
If you’ve been holding your breath waiting for HHS to finalize the new HIPAA Security Rule, you can exhale, for now. But don’t get comfortable.
In our last post, we walked through the proposed overhaul to the HIPAA Security Rule: the first major rewrite since 2013, and one that would eliminate the long-standing “addressable vs. required” distinction that’s let healthcare organizations treat safeguards like multi-factor authentication and encryption as optional. Since then, the timeline has shifted, and if your inbox is full of vendor emails implying you’re already out of compliance with a new rule, here’s the reality check.
Where Things Actually Stand
The Department of Health and Human Services published its Notice of Proposed Rulemaking in January 2025 and closed the public comment period in March 2025 after receiving nearly 4,750 comments from hospitals, health systems, vendors, and advocacy groups. OCR had originally targeted May 2026 to issue a final rule.
That date has come and gone. In its most recent Unified Agenda, HHS moved the rule to its “Long-Term Actions” list and pushed the target for final action out to July 2027. More than 100 hospital and provider organizations have gone further, formally asking HHS to withdraw the proposal altogether. Whether OCR finalizes the rule as written, narrows it, or scraps it entirely is still an open question.
So: the rule is delayed. It may even change substantially before it’s final. But three things haven’t slowed down at all.
Three Reasons “Delayed” Doesn’t Mean “Deprioritize”
1. The direction of travel is clear. Whatever the final language ends up being, the intent behind it isn’t going away. Regulators want mandatory MFA, encryption at rest and in transit, network segmentation, and regular technical testing, not policies that say these things are “nice to have.” Even if this specific proposal stalls, the next one (or the next audit standard) will likely lean the same direction. Building toward it now isn’t wasted effort.
2. Enforcement under the current rule is getting more expensive. This is the part that gets lost in “the new rule is delayed” headlines: OCR doesn’t need a new rule to penalize you. Civil monetary penalties under the existing HIPAA framework were inflation-adjusted in January 2026, and the top-tier cap for “willful neglect, not-timely-corrected” violations now sits above $2.19 million. Risk analysis, the same core requirement that’s existed for years, remains the single most-cited deficiency in OCR investigations.
3. “Addressable” was never “optional,” and auditors know it. Even under today’s rule, treating a safeguard as addressable requires documented justification for why it isn’t reasonable or appropriate for your environment, not just a checkbox left blank. Organizations that have been quietly skipping this step are exposed regardless of what happens in 2027.

What This Means for Your IT and Compliance Strategy
The organizations in the best position aren’t the ones scrambling to react to a final rule — they’re the ones already closing the gap between where they are and where regulators are clearly headed. That includes:
- Mandatory MFA across all systems that touch ePHI, not just email and VPN access
- Encryption at rest and in transit, aligned with NIST standards, with real key management, not just “we have SSL”
- Documented, defensible risk analyses that would hold up under an OCR investigation today, not just at renewal time
- Network segmentation that limits how far an intrusion can spread if a single endpoint is compromised
- Regular technical testing, vulnerability scans and penetration tests on a defined cadence, not “whenever we get around to it”
- Incident response plans built around fast detection and reporting, since faster reporting windows are a consistent theme across every draft of this rule
None of this requires a final rule to justify. It requires a plan.
The Takeaway
A delayed rule is not a reason to wait. It’s a rare gift of extra runway to get ahead of requirements that are almost certainly coming in some form without the pressure of a hard compliance deadline forcing rushed decisions. Organizations that use this window well will be the ones writing “we were already ready” posts in 2027, instead of scrambling posts.
Not sure where your organization stands against these proposed safeguards? IP Pathways can help you assess your current posture; encryption, MFA, segmentation, testing cadence, and risk analysis documentation; and build a practical roadmap that holds up whether the rule finalizes in 2027, gets rewritten, or gets withdrawn entirely.


