By Chris Bowen — Founder & CEO, Bowen & Company. Former Founder & CISO, ClearDATA.
Ransomware gangs never got the memo about "addressable" safeguards. While healthcare organizations spent years debating whether certain HIPAA Security Rule controls should be optional, attackers simply kept stealing patient data. The proposed HIPAA Security Rule overhaul is HHS's attempt to close that gap — but the story isn't over yet.
Where things actually stand
Current Status — June 30, 2026
- The HIPAA Security Rule overhaul remains a proposed rule. The Notice of Proposed Rulemaking (NPRM) was published on January 6, 2025.
- HHS missed its own target of finalizing the rule by May 2026. No Final Rule has been published as of today.
- Until a Final Rule is published, none of the proposed requirements are enforceable.
- If the rule is finalized, organizations will have 240 days to comply — 60 days until the rule becomes effective, followed by a 180-day compliance period.
If adopted: what changes
If adopted substantially as proposed, this would be the most significant HIPAA Security Rule update in more than two decades. The key changes:
- Multi-factor authentication (MFA) required for all systems accessing ePHI
- Encryption of ePHI at rest and in transit — no exceptions
- Network segmentation for systems containing ePHI
- Annual penetration testing
- Elimination of the long-standing "required" vs. "addressable" implementation specification distinction — all controls become mandatory
The "required vs. addressable" change is the one with the broadest operational impact. Under the current rule, addressable controls allow organizations to document a rationale for not implementing them. That flexibility disappears entirely under the proposed rule. Every control becomes mandatory, full stop.
Why this isn't a done deal
More than 100 hospital systems and healthcare organizations — including the College of Healthcare Information Management Executives (CHIME) — have formally urged the administration to withdraw the proposal. Their argument: the costs, operational burden, and implementation timelines are unrealistic. HHS's own estimate puts first-year compliance costs at approximately $9 billion. For smaller covered entities and rural hospitals operating on thin margins, that number is existential.
The combination of a missed finalization deadline and significant industry pushback means the rule's ultimate form — and timeline — remains genuinely uncertain.
One thing is certain: cybercriminals won't wait for the Federal Register.
What to do now
Whether this rule is finalized as written, substantially revised, or delayed further, healthcare organizations should be strengthening their security posture now — not because a regulation says so, but because the threat landscape already does. Encryption, MFA, and documented risk assessments aren't regulatory aspirations. They're table stakes in 2026.
The organizations that navigate this best won't be the ones who waited for a Final Rule. They'll be the ones who treated these controls as operational discipline long before OCR came asking.