On January 6, 2025, the Department of Health and Human Services published a Notice of Proposed Rulemaking to update the HIPAA Security Rule. It is the first major proposed overhaul of the Security Rule in many years, and it generated significant discussion among healthcare organizations. The public comment period closed in March 2025.
It is important to be clear about one thing: this is a proposal. It is not final, and the final version could differ from what was proposed. Still, the direction is informative, and many of the ideas overlap with practices that are already good security hygiene.
The current Security Rule was written in an earlier era of technology. Healthcare has since seen a large increase in ransomware and other cyberattacks, and HHS has said the update is meant to strengthen protections for electronic protected health information.
Based on the published proposal, notable elements include the following. Details could change before any final rule.
Under the current rule, some implementation specifications are required and others are addressable, which gives organizations flexibility. The proposal would largely remove that distinction, making most specifications required, with limited exceptions.
The proposal would require a written inventory of technology assets and a map showing how electronic protected health information moves through systems. This is a practical step that supports the risk analysis.
The proposal would add detail about what a risk analysis should include, building on the existing requirement to conduct an accurate and thorough assessment.
The proposal would call for multi-factor authentication and encryption of electronic protected health information at rest and in transit, with certain exceptions.
It also discusses vulnerability scanning, penetration testing at defined intervals, network segmentation, backup and recovery capabilities with time targets, and removal of extraneous software.
The proposal would require written plans and procedures for restoring systems after an incident, and regular testing.
It would require business associates to verify that their own safeguards are in place and to notify covered entities quickly after activating contingency plans.
Several things are uncertain at this point.
Whether the rule will be finalized, and when
Whether the final text will keep, change or drop specific provisions
What compliance timelines will apply
How the proposal's cost estimates and burden concerns raised in public comments will be addressed
Because of this uncertainty, avoid making big purchases solely on the basis of the proposal. Focus instead on practices that are valuable regardless.
Many proposed items match existing recommendations from the HHS 405(d) program and the NIST Cybersecurity Framework. Steps worth taking regardless of the final outcome:
Build a technology asset inventory and a simple data flow diagram
Update your risk analysis so it reflects current systems and threats
Enable multi-factor authentication on email, remote access and clinical systems
Test your backups and document how long recovery takes
Segment your network to separate clinical, guest and building systems
Review business associate agreements and vendor security practices
Follow official HHS announcements and guidance from trade associations in long-term care. Pay attention to any final rule and its effective dates. If your organization submitted or considered comments, keep those materials for reference.
The current Security Rule remains in effect, and its requirements, including the risk analysis, still apply. Organizations that already maintain good fundamentals will be in a better position whatever happens.
UnityCare IT can help you compare your current practices against the proposal, identify gaps worth closing now and keep your compliance documentation organized as the rulemaking progresses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172