By George G. McBride | September 27, 2026
The proposed HIPAA Security Rule updates have been pushed back. HHS’s latest regulatory agenda now lists July 2027 as the target for final action and places the rulemaking under “Long-Term Actions.” The previous agenda targeted May 2026. Current regulatory agenda, previous agenda.
For healthcare organizations planning budgets, staffing, and security improvements, that is a meaningful change. But July 2027 is a projected rulemaking milestone—not a compliance deadline or a guaranteed publication date. Organizations should watch for a final rule and its actual implementation requirements.
The delay concerns the proposed Security Rule modernization, rather than HIPAA as a whole. HHS explicitly states that the current Security Rule remains in effect while this rulemaking proceeds. HHS proposal fact sheet.
The proposal would make security requirements more specific. Among its provisions are multifactor authentication and encryption with limited exceptions; documented technology inventories and network maps; vulnerability scanning at least every six months; annual penetration testing and compliance audits; and stronger incident response, recovery, and business associate oversight requirements. These remain proposals and could change before finalization. HHS summary of proposed changes.
Existing obligations still require attention. Covered entities and business associates must assess risks to electronic protected health information, implement reasonable and appropriate safeguards, address security incidents, and maintain contingency plans. A delayed proposal does not suspend those responsibilities. HHS summary of the current Security Rule.
My recommendation is to use the additional time to strengthen the program:
- Update the risk analysis. Include acquisitions, cloud services, third parties, and changes to clinical workflows.
- Close known security gaps. Prioritize access controls, multifactor authentication, encryption, and remediation based on the organization’s risks.
- Exercise recovery plans. Test whether critical systems and data can actually be restored, and whether clinical teams can operate during an outage.
- Review critical vendors. Understand their access, dependencies, incident coordination, and recovery capabilities.
- Explain the business risk to the Board. Connect security investments to patient care, operational disruption, financial exposure, and recovery readiness.
I would also keep two planning tracks: the requirements enforceable today and the additional requirements that may emerge from the final rule. That makes it easier to maintain compliance while adjusting future investments as the proposal evolves.
Healthcare leaders have more time to prepare. I would use that time to make measurable progress on the risks already facing the organization.
