Proposed HIPAA Security Rule Changes: What Operators Should Know

On January 6, 2025, HHS published a notice of proposed rulemaking (NPRM) to update the HIPAA Security Rule. It is a proposal, not a final rule, and the public comment period and any later revisions will determine what ultimately takes effect. Still, the direction is clear enough that nursing homes, assisted living communities and clinics can start preparing sensibly.

This post summarizes the major ideas as they appear in the proposal and offers practical steps. Details may change, so treat this as an overview rather than legal advice.

Why a Change Is Being Proposed

The Security Rule has been in place since the mid-2000s, with only limited updates since. Technology and threats have shifted considerably, and HHS has pointed to the rise in ransomware and other attacks on healthcare. The proposal aims to make expectations more specific and to remove some of the flexibility that organizations have sometimes interpreted as optional.

Key Ideas in the Proposal

Fewer "addressable" specifications

Today the Security Rule labels some implementation specifications as "required" and others as "addressable," which many organizations read as optional. The proposal would largely remove that distinction, making most safeguards expected.

More specific technical expectations

The proposal discusses safeguards such as:

Multi-factor authentication

Encryption of electronic protected health information at rest and in transit, with some exceptions

Network segmentation

Vulnerability scanning and penetration testing on a defined schedule

Anti-malware protection

Removal of extraneous software and disabling of unused network ports

Documentation and inventories

It would call for a written technology asset inventory and network map, reviewed and updated regularly, and for a more formal risk analysis built on that inventory.

Planning for recovery

The proposal emphasizes written incident response plans, restoring critical systems within a defined short timeframe, and testing contingency and disaster recovery plans.

Business associates

It would strengthen expectations that business associates verify their safeguards and notify covered entities quickly when they activate contingency plans.

The specific timelines and numbers in the proposal could shift. Check the Federal Register notice and HHS guidance rather than relying on summaries, including this one.

What It Means for Smaller Providers

A fair worry is the burden on smaller organizations. Commenters, including provider associations, will likely raise cost and feasibility concerns, particularly for rural and independent facilities. It is too early to say how the final rule will treat them.

But look at the list above. Most items are things a well-run facility should be doing anyway: MFA, tested backups, encryption, an accurate list of systems, and a plan for incidents. If you already do these, the proposal is more about documenting and formalizing than starting from scratch.

What To Do Now

You do not need to wait for a final rule to improve.

Build a technology inventory. List servers, workstations, laptops, tablets, medical and nurse call devices, printers, network equipment, cloud services and the data each one touches.

Draw a simple network map. Even a rough diagram showing how devices connect is a start.

Refresh your risk analysis. If your last one is more than a year old or predates major changes, update it.

Close the obvious gaps. Enable MFA, encrypt laptops and portable devices, patch regularly, and confirm backups restore.

Write or update your incident response and contingency plans, then rehearse them.

Review business associate agreements and ask key vendors how they protect your data.

Budget ahead. Even before the rule is final, plan for security work in the next budget cycle rather than treating it as an emergency expense.

Stay Informed

Watch HHS, the Office for Civil Rights and your state and national provider associations for updates. If the rule is finalized, expect a compliance period before enforcement, though the length is not yet known.

How UnityCare IT Helps

UnityCare IT works with long-term care and healthcare organizations on risk analyses, asset inventories, network mapping and security improvements that line up with the direction of the proposal. If you want to understand where you stand today, we can help with a practical gap review.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172