HomeBlogCybersecurity

HIPAA Security Rule Delayed to 2027: What Practices Do Now

Wall-mounted network enclosure in a small medical office, patch panel and switch handling systems that touch patient data

Updated September 26, 2026.

The HIPAA Security Rule overhaul has slipped to July 2027. That's the projected publication date for the final rule, roughly a year later than regulators first signaled.

It's also the worst possible reason to put off the work. The controls in the proposal are the same ones your cyber insurer and your existing risk analysis already expect.

At a glance: where the HIPAA Security Rule update stands
QuestionAnswer
Is it in effect?No. Still a proposal; today's Security Rule applies.
Projected final ruleJuly 2027 (agency projection, not a deadline)
Biggest change"Addressable" safeguards become required
What to do nowMFA, encryption, asset inventory, vulnerability scan

Is the new HIPAA Security Rule in effect yet?

No, and it won't be for a while. The Office for Civil Rights published the proposed rule in the Federal Register on January 6, 2025, with comments due March 7, 2025. No final rule has been issued since.

The timeline has already slipped once. Regulators initially pointed to May 2026 for a final rule. The projected final action date is now July 2027, per the Office of Management and Budget's regulatory tracking site, under RIN 0945-AA22.

One more signal worth knowing: HHS moved the rulemaking to its Long-Term Actions agenda. That placement means the agency doesn't expect to issue a final rule within the next twelve months.

None of these dates bind anyone. They're agency projections, not statutory deadlines, and they've already slipped once.

HIPAA Security Rule update: the timeline so far
DateWhat happened
January 6, 2025Proposed rule published in the Federal Register
March 7, 2025Comment period closed
May 2026Original target for a final rule — missed
July 2027Current projected final action date

What the proposed rule would require

The draft reads like a modern security checklist, which is the point. Per OCR's official fact sheet on the proposal:

Headline requirements in the proposed HIPAA Security Rule
RequirementWhat it means for your practice
Multi-factor authenticationRequired on every system that can reach electronic patient data (ePHI), with limited exceptions. No more treating it as optional.
EncryptionPatient data encrypted at rest and in transit, with limited exceptions.
Asset inventory and network mapA documented list of every system, device, and app that handles patient data, plus a map of how that data moves. Reviewed at least every 12 months.
Vulnerability scanning and penetration testingScans at least every six months; a penetration test at least once every 12 months.
Network segmentationA breach in one corner shouldn't hand an attacker the whole practice.
24-hour notice of contingency-plan activationBusiness associates would have to notify you within 24 hours of activating their contingency plans.

These aren't exotic. Most are what a well-run practice already does. The proposal just stops letting anyone opt out.

Why "addressable" going away is the real story

The proposal takes away the loophole most practices have been leaning on. Nearly everything becomes required, with narrow documented exceptions.

Here's what that replaces. Today's Security Rule splits safeguards into "required" and "addressable." Addressable got read, wrongly, as optional — and plenty of practices skipped encryption or MFA and wrote a note explaining why.

That single change is what's driving the fight, and it's a fair guess at why the timeline keeps moving. The proposal drew more than 4,000 public comments, and that shift is at the center of the objections.

Does a 2027 date mean you can wait?

No. Three reasons, and none of them depend on the new rule ever being finalized.

First, today's Security Rule already requires a risk analysis. A risk analysis that finds missing MFA or unencrypted laptops obligates you to address it. The proposal doesn't create that duty — it removes your ability to document your way out of it.

Second, your cyber insurer isn't waiting for HHS. In the renewal applications we help clients complete, MFA and encryption come up every time — and answering wrong is a coverage problem, not a compliance one.

Third, attackers don't read the Federal Register. Every month a practice runs without MFA on email is a month of exposure that a 2027 final rule does nothing about.

The extra runway is genuinely useful — as budget room, not as permission to stall. Spreading a penetration test, an asset inventory, and a segmentation project across three budget cycles is far easier than doing all three the quarter a final rule drops.

What your practice should do now

Treat the proposal as a preview of your next audit. Act on the items that are just good security regardless of what the final rule says:

  • Turn on MFA everywhere it isn't already — email, the practice management system, remote access.
  • Confirm encryption on laptops, servers, and backups.
  • Build the asset inventory. It's tedious once and easy to maintain after.
  • Schedule a vulnerability scan.

None of that is wasted work if the timeline slips again. Every one of those controls is what cyber insurers and existing HIPAA risk analyses already expect.

If you want a baseline before the rule lands, that's exactly what a cybersecurity assessment produces: where you stand against these controls, and a punch list to close the gaps. For the fundamentals that don't change, our HIPAA IT compliance checklist and our guide to managed IT for medical and dental practices both walk through the day-to-day.

Frequently asked questions

When does the new HIPAA Security Rule take effect?

There's no effective date yet. The proposed rule was published January 6, 2025, and the comment period closed that March. The projected publication date for a final rule is now July 2027, moved back from an earlier May 2026 target, and HHS has placed the rulemaking on its Long-Term Actions agenda. That projection is not a statutory deadline.

Was the HIPAA Security Rule update canceled?

No. It's delayed, not withdrawn. The rulemaking remains active under RIN 0945-AA22 with a projected final action date of July 2027. Long-Term Actions placement signals that HHS doesn't expect to finalize within twelve months, but the proposal itself hasn't been pulled.

Will MFA and encryption really be mandatory?

That's the proposal. Both multi-factor authentication and encryption of patient data — at rest and in transit — would become required rather than "addressable." These controls are already security best practice and insurer expectations, so waiting for the final rule to adopt them carries little upside and real risk.

Does this apply to small medical and dental practices?

Yes. The Security Rule applies to all covered entities regardless of size, and the proposal doesn't carve out small practices. A two-provider dental office would face the same core requirements — MFA, encryption, asset inventory, testing — as a large group, scaled to its systems.

What should we do before the rule is final?

Close the obvious gaps now: enable MFA everywhere, confirm encryption on all devices and backups, build a current asset inventory, and run a vulnerability scan. These are already expected under today's risk-analysis requirement and by cyber insurers, so the work counts whether a final rule arrives in 2027 or later.

Sources and further reading

By Joel Baum, who leads cybersecurity and compliance engagements at The NetSys Group and has run HIPAA risk analyses for medical and dental practices across the NY metro area. NetSys has delivered managed IT and cybersecurity since 1998.

Not sure where your practice stands against what's coming? Book a complimentary risk assessment and we'll map your gaps against the proposed requirements.

HIPAA Compliance Services

Discuss hipaa compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore HIPAA Compliance Services 845-203-3914