency discovery.
  • Verify your vendors annually. Every business associate touching your ePHI should have a signed agreement and safeguards you have actually asked about. The proposal would formalize the verification; the diligence is worth it today.

The SecureLynx Perspective

Observe:

Watch the direction, not the date. Rulemaking timelines slip, targets pass, projections move, and a practice that plans against a date will be wrong twice: once when the date slips and once when it finally arrives. The direction, by contrast, has not moved in years. Enforcement, insurance, and the proposal all describe the same set of safeguards, and that convergence is the real signal in the noise.

Adapt:

Build to the durable core, honestly sized for your practice. A three-provider office does not need to over-build for contested provisions that may never apply to it, and it cannot afford to skip the fundamentals that apply to it already. The adaptation is calm sequencing: risk analysis first, then the inventory, then the controls it says you are missing, each on your schedule instead of a regulator's.

Protect:

A practice that does this work is protected four ways at once: compliant with the rule in force now, ready for whatever version finalizes, insurable on its next renewal, and never part of the scramble when the compliance window opens. If you want to know where your practice actually stands, start with the assessment. If the rule lands in 2027, you will already be there. If it never lands, you will have lost nothing but your exposure.

Common questions

Is the new HIPAA Security Rule final? When does it take effect?

No. It is still a proposed rule. The proposal was published in January 2025, drew more than 4,700 public comments, and the government's own spring 2026 finalization target passed with nothing published; the federal regulatory agenda now projects final action in mid-2027, and those projections are not binding and can move again. More than a hundred hospital systems and provider associations have asked for the proposal to be withdrawn or reworked, so its final shape is genuinely uncertain. What is certain is that the current Security Rule is in force and enforced today.

Should our practice wait until the rule is final before doing anything?

Waiting is the one clearly wrong answer, for reasons that have nothing to do with the new rule. The current rule already requires a documented security risk analysis, and the missing risk analysis is the deficiency regulators cite most often in investigations today. Cyber insurers already condition coverage on multi-factor authentication, encryption, and tested backups. The core of the proposal simply describes what reasonable security looks like right now, so the work is worth doing on your own calm schedule whether the rule lands in 2027, later, or never.

Will a small practice really need everything proposed, like annual penetration testing?

Possibly not. The loudest criticism of the proposal is that it applies one set of requirements to everyone, from hospital systems to three-provider offices, and provisions like annual penetration testing are the kind most likely to be scaled to entity size or softened before anything finalizes. The honest way to plan is to build the durable core, the risk analysis, multi-factor authentication, encryption, an asset inventory, and tested restores, and let the contested edges settle in the rulemaking where they belong.