
Updated September 26, 2026.
The HIPAA Security Rule overhaul has slipped to July 2027. That's the projected publication date for the final rule, roughly a year later than regulators first signaled.
It's also the worst possible reason to put off the work. The controls in the proposal are the same ones your cyber insurer and your existing risk analysis already expect.
| Question | Answer |
|---|---|
| Is it in effect? | No. Still a proposal; today's Security Rule applies. |
| Projected final rule | July 2027 (agency projection, not a deadline) |
| Biggest change | "Addressable" safeguards become required |
| What to do now | MFA, encryption, asset inventory, vulnerability scan |
Is the new HIPAA Security Rule in effect yet?
No, and it won't be for a while. The Office for Civil Rights published the proposed rule in the Federal Register on January 6, 2025, with comments due March 7, 2025. No final rule has been issued since.
The timeline has already slipped once. Regulators initially pointed to May 2026 for a final rule. The projected final action date is now July 2027, per the Office of Management and Budget's regulatory tracking site, under RIN 0945-AA22.
One more signal worth knowing: HHS moved the rulemaking to its Long-Term Actions agenda. That placement means the agency doesn't expect to issue a final rule within the next twelve months.
None of these dates bind anyone. They're agency projections, not statutory deadlines, and they've already slipped once.
| Date | What happened |
|---|---|
| January 6, 2025 | Proposed rule published in the Federal Register |
| March 7, 2025 | Comment period closed |
| May 2026 | Original target for a final rule — missed |
| July 2027 | Current projected final action date |
What the proposed rule would require
The draft reads like a modern security checklist, which is the point. Per OCR's official fact sheet on the proposal:
| Requirement | What it means for your practice |
|---|---|
| Multi-factor authentication | Required on every system that can reach electronic patient data (ePHI), with limited exceptions. No more treating it as optional. |
| Encryption | Patient data encrypted at rest and in transit, with limited exceptions. |
| Asset inventory and network map | A documented list of every system, device, and app that handles patient data, plus a map of how that data moves. Reviewed at least every 12 months. |
| Vulnerability scanning and penetration testing | Scans at least every six months; a penetration test at least once every 12 months. |
| Network segmentation | A breach in one corner shouldn't hand an attacker the whole practice. |
| 24-hour notice of contingency-plan activation | Business associates would have to notify you within 24 hours of activating their contingency plans. |
These aren't exotic. Most are what a well-run practice already does. The proposal just stops letting anyone opt out.
Why "addressable" going away is the real story
The proposal takes away the loophole most practices have been leaning on. Nearly everything becomes required, with narrow documented exceptions.
Here's what that replaces. Today's Security Rule splits safeguards into "required" and "addressable." Addressable got read, wrongly, as optional — and plenty of practices skipped encryption or MFA and wrote a note explaining why.
That single change is what's driving the fight, and it's a fair guess at why the timeline keeps moving. The proposal drew more than 4,000 public comments, and that shift is at the center of the objections.
Does a 2027 date mean you can wait?
No. Three reasons, and none of them depend on the new rule ever being finalized.
First, today's Security Rule already requires a risk analysis. A risk analysis that finds missing MFA or unencrypted laptops obligates you to address it. The proposal doesn't create that duty — it removes your ability to document your way out of it.
Second, your cyber insurer isn't waiting for HHS. In the renewal applications we help clients complete, MFA and encryption come up every time — and answering wrong is a coverage problem, not a compliance one.
Third, attackers don't read the Federal Register. Every month a practice runs without MFA on email is a month of exposure that a 2027 final rule does nothing about.
The extra runway is genuinely useful — as budget room, not as permission to stall. Spreading a penetration test, an asset inventory, and a segmentation project across three budget cycles is far easier than doing all three the quarter a final rule drops.
What your practice should do now
Treat the proposal as a preview of your next audit. Act on the items that are just good security regardless of what the final rule says:
- Turn on MFA everywhere it isn't already — email, the practice management system, remote access.
- Confirm encryption on laptops, servers, and backups.
- Build the asset inventory. It's tedious once and easy to maintain after.
- Schedule a vulnerability scan.
None of that is wasted work if the timeline slips again. Every one of those controls is what cyber insurers and existing HIPAA risk analyses already expect.
If you want a baseline before the rule lands, that's exactly what a cybersecurity assessment produces: where you stand against these controls, and a punch list to close the gaps. For the fundamentals that don't change, our HIPAA IT compliance checklist and our guide to managed IT for medical and dental practices both walk through the day-to-day.
Frequently asked questions
When does the new HIPAA Security Rule take effect?
There's no effective date yet. The proposed rule was published January 6, 2025, and the comment period closed that March. The projected publication date for a final rule is now July 2027, moved back from an earlier May 2026 target, and HHS has placed the rulemaking on its Long-Term Actions agenda. That projection is not a statutory deadline.
Was the HIPAA Security Rule update canceled?
No. It's delayed, not withdrawn. The rulemaking remains active under RIN 0945-AA22 with a projected final action date of July 2027. Long-Term Actions placement signals that HHS doesn't expect to finalize within twelve months, but the proposal itself hasn't been pulled.
Will MFA and encryption really be mandatory?
That's the proposal. Both multi-factor authentication and encryption of patient data — at rest and in transit — would become required rather than "addressable." These controls are already security best practice and insurer expectations, so waiting for the final rule to adopt them carries little upside and real risk.
Does this apply to small medical and dental practices?
Yes. The Security Rule applies to all covered entities regardless of size, and the proposal doesn't carve out small practices. A two-provider dental office would face the same core requirements — MFA, encryption, asset inventory, testing — as a large group, scaled to its systems.
What should we do before the rule is final?
Close the obvious gaps now: enable MFA everywhere, confirm encryption on all devices and backups, build a current asset inventory, and run a vulnerability scan. These are already expected under today's risk-analysis requirement and by cyber insurers, so the work counts whether a final rule arrives in 2027 or later.
Sources and further reading
- Federal Register — HIPAA Security Rule NPRM — the proposed rule as published, with the January 6, 2025 date and the March 7, 2025 comment deadline. Accessed September 2026.
- HHS Office for Civil Rights — NPRM fact sheet — the proposed requirements, in the regulator's own summary. Accessed September 2026.
- Holland & Knight — Amendments Now Projected for July 2027 — the July 2027 final action date and RIN 0945-AA22, from OMB's regulatory tracking site. Accessed September 2026.
- Clark Hill — Update Delayed Until 2027 — the move to the Long-Term Actions agenda, the comment count, and what that placement signals. Accessed September 2026.
- HIPAA Journal — Security Rule Update Postponed — the original May 2026 target the timeline slipped from. Accessed September 2026.
By Joel Baum, who leads cybersecurity and compliance engagements at The NetSys Group and has run HIPAA risk analyses for medical and dental practices across the NY metro area. NetSys has delivered managed IT and cybersecurity since 1998.
Not sure where your practice stands against what's coming? Book a complimentary risk assessment and we'll map your gaps against the proposed requirements.
Related reading
Healthcare ITHIPAA IT Compliance Checklist for Small Medical and Dental Practices
Read Article
ComplianceIs Google Workspace HIPAA Compliant? BAA, Plans and Setup
Read Article
ComplianceIs Faxing HIPAA Compliant? Fax and eFax Rules for Practices
Read ArticleAlso on this topic: AI for Medical Practices: What Doctors' Offices Can Automate Safely
Discuss hipaa compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
