The U.S. Department of Health and Human Services has pushed back final action on its proposed overhaul of the HIPAA Security Rule from May 2026 to July 2027, giving covered entities and business associates additional time to prepare for what would be the first major update to the Security Rule since 2013. Employers that sponsor self-insured health plans should take note of the delay and consult with ERISA counsel on next steps to ensure their plans are in compliance.
The proposed rule, published in the Federal Register on January 6, 2025, would eliminate the distinction between “required” and “addressable” implementation specifications, mandate multi-factor authentication, expand encryption requirements, require comprehensive technology asset inventories and network mapping, extend documentation requirements, and impose detailed incident response and disaster recovery planning obligations, among other significant changes.
The delay follows nearly 5,000 public comments, with many healthcare organizations and industry groups raising concerns about implementation costs and feasibility, particularly for smaller providers and rural healthcare organizations.
Link to What Should Employers Do Now? What Should Employers Do Now?
While the timeline has shifted, meaningful updates to the HIPAA Security Rule remain a matter of when, not if, the evolving cybersecurity landscape demands it.
Organizations should not treat this delay as a reprieve. Instead, use this additional time to evaluate current HIPAA Security Rule compliance programs, update risk analyses, review technical safeguards, and assess business associate oversight so that you are well-positioned when the final rule arrives.