HIPAA Security Rule overhaul delayed: 6 things to know

Advertisement

Federal regulators have delayed a final update to the HIPAA Security Rule until at least July 2027 while continuing work on other healthcare regulations focused on patient access and interoperability, BankInfoSecurity reported July 8.

Here are six things to know:

  1. In an updated federal regulatory agenda, the Department of Health and Human Services’ Office for Civil Rights (OCR) pushed back final action on its proposed overhaul of the HIPAA Security Rule, which had previously been targeted for May 2026. According to the agenda, OCR still plans to finalize updates to the HIPAA Privacy Rule in August and pursue additional rulemaking related to health IT interoperability and certification requirements.

  2. The proposed Security Rule update, published in January 2025 in the waning days of the Biden administration, would substantially strengthen cybersecurity requirements for organizations that handle electronic protected health information. Among the proposed changes are eliminating the distinction between “required” and “addressable” implementation specifications, making safeguards such as multifactor authentication, encryption, vulnerability scanning and segmentation mandatory except in limited circumstances. The proposal would also require written documentation for all Security Rule policies, procedures, plans and analyses.

  3. According to BankInfoSecurity, OCR received nearly 5,000 public comments on the proposed Security Rule, with many healthcare organizations and industry groups arguing the requirements would be costly and difficult to implement.

  4. While the Security Rule has been delayed, OCR plans to finalize updates to the HIPAA Privacy Rule in August. The update, which dates back to a proposal issued in January 2021 near the end of President Donald Trump’s first term, is intended to strengthen patients’ rights to access their protected health information, improve information sharing for care coordination, expand family and caregiver involvement during emergencies and make other modifications, according to the regulatory agenda.

  5. OCR also plans to issue a proposed rule in November addressing the amount of time covered organizations have to respond to patient requests for their health information. The move follows years of OCR enforcement actions over right-of-access complaints, which the agency has said make up the largest category of HIPAA complaints it receives.

  6. Separately, the Office of the National Coordinator for Health IT (ONC) is planning rulemaking aimed at advancing interoperability, addressing information-blocking issues, reducing certain health IT certification requirements and expanding the use of application programming interfaces. According to the regulatory agenda, ONC also plans to remove certain longstanding certification criteria to reduce compliance burdens while allowing more flexibility for AI-enabled interoperability technologies.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in EHRs / Interoperability

Advertisement