In January 2025, the HHS Office for Civil Rights published a notice of proposed rulemaking that would substantially rewrite the HIPAA Security Rule. The Security Rule’s substantive requirements have changed little since it took effect in 2003, with modifications in 2013. HHS has described the proposal as the first update to the Security Rule since 2013. The comment period closed in March 2025.

Before anything else, the single most important sentence in this article: this is a proposed rule, not a final one. Nothing in it applies to your practice today. A notice of proposed rulemaking is a formal request for public input. What emerges at the end — if anything emerges — can look quite different, arrive years later, or never arrive at all. We are writing about it because the direction of travel is useful information for planning, not because there is a deadline to panic about.

With that said, the proposal is worth reading carefully, because most of what it would require is already what auditors, insurers, and breach investigators expect. If it never finalizes, the practices below still put you in a better position. If it does finalize, you will have started early.

Where the Current Rule Stands

The Security Rule as written today is deliberately flexible. It sets standards, and under most standards lists implementation specifications marked either required or addressable. Addressable has never meant optional: you implement the specification, or you document why it is not reasonable and appropriate for your organization and put an equivalent alternative safeguard in place.

That flexibility was intentional in 2003, when the rule had to cover a solo practice with one computer and a hospital system with thousands. It has also been the source of most of the confusion we see. Encryption is the classic example. It is addressable, which a surprising number of practices have read as “we do not have to.” In practice, there is no equivalent alternative to encryption, so the defensible reading has always been that you encrypt or you carry the liability.

Two other current-rule facts worth stating plainly, because they get restated wrongly all the time. HIPAA requires ongoing risk analysis and does not specify a frequency — annual is the accepted standard of care and what auditors expect, but the rule does not say the word. And business associates carry the same Security Rule obligations as covered entities. Our HIPAA IT compliance checklist covers the current obligations in detail.

What the Proposal Would Change

Every item below is described as proposed. None of it is in force.

The addressable category would largely disappear. This is the headline. As proposed, nearly all implementation specifications would become required, with a small set of specific exceptions. The flexibility that let organizations document their way around a safeguard would mostly go away.

Encryption would be required for protected health information both at rest and in transit, subject to limited exceptions. For a practice that already encrypts laptops, servers, backups, and email in transit, this is largely a documentation exercise. For one that does not, this is the project.

Multi-factor authentication would be required, again with limited exceptions. Microsoft’s research has consistently found that multi-factor authentication blocks more than 99% of automated account-compromise attempts, which is why every framework has converged on it. It is also not a force field — adversary-in-the-middle phishing kits steal the session token after you approve the prompt, which defeats app codes and push approvals alike. For finance, email admin, and anything touching money, use phishing-resistant MFA such as passkeys or a hardware security key. If you have not rolled it out beyond email, our MFA guide for business owners covers the sequence.

A written asset inventory and network map would be required, covering the technology assets that create, receive, maintain, or transmit protected health information, and updated at least annually and when relevant changes occur. This one sounds bureaucratic and is quietly the most useful item on the list. You cannot protect, patch, or investigate what you have not written down, and in nearly every breach investigation the surprise is a system nobody remembered.

Network segmentation would be required. In plain terms: the guest Wi-Fi, the medical devices, the front-desk workstations, and the servers holding records should not all sit on one flat network where anything can reach anything.

Regular technical testing. As proposed, vulnerability scanning at least every six months and penetration testing at least annually, along with periodic review and testing of security measures.

Specific contingency and recovery expectations. The proposal contemplates restoring certain critical systems and data within 72 hours of a loss, with written procedures and a prioritized restoration order. That number is a planning target in the proposal, not a current legal obligation, but it is a reasonable yardstick for asking whether your current backup arrangement could actually deliver.

Tighter vendor and workforce timelines. As proposed, a business associate would have to notify a covered entity within 24 hours of activating its contingency plan, and would have to provide annual written verification — supported by an analysis and certification from a subject matter expert — that required technical safeguards are deployed. There is also a proposed 24-hour window for notifying relevant parties when a workforce member’s access to protected health information is terminated or changed, which is really an offboarding discipline requirement.

More documentation, and more specific documentation. Written policies and procedures for essentially everything, with defined content requirements for the risk analysis itself rather than the current open-ended standard.

What Is Genuinely Uncertain

We are not going to predict a finalization date, and you should be skeptical of anyone who does. Rulemaking timelines are long and unpredictable, agency priorities shift, and comments on this proposal raised substantial concerns about cost and feasibility for small providers — exactly the kind of feedback that produces changes between proposal and final rule, or produces no final rule at all.

What is worth watching, rather than acting on: whether the addressable category survives in some form, whether small providers get a scaled or phased set of obligations, how long the compliance runway is after any final rule, and whether the technical testing and vendor certification requirements survive contact with the comment record.

What is not uncertain is the direction. Every serious framework, every cyber insurance questionnaire, and every OCR settlement agreement of the last several years points the same way: inventory your systems, encrypt the data, require strong authentication, segment the network, test the backups, and write it down.

What to Do Now, Regardless

Here is the honest version of a to-do list. None of it is wasted effort if the proposal never finalizes, because all of it is defensible under the current rule and most of it will show up on your next insurance renewal anyway.

The Bottom Line

A proposed rule is a signal, not a deadline. The signal here is clear: the era of documenting your way around a safeguard is ending, whether by regulation, by insurance underwriting, or by enforcement practice. Penalties under HIPAA are tiered by culpability and adjusted annually for inflation, and the HHS enforcement page is the authoritative place to check them rather than any figure printed in an article.

If your practice already has an inventory, encryption, MFA, tested restores, and a risk analysis with this year’s date on it, a final rule would be an administrative exercise. If it does not, the work is worth starting now on your own schedule — which is a considerably better experience than starting it on someone else’s.

Related Questions

Is the new HIPAA Security Rule in effect yet?

No. What exists is a notice of proposed rulemaking published by the HHS Office for Civil Rights in January 2025, with a public comment period that closed in March 2025. A proposed rule is a formal request for input, not a legal obligation. Nothing in it applies to your practice unless and until a final rule is published, and final rules routinely differ from proposals in meaningful ways after agencies read the comments. Proposals can also be narrowed, delayed indefinitely, or withdrawn entirely. Until a final rule appears in the Federal Register with its own compliance dates, the Security Rule you must follow is the one already on the books.

What does it mean that encryption would change from addressable to required?

Under the Security Rule as it stands today, encryption is an addressable implementation specification. That does not mean optional. It means you either implement it, or you document why it is not reasonable and appropriate in your environment and deploy an equivalent alternative safeguard. In practice there is no equivalent alternative to encryption, so the honest reading has always been that you encrypt or you accept the liability. The proposal would remove the addressable category for most specifications and require encryption of protected health information at rest and in transit, with limited exceptions. For a practice that already encrypts laptops, servers, backups, and email in transit, that is a documentation change. For one that does not, it is the real work.

What would change for business associates?

Business associates already carry the same Security Rule obligations as covered entities, which surprises a lot of vendors. The proposal would add verification duties on top. As proposed, a business associate would have to provide the covered entity with written confirmation, supported by an analysis and certification from a subject matter expert, that the required technical safeguards are actually deployed, on a recurring annual basis. It would also require a business associate to notify the covered entity within 24 hours of activating its contingency plan. If finalized in that form, vendor management stops being a signed agreement in a filing cabinet and becomes an annual evidence collection exercise.

What should a small clinic do now, before anything is final?

Work on the items that are already the accepted standard of care, because the proposal mostly codifies them rather than inventing them. Build an accurate inventory of every system and device that touches protected health information, and a simple diagram of how they connect. Encrypt everything you reasonably can, including laptops, servers, backups, and portable media. Turn on multi-factor authentication for email, remote access, and administrative accounts. Test a restore quarterly and do one full restore test a year, timing how long it takes. Refresh the written risk analysis annually and keep the documentation. Run a tabletop exercise against the incident response plan. Every one of those improves your position under the current rule, under any final version of the proposal, and with your cyber insurance carrier.

Want to Know Where Your Practice Stands?

We work with hospices, clinics, and medical practices across the Central Valley. We will walk your environment against the current Security Rule, flag what a final version of the proposal would add, and give you a prioritized list — not a compliance scare.

Schedule a HIPAA Readiness Review (888) 735-7701