KENTUCKY REGIONAL EXTENSION CENTER

The anticipated updates to the HIPAA Security Rule are delayed until July 2027

This decision is according to the Office of Information and Regulatory Affairs (reginfo.gov).

The proposed rule, introduced on January 6, 2025 through the Notice of Proposed Rulemaking (NPRM), HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, was originally anticipated for final action in May 2026. If finalized, the proposal would represent the first major update to the HIPAA Security Rule since 2013 and would establish more prescriptive cybersecurity requirements for regulated entities.

The delay provides healthcare organizations additional time to prepare for potential new compliance obligations and strengthen cybersecurity programs.

Proposed Changes Outlined in the NPRM:

• Comprehensive and accurate technology asset inventory and network map showing where electronic protected health information (ePHI) is created, stored, processed, and transmitted
• New and expanded requirements for implementing encryption
• Multifactor authentication
• Network segmentation
• Anti-malware protection
• Annual penetration tests
• Vulnerability scans every 6 months
• Annual audits of Security Rule compliance
• Annual risk analyses
• Additional data backup and recovery controls and testing requirements
• Revised business associate agreements and annual written verification that business associates deploy certain technical safeguards
• Extensive documentation requirements
• Treat all implementation specifications as mandatory, eliminating the distinction between “required” and “addressable” implementation specifications

While the delay may offer some breathing room, it should not be viewed as a reason to pause security efforts.

Healthcare organizations should continue conducting annual Security Risk Assessments (SRAs), addressing identified vulnerabilities, strengthening technical safeguards, and maintaining compliance with the current HIPAA Security Rule requirements. Cyber threats continue to evolve, and proactive risk management remains essential for protecting (ePHI) and supporting patient care.

Have Questions?

Our trusted advisors at the Kentucky REC assist healthcare organizations with strengthening HIPAA Security compliance and cybersecurity readiness by offering specialized services to help organizations identify vulnerabilities, address compliance gaps, and prepare for future regulatory requirements.

Contact YOUR experts at Kentucky REC if you have any questions or need assistance with HIPAA security risk assessments, internal vulnerability network scanning, and project management support. We’re here to help: 859-323-3090.