On January 6, 2025, HHS published a notice of proposed rulemaking to update the HIPAA Security Rule. One year later, it remains a proposal as far as covered entities are concerned, which means the current Security Rule is still the standard you are held to. But the proposal is a useful preview of where regulators want organizations to go, and many of its ideas match good practice anyway.
This post summarizes the main themes of the proposal, explains how to treat it, and suggests practical steps you can take now.
A proposed rule is not law. It goes through public comment, review and possible revision, and the final version can differ from what was first proposed. Before it could take effect, a final rule would need to be published, and there would be a compliance period. Until then, follow the existing Security Rule and watch for official announcements from HHS and the Office for Civil Rights.
That said, waiting for certainty is not a security strategy. The threats the proposal addresses are already here.
Today, many Security Rule implementation specifications are labeled addressable, which organizations have sometimes treated as optional. The proposal suggested treating them as required, with limited exceptions.
The proposal described requirements such as multi-factor authentication, encryption of ePHI at rest and in transit, network segmentation, vulnerability scanning and penetration testing at set intervals, and anti-malware protection. Details and timelines would matter if a rule is finalized.
The proposal emphasized written inventories of technology assets and a network map showing how ePHI moves through systems, along with updated written policies and regular review.
It called for written plans to restore critical systems and data within a defined period after an incident, along with testing of those plans.
Business associates would face tighter expectations, including written verification of their safeguards and prompt notice to covered entities when certain contingency plans are activated.
None of the following depends on the proposal becoming final. They are good practice under the existing rule too.
List every device and system that touches ePHI, and sketch how data flows between them. This helps your risk analysis and your incident response.
Enable MFA on email, remote access and clinical systems. Verify that laptops, phones and removable media are encrypted, and that data in transit is protected.
Make sure your risk analysis is current, covers all systems, and has a risk management plan with owners and dates.
Define how long you can afford to be without the EHR, and test whether your backups meet that target. Document the results.
Check that agreements are on file, that vendors are listed, and that you know how they would notify you of an incident.
If you currently treat an addressable specification as not reasonable or appropriate, make sure the reasoning is written down and reviewed.
Small and mid-size operators often worry about cost. Spread the work across the year, prioritize the items that cut the most risk, and keep records of what you completed. If a final rule eventually arrives, an organization that has been steadily improving will have less catching up to do.
Because rulemaking timelines are uncertain, build your plan around risk rather than a deadline. Ask each quarter what has changed in your environment, which gaps remain open, and which improvements are already underway. That habit pays off whether or not a final rule is published.
Check the HHS HIPAA website and the Federal Register for official updates, and consider asking your counsel or compliance advisor to flag developments. UnityCare IT can help you compare your current environment against the proposal's themes and the existing Security Rule, then turn the gaps into a practical plan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172