By Chris Bowen, Founder & CEO, Bowen & Company. Founder & former CISO, ClearDATA.
Status as of September 25, 2026: HHS published the proposal on January 6, 2025. The federal regulatory agenda lists final action for July 2027. The current Security Rule remains in effect, and HHS says so on its own fact sheet. OCR continues to enforce it.
The proposed update to the HIPAA Security Rule would be the first major overhaul of the regulation since 2013. HHS published the Notice of Proposed Rulemaking on January 6, 2025, and the comment period closed on March 7, 2025. If you handle electronic protected health information as a covered entity or a business associate, the proposal shows where regulators are heading, and most of it maps to work worth doing now.
I have spent 16 years building and operating HIPAA compliance programs at scale. Most of what I have seen over that time is organizations treating the Security Rule as a documentation exercise. The proposal moves the standard toward evidence that controls operate.
What the proposal would change
The headline change would remove the distinction between "required" and "addressable" implementation specifications, with limited exceptions. Under the current rule, addressable means an organization can document a rationale for not implementing a control. That flexibility was always narrower than most organizations believed. The proposal would remove it for the most critical controls.
- Encryption. Encryption of ePHI at rest and in transit, with limited exceptions.
- Multi-factor authentication. MFA for systems that access ePHI, with limited exceptions.
- Asset inventory and network map. A written technology asset inventory and a network map showing how ePHI moves, reviewed at least every 12 months.
- Network segmentation. Policies and procedures that segment systems holding ePHI to limit lateral movement.
- Contingency planning. Written procedures to restore critical systems within 72 hours. Business associates would notify covered entities within 24 hours of activating a contingency plan.
- Testing. Vulnerability scanning at least every six months and penetration testing at least every 12 months.
- Business associate verification. Annual written verification that technical safeguards are deployed.
The 60-day breach notification rule stays as written. The 72-hour figure applies to system restoration, and the 24-hour figure applies to a business associate's notice that it has activated a contingency plan.
Why this matters for business associates
Large health systems and health plans have compliance programs and internal GRC teams. They will adapt. The organizations with the most ground to cover are business associates: healthcare SaaS companies, medical billing vendors, telehealth platforms, and AI companies that handle ePHI on behalf of covered entities.
Many business associates I work with have a BAA in place and a completed security questionnaire. Those documents record a relationship. A risk analysis records your actual risk, and it is the document OCR asks for first.
Here is what I see most often: encryption is inconsistent across environments, MFA covers some systems but not all, there is no formal asset inventory, and the incident response plan has not been tested against a 72-hour restoration window. The proposal puts a spotlight on each of these.
The pressure is also commercial. Health systems increasingly ask business associates for a current HIPAA Security Risk Assessment before contract renewal. I have seen deals delayed and lost because a vendor could not produce one.
The SRA requirement today
The current Security Rule already requires an accurate and thorough risk analysis, and incomplete or missing risk analysis remains the deficiency OCR cites most often. The rule sets no fixed frequency. OCR expects the analysis to stay current: reviewed at least annually and updated after a material change such as a new vendor, a new system, or an incident. The proposal would make annual review an explicit written requirement.
That makes a current SRA the strongest preparation available. It produces the asset inventory, the risk register, and the remediation roadmap that the proposed controls build on. The case for a current SRA rests on today's rule, so it holds whether or not the proposal is finalized. Documented, good-faith remediation also carries weight with OCR.
What to do now
- Complete or refresh your HIPAA SRA. If your last one is more than 12 months old, or predates your current technology environment, it does not reflect your current risk.
- Review your encryption posture. Map every system that stores or transmits ePHI. Identify gaps in encryption at rest and in transit. Prioritize by data sensitivity and exposure.
- Extend MFA. Cover EHR access, cloud storage, email, remote access tools, and API connections.
- Build your asset inventory and network map. This is the prerequisite for everything else. You cannot encrypt what you have not inventoried.
- Test your incident response plan. Run a tabletop exercise against a 72-hour restoration target.
- Review your BAA portfolio. If the rule is finalized, business associates would provide annual written verification of their technical safeguards. Reviewing subcontractor and vendor language now makes later updates simple.
The bottom line
The proposal reflects what regulators expect from organizations that handle patient data. Encryption and MFA are standard practice in 2026, and an organization that can demonstrate both with documented evidence is well positioned whatever the final rule says.
The organizations that navigate this transition well treat it as an operational discipline: current SRAs, tested controls, documented remediation, and an honest internal view of where the gaps are.
If you are a business associate and want to know where you stand, book a 30-minute conversation.
Chris Bowen
Founder & CEO, Bowen & Company
Founder & Former CISO of ClearDATA. 16+ years building HIPAA compliance programs for covered entities and business associates. Zero reportable breaches. Former Forbes Technology Council contributor.
Sources
- HHS: HIPAA Security Rule NPRM fact sheet
- HIPAA Journal: Security Rule update postponed to July 2027
- Compliancy Group: Proposed HIPAA Security Rule update
- Kaufman Dolowich: Proposed changes under review
- Moss Adams: Proposed rule to enhance ePHI cybersecurity
- Crowell & Moring: NPRM summary
- Elisity: Segmentation in the proposed rule
- Epstein Becker Green: Contingency planning timelines
- CoE-PHI: NPRM fact sheet (testing cadence)
- BD Emerson: Breach notification rule unchanged
- MetricStream: Risk analysis most cited deficiency