On April 23, 2026, the HHS Office for Civil Rights announced four HIPAA settlements in a single day: Assured Imaging, Regional Women's Health Group, Star Group's health benefit plan, and Consociate Health.

Read past the headline number and the pattern is the story. Unencrypted databases and backups. Internet-facing systems that hadn't been patched. No multifactor authentication on remote access. No network segmentation to stop an intruder from moving laterally once they were in. OCR did not discover a new category of failure. It documented the same handful of gaps regulators and the industry's own guidance have been naming for five years.

That is the context worth holding onto now that HHS has pushed final action on the Security Rule update from its original May 2026 target to July 2027. A lot of covered entities are reading that delay as a reprieve, a longer runway before anything changes. It is the wrong read. What moved is the date a specific set of controls becomes a codified rule violation. What did not move is the standard OCR is already enforcing today, settlement by settlement, under the risk analysis and risk management requirements that have been in force since 2013.

The Advisory Chain Has Been Running Since 2021

HHS did not spring multifactor authentication and encryption on the industry in a January 2025 proposed rule. It has been building the record for this for half a decade.

Section 13412 of the HITECH Act, added by Congress effective January 5, 2021, told HHS that when it calculates penalties, scopes an audit, or negotiates a corrective action plan, it must consider whether a covered entity had "recognized security practices" in place for the preceding twelve months, meaning the NIST Cybersecurity Framework or the approaches published under Section 405(d) of the Cybersecurity Act of 2015. OCR followed in April 2022 with a formal Request for Information asking the industry, in effect, whether it had implemented what the law was now incentivizing.

Then came the HHS Healthcare Sector Cybersecurity Performance Goals, published as a concept paper in December 2023 and finalized in January 2024. HHS named ten essential goals and called them voluntary. The list: mitigating known vulnerabilities, email security, multifactor authentication, basic workforce training, strong encryption, revoking credentials for departing staff, incident planning, unique credentials, separating user and privileged accounts, and vendor cybersecurity requirements.

Set that list next to the mandatory controls in the January 2025 Notice of Proposed Rulemaking and the overlap is close to total. Encryption at rest and in transit. Multifactor authentication for every system touching ePHI. Annual risk analyses instead of the ambiguous "periodic" standard. Vulnerability scans, penetration testing, network segmentation, a current technology asset inventory. The NPRM did not invent a new bar. It proposed making the bar HHS already published, mandatory, and it removed the "addressable" label that let organizations treat these controls as optional.

Addressable Was Never A Synonym For Optional

That distinction matters, and it's worth being precise about it, because I still hear it argued the other way. Encryption has been an addressable implementation specification under the Security Rule since 2013. Addressable never meant discretionary. It meant an organization had to implement the control, implement an equivalent alternative, or document a genuine, risk-based reason it wasn't necessary. "We hadn't gotten to it yet" was never that reason, and the April 2026 settlements confirm OCR has never treated it as one.

What The Delay Bought You

Two more years before an unmet control becomes a Security Rule violation on its own, rather than evidence supporting a risk analysis violation OCR can already cite. That's the whole difference. Compliance teams treating this timeline as room to plan a control rollout for 2027 are conflating a rulemaking calendar with a risk calendar, and ransomware actors are not on the rulemaking calendar. Healthcare breaches remain the costliest of any industry IBM tracks, at $7.42 million on average in 2025, and OCR logged 710 large breaches last year alone.

If you're a healthcare CISO, compliance officer, or board member and any of the following isn't already true, close the gap now rather than in 2027:

  • Multifactor authentication is enforced everywhere ePHI lives. Remote access, admin accounts, and cloud consoles included, not just the EHR login.
  • Encryption is applied at rest and in transit, without exceptions left undocumented. If something is unencrypted, there should be a written, current, risk-based reason on file, not a gap nobody got back to.
  • The risk analysis happens annually and covers the environment you run today, including cloud infrastructure, connected devices, and business associate access, not the environment you documented three years ago.
  • The network is segmented so a single compromised endpoint doesn't hand an attacker a path to every system holding patient data.
  • Backups are tested, not just retained. A backup you haven't restored from is a hypothesis, not a control.
  • Vendor and business associate access is scoped and reviewed. Unpatched internet-facing systems and exploited credentials showed up repeatedly across the April settlements, not just internal missteps.

The Standard Of Care Didn't Move

I am not telling regulated entities to wait for HHS to finish a rulemaking that has already slipped once. I am telling them the rulemaking was never the starting gun. HHS put this in writing in 2021, asked the industry to prove it in 2022, and published the specific control list in 2024. OCR has spent 2026 enforcing exactly that list against organizations that treated it as guidance rather than a floor.

The compliance date moved. The standard patients, regulators, and plaintiffs' attorneys will hold you to did not.