HIPAA Security Rule Overhaul Pushed to 2027 — Why You Shouldn't Wait to Prepare
HHS has pushed final action on the HIPAA Security Rule overhaul to at least July 2027, moving ahead separately with Privacy Rule changes. If you run a healthcare practice or handle PHI, it's tempting to treat this delay as breathing room. It isn't.
Who This Rule Affects
HIPAA applies to covered entities — healthcare providers, health plans, and healthcare clearinghouses — as well as their business associates: any vendor, contractor, or software platform that creates, receives, maintains, or transmits PHI on their behalf.
In practice, that's a wide net. If your practice works with billing companies, EHR vendors, cloud storage providers, answering services, or IT support that touches patient data in any way, those relationships fall under this rule too — and your business associate agreements need to reflect it.
What's Changing
The proposed Security Rule update would make multi-factor authentication, encryption, and other safeguards required controls rather than optional "addressable" ones. HHS estimates first-year compliance costs across regulated entities at roughly $9 billion industry-wide — a signal of how substantial these changes are expected to be.
Why Prepare Now, Not Later
Required controls will likely mirror what's already best practice — MFA and encryption gaps you have today will need fixing eventually regardless of the rule's timeline.
OCR audits already look for these safeguards in practice, even before they're formally mandatory.
Getting ahead of the rule avoids a compressed, expensive scramble once it's finalized.
Practical First Steps
Audit where MFA is not yet enforced across systems handling PHI.
Confirm encryption at rest and in transit for all PHI repositories.
Document your current safeguards against the proposed rule so gaps are visible before they become mandatory.
Don't Wait for the Deadline to Find Your Gaps
Waiting until the rule is finalized means responding under pressure, on a tight timeline, at a higher cost. Compliance Labs builds and maintains HIPAA compliance programs for practices like yours, so when this rule lands, you're already compliant — not scrambling.
Schedule your free HIPAA readiness consultation today and find out exactly where your practice stands.

Comments