The HIPAA Security Rule Hasn’t Changed Since 2013. The 2026 Update Changes That.

The Change Healthcare breach in early 2024 disrupted billing and claims processing for weeks across thousands of healthcare organizations. The average healthcare data breach cost $10.9 million in 2024. OCR closed 22 enforcement investigations that same year, collecting nearly $13 million in penalties.

If you’re a healthcare organization, healthtech company or software vendor handling protected health information (PHI), or a digital health team that operates under a Business Associate Agreement (BAA), the regulatory floor you’ve been standing on is about to move.


What Is the 2026 HIPAA Security Rule Update?

The HIPAA Security Rule sets the baseline for how covered entities and business associates must protect ePHI. It was last substantively updated in 2013. A lot has changed since then.

In January 2025, HHS Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) to overhaul the HIPAA Security Rule. The proposed rule was published in the Federal Register on January 6, 2025, under docket RIN 0945-AA22. OCR received over 4,700 public comments during the 60-day comment period. A final rule has been targeted for mid-2026, though the exact date has not been confirmed. Certain industry associations have petitioned HHS to withdraw or modify the proposal.

OCR is planning to make the requirements for the HIPAA Security Rule stricter. Even if the final rule is narrower than the proposed changes, the technical expectations are increasing.

hipaa security rule proposed changes timeline


What the 2026 HIPAA Security Rule Changes Mean for Your Organization

The current HIPAA Security Rule uses a two-tier system: “required” specifications and “addressable” ones. Addressable did not mean optional. It meant organizations could document a legitimate reason for not implementing something and substitute a reasonable alternative.

In practice, some organizations used addressable specification as an excuse for weaker controls. Organizations documented their way around encryption, skipped MFA on legacy systems, and created the paperwork. That is the check-the-box compliance model the proposed update is designed to eliminate. OCR’s own 2024 enforcement report found that weak authentication practices and unchecked lateral movement were among the most common patterns in investigated breaches.

The proposed 2026 update eliminates the required/addressable distinction almost entirely. If finalized as written, nearly every implementation specification becomes required outright. This is not a documentation problem anymore. It’s a technical implementation problem.

These changes would certainly affect the overall operations for covered entities such as healthcare providers and practices. For healthtech and software companies operating as business associates, the gap between your current posture and what will be required may be larger than you think.


The Proposed 2026 HIPAA Security Rule Changes

Here are some of the major changes in the proposed rule (NPRM) to the HIPAA Security Rule.

Please Note: The following standards are “proposed” in the current HIPAA Security Rule NPRM (Notice of Proposed Rulemaking), but have not been finalized (as of June 16, 2026). All requirements, implementation, and timelines are subject to change based on public comment, agency and government initiatives, and final rulemaking.

1. Mandatory Encryption of ePHI at Rest and in Transit

The proposed rule moves encryption from an “addressable” specification to a “required” standard.

  • Encryption at rest and in transit must be configured for all ePHI using prevailing cryptographic standards.
  • Encryption must be implemented on all workstations, servers, and backup systems containing ePHI. No more cleartext HL7 feeds.
  • Narrow technical exceptions remain for legacy and FDA-regulated devices under documented migration plans, but the bar for those exceptions is significantly tighter.

2. Mandatory Multi-Factor Authentication (MFA)

The proposed rule requires multi-factor authentication (MFA) on all systems accessing ePHI.

  • That includes remote access paths, admin consoles, cloud portals, vendor accounts, and legacy systems.
  • If you have MFA on email but not on your Citrix portal or EHR web portal, that is a gap.
  • Exceptions for legacy clinical devices exist, but they are enumerated and narrow — not flexible.

3. Written Technology Asset Inventory and Network Map

The proposed rule requires covered entities and business associates must maintain a current written inventory of all technology assets that create, receive, maintain, or transmit ePHI.

  • The inventory must include hardware assets, software assets, cloud services, and API connections.
  • The inventory must be reviewed and updated annually.

4. Network Segmentation

The proposed rule requires organizations to implement network segmentation policies and supporting technical controls to isolate ePHI-handling systems from the rest of the network.

  • Segmentation must be implemented to limit access and prevent lateral movement by attackers.
  • Flat networks that mix clinical systems with IoT devices, CCTV, or general corporate infrastructure would not meet this requirement.

5. Vulnerability Scanning and Penetration Testing

The proposed rule introduces specific requirements for vulnerability scanning, penetration testing, and patch management.

  • Automated vulnerability scanning must be conducted every 6 months and reviewed for effectiveness every 12 months.
  • Penetration testing must be performed every 12 months.
  • Critical risks must be patched within 15 calendar days. High risks within 30 calendar days.

6. Enhanced Incident Response Obligations

The proposed rule requires covered entities and business associates to implement and annually test a formal incident response plan.

  • Business associates must notify covered entities within 24 hours of activating their contingency plan.
  • BAAs may need to be rewritten to reflect this requirement.

7. Tighter BAA Requirements and Vendor Verification

The proposed rule requires covered entities must obtain written verification at least annually confirming that business associates have implemented the required technical safeguards. The proposed rule also extends that accountability downstream: anyone handling ePHI on behalf of a business associate must be bound by the same terms.

8. Annual Risk Analysis

The proposed rule makes risk analysis requirements more prescriptive. The current rule requires a risk analysis but does not define how often it must be conducted.

  • Risk analyses must be conducted annually (vs “periodically” as defined before).
  • The risk analysis must be scoped against the technology asset inventory required under item 3. You cannot assess risks to ePHI you have not identified and inventoried.
  • Risk analyses must produce documented corrective action. Findings that are identified and not remediated are treated as willful neglect by OCR, not good faith.
  • The scope must cover all ePHI the organization creates, receives, maintains, or transmits — including through third-party systems and cloud services.

9. Annual Compliance Audit

The proposed rule requires covered entities and business associates to perform and document a compliance audit at least once every 12 months.

  • The audit must cover each standard and implementation specification in the Security Rule — a comprehensive review, not a general security check.
  • Both performance and documentation are required. An undocumented audit does not satisfy the requirement.

10. Security Awareness and Training

The proposed rule requires annual security awareness training for all workforce members, with specific content and timing requirements not present in the current rule.

  • Training must cover ePHI handling policies, detecting and reporting security incidents (including malicious software and social engineering), and password and access policies.
  • All workforce members must complete training at least once every 12 months.
  • New hires must complete training within 30 days of first accessing relevant systems.
  • When material policy changes occur, affected workforce members must be trained within 30 days.

11. Anti-Malware Protection

The proposed rule requires organizations to deploy technical controls protecting all technology assets in relevant electronic information systems against malicious software.

  • Protection must cover all technology assets — not just endpoints. This includes servers and systems within the ePHI environment.
  • The requirement explicitly covers viruses and ransomware, though the standard is not limited to those threat types.
  • The rule provides flexibility in how protection is implemented, but not in whether it is implemented.

12. Configuration Management

The proposed rule requires organizations to establish and deploy technical controls for securing relevant electronic information systems and technology assets in a consistent manner.

  • Systems and workstations must be configured and maintained according to the organization’s established secure baselines.
  • The same configuration standards must apply consistently across all relevant systems — ad-hoc or inconsistent configurations are not compliant.
  • Secure baselines must be established before systems are deployed, not retroactively documented.

13. Contingency Planning

Contingency planning requirements span multiple sections of the proposed rule, covering data backup, disaster recovery, emergency access, and testing.

  • Organizations must maintain exact, retrievable copies of ePHI with a documented recovery plan for system failures or emergencies.
  • Emergency access procedures must be in place so authorized personnel can access ePHI when primary systems are unavailable.
  • Applications and data must be assessed for criticality so recovery priorities are documented in advance.
  • Contingency plans must be tested, reviewed, and updated on a defined schedule — not written once and filed.

Common HIPAA Compliance Mistakes

OCR’s 2024 enforcement report identified consistent patterns across the investigations it resolved. Most of these organizations were not bad actors. They were organizations that ran compliance programs that made sense under the old rules and failed to update them.

  • Performing risk analysis and not acting on the findings. OCR is explicit: the analysis is the start of a cycle, not the deliverable. By early 2026, OCR had already issued 11 enforcement actions under its Risk Analysis Initiative, most following ransomware attacks where the organization had conducted a risk analysis but not acted on the findings.
  • Treating MFA as an IT project instead of a compliance requirement. MFA on email is not enough. It needs to cover every access point to ePHI: remote access, admin tools, legacy clinical portals, and vendor accounts.
  • Ignoring subcontractor exposure. If your business associate uses a subprocessor that handles ePHI, that subprocessor needs a BAA and needs to be covered under the same controls. Most organizations don’t track this beyond one level.
  • Missing the BAA refresh window. A BAA signed in 2020 or 2021 does not reference the 2026 Security Rule requirements. When the final rule lands, those agreements are outdated on day one. You need a plan to re-execute them, not just a plan to update the template.
  • Confusing “cloud-hosted” with “encrypted.” Hosting ePHI on AWS or Azure does not automatically satisfy encryption requirements. Service-side encryption must be explicitly configured and documented. Encryption keys must be managed appropriately. Laptops and endpoints connecting to cloud systems still need full-disk encryption enabled.

How Much Time Do You Have?

Once the final rule is published, generally covered entities get 180 days to comply and business associates get 240 days to comply (an additional 60 days). That is eight months.

If the final rule publishes mid-2026 as targeted, compliance will likely be required by late Q1 or early Q2 2027.

Eight months sounds like enough time. It is not, for most organizations. Rolling out multi-factor authentication (MFA) across every ePHI-accessing system, encrypting endpoints, standing up biannual vulnerability scanning and annual pen testing, completing a documented asset inventory, and re-executing BAAs across your entire vendor footprint is a project, not a checklist item.

Organizations that are starting gap assessments now, should be well-prepared for changes to the HIPAA Security Rule.


What to Do Right Now

You do not need to wait for the final rule to start closing gaps. The controls being proposed are not novel. They are good security hygiene. Most of them are already expected under SOC 2 Type II and HITRUST. The goal is to build a compliance posture that is realistic to maintain long-term, not one built to pass a single audit.

Here is where to focus:

  1. Run a gap assessment against the proposed rule requirements. Map your current controls to the specific proposed specifications: MFA coverage, encryption status, asset inventory completeness, patch cadence, and incident response plan currency.
  2. Audit your MFA coverage. Document every access point to ePHI. Identify systems where MFA is not implemented and build a remediation plan with a timeline.
  3. Start your asset inventory. If you cannot answer “where does our ePHI go?”, that is the first problem to solve. This is also the foundation of a defensible risk analysis.
  4. Review your BAAs. Identify every vendor and subcontractor that handles ePHI. Check when agreements were last updated. Build a re-execution plan so you are not doing this in a rush after the final rule publishes.
  5. Get a vulnerability scan on the calendar. If you have not run one in the last six months, do it now. The results will feed directly into your risk analysis.
  6. Update your incident response plan. Build the 24-hour BA notification requirement into your process now. Train the relevant staff. Test the plan.

How Dash ComplyOps Can Help

At Dash, we work with healthtech and software teams to build and maintain security and compliance programs that are realistic to operate.

If you want to know where your security program stands against the new HIPAA proposed rule requirements, we can start with a HIPAA gap assessment and share a structured review of your current controls mapped to the specific proposed specifications. Speak with a compliance expert to get started.

For teams that want to go further, the Dash ComplyOps covers the full compliance workflow: risk assessments through our RiskOps module, comprehensive administrative policies mapped to HIPAA requirements, and vendor and BAA management to keep your subcontractor footprint documented and current.

We are also tracking the 2026 Security Rule rulemaking closely. When the final rule is published, we will update this page and notify customers of any changes to requirements or timelines.


Frequently Asked Questions

What is the 2026 HIPAA Security Rule update?

The 2026 HIPAA Security Rule update refers to a proposed overhaul published by HHS Office for Civil Rights (OCR) in January 2025. It is the first substantive update to the Security Rule since 2013. Key changes include mandatory encryption, mandatory MFA, required network segmentation, and the elimination of the “addressable” specification category. Nearly every technical safeguard would become a hard requirement rather than a flexible option.

Has the 2026 HIPAA Security Rule been finalized?

No. As of June 2026, the rule has not been finalized. OCR published the NPRM in January 2025 and received over 4,700 public comments. The agency targeted a final rule for mid-2026, but that window has passed without publication. A final rule could still be issued, though a narrower version than the NPRM remains possible.

When do the new HIPAA Security Rule requirements take effect?

The compliance timeline has not been confirmed because the final rule has not been published. Once finalized, covered entities will generally have 180 days to comply. Business associates will have 240 days to comply (an additional 60 days). If the final rule publishes in late 2026, compliance deadlines would fall in 2027.

How do the 2026 HIPAA Security Rule changes affect covered entities?

Covered entities, including healthcare providers, health plans, and healthcare clearinghouses, would face stricter technical requirements under the proposed rule. Controls that were previously “addressable” would become mandatory. This includes encryption, MFA, network segmentation, vulnerability scanning, and annual risk analyses. Covered entities would also be required to obtain annual written verification from their business associates confirming those safeguards are in place.

How do the 2026 HIPAA Security Rule changes affect business associates?

Business associates would face the same mandatory technical controls as covered entities under the proposed rule. The changes also tighten subcontractor accountability. Anyone downstream of a business associate who handles ePHI must be bound by the same requirements. Business associates would need to notify covered entities within 24 hours of activating their incident response plan, and existing BAAs would need to be updated to reflect the new requirements.

Do Business Associate Agreements (BAAs) need to be updated under the new HIPAA rules?

Yes, once the final rule is published. BAAs signed before the rule goes into effect will not reference the updated requirements, making them outdated on day one. Organizations should identify every vendor and subcontractor that handles ePHI now, check when agreements were last updated, and build a re-execution plan before the final rule drops.

Does the 2026 HIPAA Security Rule require multi-factor authentication (MFA)?

Yes, under the proposed rule. MFA would be required for all workforce members and systems accessing ePHI. This includes remote access paths, admin consoles, cloud portals, vendor accounts, and legacy systems. Narrow exceptions exist for certain legacy clinical devices, but they are enumerated and specific. Organizations that have MFA on email but not on EHR access points or VPNs have a gap to close.

Does the 2026 HIPAA Security Rule require encryption?

Yes, under the proposed rule. Encryption would move from an “addressable” specification to a required standard. Encryption at-rest and in-transit would be required for all ePHI using prevailing cryptographic standards, including workstations, servers, backup systems, and data in transit. Hosting ePHI on AWS or Azure does not automatically satisfy this requirement. Service-side encryption must be explicitly configured and documented.

Does the 2026 HIPAA Security Rule require vulnerability scanning and penetration testing?

Yes, under the proposed rule. Automated vulnerability scanning would be required every 6 months, with a review of scanning tool effectiveness every 12 months. Annual penetration testing would also be required. Critical risks must be patched within 15 calendar days; high risks within 30 calendar days.