The HIPAA Security Rule update is still a proposal, not a rule, and the date for finalising it has slipped from May 2026 to July 2027. That is the news. The rest is that the proposal has not changed, the breach figures that produced it have got worse, and every item in it is something a Michigan practice can do this quarter without waiting for the Federal Register. This post lists what the proposed rule would require, what the numbers behind it say, and the order to do it in for a practice with one office manager and no IT department.
In short
- Proposed rule published January 6, 2025; comments closed March 7, 2025. The final rule's target on the federal regulatory agenda is now July 2027, per HIPAA Journal.
- 804 large healthcare breaches were reported to HHS in 2025, up from 738 in 2024, affecting about 138.5 million people. Hacking accounted for more than 80% of them.
- The proposal makes multifactor authentication, encryption at rest and in transit, six-monthly vulnerability scans, annual penetration tests and 72-hour restoration mandatory for every covered entity, with no small-practice exemption.
- In 2022, 55% of OCR's financial penalties fell on small medical practices, per HIPAA Journal.

Where the rule stands in September 2026
The Department of Health and Human Services published the proposed Security Rule in the Federal Register on January 6, 2025. It was the first substantive rewrite since 2013, and the comment period closed on March 7, 2025 with more than 4,000 comments filed. Under the old timetable a final rule could have appeared by May 2026. It did not. HIPAA Journal reported in 2026 that the Office of Management and Budget's regulatory agenda now lists July 2027 for the final rule. Nothing in the current Security Rule changed in the meantime, and it is still enforced.
Two ways to read the delay. One is that a practice has two more years. The other is that the practice has two more years of the current rule, under which the same breaches keep happening and the same penalties keep landing, and that the proposal is a published list of what HHS thinks a compliant practice looks like. The second reading is the useful one.
What the proposed Security Rule requires
The proposal's central move is to remove the distinction between "required" and "addressable" implementation specifications. Under the current rule a practice can document why an addressable safeguard, encryption being the famous one, was not reasonable for it. Under the proposal there is no addressable category. Everything is required, with narrow exceptions. The specific additions, from the HHS fact sheet and the Federal Register text:
| Requirement | Proposed standard |
|---|---|
| Written policies and procedures | All Security Rule policies documented and reviewed |
| Technology asset inventory and network map | Written, showing where ePHI moves, updated at least every 12 months |
| Risk analysis | Written, with specific required elements, updated at least every 12 months |
| Multifactor authentication | Required on systems holding ePHI, with limited legacy and emergency exceptions |
| Encryption | Required for ePHI at rest and in transit |
| Vulnerability scanning | At least every 6 months |
| Penetration testing | At least every 12 months |
| Restoration of critical systems | Within 72 hours of a loss |
| Workforce access changes | Relevant parties notified within 24 hours of a change or termination |
| Compliance audit | At least every 12 months |
| Business associate safeguards | Written verification by a qualified person at least every 12 months |
None of that is exotic for a health system. For a three-provider dental office in Livonia, the asset inventory alone is a day's work nobody has scheduled.
Why the numbers make waiting expensive

HIPAA Journal's running tally of breaches reported to HHS counts 804 large breaches, those affecting 500 or more people, in 2025, up from 738 in 2024. About 138.5 million people were affected in 2025. Hacking and other IT incidents accounted for more than 80% of the large breaches that year. In its own proposal HHS cited a survey in which 92% of healthcare organisations reported a cyberattack in the previous year, and nearly three quarters of those said it affected patient care.
The enforcement side is the part small practices tend not to hear. HIPAA Journal's analysis of OCR penalties found that in 2022, 55% of the financial penalties were imposed on small medical practices, not on hospitals. The practice that assumes it is too small to be a target is the practice that is easiest to breach and simplest to fine, and the proposed rule's removal of the addressable category takes away the paragraph that used to explain why encryption had not been switched on.
What to do this quarter, in order

- Write the asset inventory. Every device, application and service that stores, sends or can reach patient information: the practice management system, the imaging software, the laptop the bookkeeper uses at home, the phone system, the text reminder service, the cloud backup. One row each, with who runs it and where the data sits. This is the proposed rule's network map, and it is the document every other step reads from.
- Turn on multifactor authentication everywhere the inventory allows. The practice management system, email, the remote access tool, the backup console. Where a system cannot do it, write down that it cannot; that is the exception the proposal allows, and it is only an exception if it is written.
- Encrypt the two things that get lost. Laptops and phones. Full-disk encryption is a setting on every current operating system, and a stolen encrypted laptop is a stolen laptop rather than a reportable breach.
- Test a restore. The proposal says critical systems back within 72 hours. Ask the backup vendor to restore last Tuesday's schedule to a test machine and time it. A backup that has never been restored is a hope.
- Collect the business associate agreements. Every vendor in the inventory that touches patient information needs one, and the proposal wants written verification of their safeguards every year. That includes the answering service, the reminder platform and any AI tool that reads a call or an intake form.
- Put the access-change step in the offboarding checklist. When a staff member leaves, the accounts are closed the same day and the closure is written down. The proposal's 24-hour window is the standard; the practice that does it in an hour is the one with a checklist.
The mistake most practices make at step 5
They treat the business associate agreement as the vendor's paperwork and sign whatever arrives, or nothing at all. Under both the current rule and the proposal, the covered entity is responsible for choosing vendors that safeguard the data, and the proposal adds an annual written check that they actually do. A practice adding an AI front desk or automated reminders is adding a business associate, and the question to ask before the pilot is not whether the vendor is HIPAA compliant, a phrase with no legal meaning, but whether they will sign the agreement, where the recordings live, and how long they keep them.
The second mistake is doing the risk analysis last, as a document to have. The proposal wants it first, written, with specific elements, and refreshed yearly. Done from the inventory in step 1, it is an afternoon. Done from memory, it is the finding in the audit.
What the delay is for
A rule targeted for July 2027 will, if it holds, apply in 2028 to practices whose inventories, authentication, encryption and backups were built years earlier. The proposal is the clearest statement HHS has yet published of what it will expect, and the practice that works through the six steps above this quarter meets the current rule better, meets the proposed one in advance, and stops being the easy target the breach numbers describe. Start with the inventory. It is one spreadsheet, and every other step is a column in it.