Skip to content
    Back to Regulatory Radar
    CriticalNew RegulationJanuary 6, 2025

    HIPAA Security Rule NPRM Published in Federal Register

    HHS published the Notice of Proposed Rulemaking (NPRM) to modernize the HIPAA Security Rule, the first major update since the 2013 Omnibus Rule. The proposal eliminates the distinction between addressable and required implementation specifications, mandates encryption of ePHI at rest and in transit with limited exceptions, requires multi-factor authentication, and establishes 72-hour system restoration requirements, alongside annual compliance audits and network segmentation. The comment period closed March 7, 2025 with nearly 5,000 comments, and no final rule has issued; the 2026 Unified Agenda moved the rulemaking to the Long-Term Actions agenda with final action now projected for July 2027, slipping from a prior May 2026 target.

    HIPAAHealthcare

    Key Analytics

    January 6, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    The elimination of addressable specifications would make every security control mandatory, removing the flexibility many smaller covered entities have relied upon, and the encryption, MFA, and 72-hour restoration mandates would require significant infrastructure investment. Heavy industry pushback, driven in part by an HHS-estimated $9 billion first-year compliance cost, contributed to the slip to July 2027, but the delay is runway, not reprieve: OCR continues to signal that encryption, MFA, and tested recovery capabilities reflect its expectations under the existing Security Rule, and organizations that defer preparation risk a compressed implementation window once the final rule lands.

    Recommended Actions

    • Conduct a gap assessment against the proposed requirements, with particular focus on encryption at rest, MFA, and 72-hour restoration capabilities
    • Use the extended timeline to budget and phase infrastructure upgrades for encryption, network segmentation, and tested disaster recovery ahead of the final rule
    • Monitor the Unified Agenda and OCR announcements for the final rule's timing and any changes from the proposal, and track OCR enforcement activity under the current Security Rule in the interim

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate65-155 hours
    Key Workstreams
    • Gap assessment on encryption, MFA, and restoration proposals
    • Phased infrastructure budget and upgrade roadmap
    • Disaster recovery testing against a 72-hour restoration target

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 65-155 hours
    Start cold under pressureSignificant · 170-390 hours

    Roughly 105 to 235 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events