The Proposed HIPAA Security Rule Update: What to Do Now

On January 6, 2025, the Department of Health and Human Services published a notice of proposed rulemaking to update the HIPAA Security Rule. It is a proposal, not a final rule. It may change significantly, be delayed or never take effect in its current form, and the public comment period has closed. Still, it signals where federal regulators believe healthcare security should go, and many of the ideas match practices you can adopt now.

This post summarizes the general direction and offers sensible steps. Read the proposal itself, and consult counsel, for official details.

What the proposal would change, in general terms

The current Security Rule, written in the early 2000s, labels many implementation specifications as addressable, which has allowed organizations to treat some safeguards as optional if they document why. The proposal would, in general, make most specifications required and add more specific expectations. Among the items discussed:

A written technology asset inventory and a network map showing how ePHI moves.

A more detailed, written risk analysis, reviewed at least annually.

Required multi-factor authentication for many systems, with limited exceptions.

Encryption of ePHI at rest and in transit, with exceptions.

Network segmentation, vulnerability scanning and periodic penetration testing.

Defined timeframes for applying patches.

Written procedures to restore critical systems and data within a short period after an incident.

Annual compliance audits.

Stronger expectations that business associates verify their safeguards and notify covered entities quickly of certain events.

Treat the specifics as proposed, since the final text could differ.

Why you should care even though it is not final

Regulators, insurers and plaintiffs' attorneys already look at these practices as reasonable security. A breach investigation under the current rule can ask whether you did what was reasonable and appropriate.

Many of these controls take months to implement. Starting early spreads cost and effort over a longer period.

Vendors and partners may begin asking you for evidence of these controls regardless of the final rule.

The proposal reflects the HHS 405(d) Health Industry Cybersecurity Practices and NIST guidance, which are already available.

Practical steps now

1. Build or update your asset inventory

List hardware, software, cloud services, medical devices and vendors that touch ePHI. This helps with nearly everything else.

2. Map data flows

Draw a simple diagram of how patient information enters, moves through and leaves your organization, including through vendors, fax and email.

3. Refresh your risk analysis

If yours is more than a year old or does not reflect current systems, update it. Include a prioritized risk management plan with owners and dates.

4. Close the MFA gaps

Protect email, remote access, administrator accounts and the EHR with multi-factor authentication where possible.

5. Check encryption

Confirm laptops, phones, removable media and backups are encrypted, and that data in transit uses current protocols.

6. Document patching

Set written patch timeframes and track compliance, including network devices.

7. Test your recovery

Write restoration priorities for critical systems, then test a restore. A written contingency plan that has never been exercised may not hold up.

8. Segment the network

Separate guest Wi-Fi, medical devices, building systems and servers.

9. Review business associate agreements

Check your vendor list, confirm the agreements are current and ask high-risk vendors about their security controls and notification timelines.

10. Plan for audits

If you have not had an independent review, schedule one, and keep your documentation organized.

What not to do

Do not wait for a final rule before improving. The current rule already requires risk analysis and risk management.

Do not buy products solely because they are labeled as compliant. Compliance comes from a program, not a tool.

Do not treat the proposal as law. Watch for official updates from HHS and the Federal Register, and ask your counsel how it affects you.

Budget perspective

Small providers worry about cost. A staged approach, starting with the inventory, risk analysis, MFA and backups, delivers the largest risk reduction per dollar and aligns with where the proposal points.

Support from UnityCare IT

UnityCare IT helps healthcare organizations compare their current practices with proposed expectations, update risk analyses and prioritize the work. If you would like a gap review, we can walk through it with you in plain language.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172