Skip to content

Blog

Regulatory & Compliance

The HIPAA Security Rule Update Slipped to July 2027. That Isn't a Reason to Wait.

HHS moved its target for the Security Rule overhaul. The rule in effect today, and what OCR expects under it, didn't change.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting

In July, HHS updated its regulatory agenda and moved the projected final action date for the HIPAA Security Rule overhaul to July 2027, from the earlier May 2026 target. The rulemaking also moved to the agenda's long-term actions list, signaling that a final version is more than a year away. Agenda dates are planning targets, not deadlines, so it could move again in either direction.

For practices bracing for a much more prescriptive rule, that sounds like breathing room. It is, but only for one thing: the new rule's specific mandates. Nothing about the rule already in effect changed.

What's in effect today

The current Security Rule still requires every covered entity and business associate to conduct an accurate and thorough risk analysis, act on what it finds, and protect ePHI with safeguards appropriate to its environment.

What OCR already expects

Risk analysis is a formal enforcement priority. Investigations look at whether security holds up against today's threats, not whether a document exists. A risk analysis that ignores ransomware, phishing, or unprotected remote access is hard to defend as accurate and thorough.

Since 2021, OCR has been required to consider whether an organization had recognized security practices, such as the NIST Cybersecurity Framework, in place for the previous 12 months when deciding penalties and audit outcomes.

What to do with the extra time

Update the risk analysis so it reflects current systems and today's threats.

Close the gaps it finds, starting with MFA on every account, encryption, tested backups, and access reviews.

Document what has been done and when, so you can show 12 months of practice, not a plan.

Treat the proposed rule as a preview of where the bar is heading, not a requirement to ignore until 2027.

Practices that do this now will not be scrambling when the final rule lands.

For a fuller walkthrough, read our guide to the HIPAA Security Risk Analysis.

Next step

Not sure where your practice stands?

Schedule an IT Environment Review.