Last week, HHS quietly updated its Unified Agenda and pushed the final HIPAA Security Rule overhaul back to July 2027. If you weren't watching closely, you missed it. That's usually how these things go — the delays get buried, the breaches make headlines.
Here's the timeline, and it's worth sitting with:
- January 6, 2025 — OCR publishes the proposed overhaul, the first substantive rewrite of the Security Rule in over two decades.
- March 7, 2025 — Comment period closes. Nearly 5,000 responses, most of them industry pushback.
- May 2026 — The original target date for a final rule comes and goes. Nothing.
- July 2026 — The Unified Agenda quietly resets the target to July 2027. The rule's status has been downgraded from "final rule stage" to "long term actions."
Two and a half years from proposal to (maybe) final action, on a rule meant to close security gaps that have been public knowledge since the Bush administration.
The special interests won this round
In December 2025, a coalition led by CHIME — joined by the AMA, the American Academy of Pediatrics, Cleveland Clinic, Yale New Haven, Advocate Health, and dozens of state and specialty associations — sent HHS a letter asking that the rule be withdrawn outright. Their argument: too expensive, too burdensome, too disruptive to patient care.
I don't dismiss the cost argument reflexively. HHS itself estimated roughly $9 billion in year-one compliance costs, tapering to about $6 billion annually for years two through five. That's real money, and for under-resourced rural and safety-net systems, it's a legitimate operational concern that deserves a serious, risk-based phase-in — not a blanket "withdraw the rule" ask.
But weigh that $9 billion against what a single major breach costs the system — not just in remediation and regulatory exposure, but in stolen identities, corrupted clinical records, and patients who no longer trust the systems holding their data. Change Healthcare's 2024 breach alone has cost UnitedHealth Group more than $3.1 billion in direct response and business-disruption costs to date, on top of exposing roughly 190 million patients — one incident, at one company, approaching half the industry's entire year-one compliance bill. Anthem's 2015 breach, 78.8 million records, ran the company close to $260 million in notification, credit monitoring, remediation, and settlements — and that was a decade ago, before ransomware turned data theft into data extortion. Community Health Systems' 2014 breach of 6.1 million patient records was independently estimated at $75–100 million before the legal bills were even final. None of that counts the intangible cost: IBM's 2025 Cost of a Data Breach Report puts the average U.S. healthcare breach at $7.42 million, and healthcare has held the title of costliest breached industry for fourteen consecutive years running. Multiply that by the 772 large breaches OCR logged in 2025 alone and you're well past the NPRM's price tag — except that money gets spent reactively, breach by breach, instead of once, systematically, on controls that would have stopped most of it.
Meanwhile, 2025 was the worst year on record for large healthcare breaches — 772 reported to OCR, breaking the previous record of 746 set in 2023. Nearly 61 million patient records were exposed or stolen in that span alone. This isn't a hypothetical risk regulators are debating into 2027. It's happening now, at record pace, while the rule meant to address it sits in "long term actions."
The cost that doesn't show up on a balance sheet
Every dollar figure above is a proxy for something worse: when ransomware encrypts or corrupts a record, or an identity thief contaminates one, the clinician on the other end is making decisions on bad data. Ponemon Institute's 2025 Cyber Insecurity in Healthcare study — its fourth annual survey, 677 healthcare IT and security practitioners — found that 32% of organizations that suffered a cyberattack reported an increase in patient mortality rates as a result, up from 26% in 2024 and roughly 22% just three years earlier. That trend line is moving the wrong direction while the rulemaking clock resets.
Independent academic research points the same way, with more caution than a vendor-sponsored survey warrants. Researchers analyzing Medicare claims data found that in-hospital mortality for patients already admitted when a ransomware attack hit rose 34–38%, and estimated the disruption contributed to 42–67 additional Medicare patient deaths between 2016 and 2021. That's a working paper, not yet peer-reviewed, and limited to Medicare beneficiaries — I won't overstate it — but it's directionally consistent with what Ponemon's practitioners are reporting from inside their own organizations.
Named cases add faces to the numbers, with an honest caveat: causation is hard to prove and not every headline holds up. In July 2019, Springhill Medical Center in Mobile, Alabama was mid-ransomware-attack when a newborn suffered severe brain damage after fetal heart-rate monitoring failed during the systems outage; the child died months later, and the family's wrongful-death suit against the hospital was ultimately settled. By contrast, German prosecutors initially linked a 2020 ransomware-driven ambulance diversion at University Hospital Düsseldorf to a patient's death, then closed the negligent-homicide investigation after concluding her underlying condition — not the delay — was the actual cause. Both cases got the same breathless headline. Only one held up.
Then there's the harm that never makes headlines at all: contaminated charts. When a criminal uses stolen credentials to obtain care under someone else's identity, the impostor's blood type, allergies, and diagnoses get written into the real patient's permanent record — often invisibly, and permanently, unless someone catches it. Ponemon's medical identity theft research found that among victims, 15% reported a resulting misdiagnosis, 14% a treatment delay, 13% mistreatment, and 11% were prescribed the wrong medication because of it. Half of consumers surveyed had no idea their medical record could carry an error like that at all. Those numbers are a decade old, from Ponemon's fifth annual medical identity theft study, and medical record volumes stolen since then have grown by orders of magnitude — there's no reason to think the underlying rate has improved.
Weigh that against the CHIME coalition's ask to withdraw the rule outright. "Too expensive" is a defensible position when you're talking about the how and the when of implementation. It stops being defensible when the what includes mandatory encryption and the alternative is measurably worse patient safety outcomes.
"Addressable" was never supposed to mean optional
Here's the part that should bother every CISO and every board member in healthcare: as of today, encryption of ePHI is still an addressable implementation specification under the Security Rule — not a required one. That distinction, baked into the original 2003 rule, lets a covered entity document why encryption isn't "reasonable and appropriate" for them and implement something else instead. Two decades later, providers are still using that language to justify not encrypting data at rest or in transit.
The pending NPRM would fix exactly this — eliminating the required/addressable distinction and mandating encryption of ePHI at rest and in transit, with narrow exceptions. It is, frankly, one of the least controversial parts of the proposal. Encryption is table-stakes infrastructure in every other regulated data environment. That it remains optional in healthcare in 2026, while providers race to bolt AI onto the same unencrypted systems, is not a technology gap. It's a governance failure.
I've been making this argument for sixteen years, going back to when I founded Clear Data with the singular mission of protecting patient data in the cloud. I've also been on the other side of this problem — hacked at least eight times, personally and professionally. Voluntary security has had two decades to work. It hasn't.
Where this leaves healthcare leaders
Waiting for the mandate is not a strategy. Encryption at rest and in transit, real MFA, network segmentation, and documented recovery planning are controls every mature organization should have implemented regardless of what OCR finalizes or when. If your compliance posture depends on "addressable" meaning "optional," you are one breach notification letter away from finding out how that argument holds up with a plaintiff's attorney, a state AG, or your own board.
Regulators bought themselves another year. Patients didn't get one.