HIPAA Security Rule NPRM Published in Federal Register
HHS published the Notice of Proposed Rulemaking (NPRM) to modernize the HIPAA Security Rule, the first major update since the 2013 Omnibus Rule. The proposal eliminates the distinction between addressable and required implementation specifications, mandates encryption of ePHI at rest and in transit with limited exceptions, requires multi-factor authentication, and establishes 72-hour system restoration requirements, alongside annual compliance audits and network segmentation. The comment period closed March 7, 2025 with nearly 5,000 comments, and no final rule has issued; the 2026 Unified Agenda moved the rulemaking to the Long-Term Actions agenda with final action now projected for July 2027, slipping from a prior May 2026 target.
Key Analytics
Impact Analysis
The elimination of addressable specifications would make every security control mandatory, removing the flexibility many smaller covered entities have relied upon, and the encryption, MFA, and 72-hour restoration mandates would require significant infrastructure investment. Heavy industry pushback, driven in part by an HHS-estimated $9 billion first-year compliance cost, contributed to the slip to July 2027, but the delay is runway, not reprieve: OCR continues to signal that encryption, MFA, and tested recovery capabilities reflect its expectations under the existing Security Rule, and organizations that defer preparation risk a compressed implementation window once the final rule lands.
Recommended Actions
- Conduct a gap assessment against the proposed requirements, with particular focus on encryption at rest, MFA, and 72-hour restoration capabilities
- Use the extended timeline to budget and phase infrastructure upgrades for encryption, network segmentation, and tested disaster recovery ahead of the final rule
- Monitor the Unified Agenda and OCR announcements for the final rule's timing and any changes from the proposal, and track OCR enforcement activity under the current Security Rule in the interim
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment on encryption, MFA, and restoration proposals
- ›Phased infrastructure budget and upgrade roadmap
- ›Disaster recovery testing against a 72-hour restoration target
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 105 to 235 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.