What the Proposed HIPAA Security Rule Update Could Mean

On January 6, 2025, the Department of Health and Human Services published a Notice of Proposed Rulemaking to update the HIPAA Security Rule. It is the first major proposed overhaul of the Security Rule in many years, and it generated significant discussion among healthcare organizations. The public comment period closed in March 2025.

It is important to be clear about one thing: this is a proposal. It is not final, and the final version could differ from what was proposed. Still, the direction is informative, and many of the ideas overlap with practices that are already good security hygiene.

Why the Rule Is Being Revisited

The current Security Rule was written in an earlier era of technology. Healthcare has since seen a large increase in ransomware and other cyberattacks, and HHS has said the update is meant to strengthen protections for electronic protected health information.

Key Ideas in the Proposal

Based on the published proposal, notable elements include the following. Details could change before any final rule.

Removing the Addressable Distinction

Under the current rule, some implementation specifications are required and others are addressable, which gives organizations flexibility. The proposal would largely remove that distinction, making most specifications required, with limited exceptions.

Technology Asset Inventory and Network Map

The proposal would require a written inventory of technology assets and a map showing how electronic protected health information moves through systems. This is a practical step that supports the risk analysis.

More Specific Risk Analysis Expectations

The proposal would add detail about what a risk analysis should include, building on the existing requirement to conduct an accurate and thorough assessment.

Multi-Factor Authentication and Encryption

The proposal would call for multi-factor authentication and encryption of electronic protected health information at rest and in transit, with certain exceptions.

Other Technical Safeguards

It also discusses vulnerability scanning, penetration testing at defined intervals, network segmentation, backup and recovery capabilities with time targets, and removal of extraneous software.

Incident Response and Contingency Planning

The proposal would require written plans and procedures for restoring systems after an incident, and regular testing.

Business Associate Oversight

It would require business associates to verify that their own safeguards are in place and to notify covered entities quickly after activating contingency plans.

What Is Not Settled

Several things are uncertain at this point.

Whether the rule will be finalized, and when

Whether the final text will keep, change or drop specific provisions

What compliance timelines will apply

How the proposal's cost estimates and burden concerns raised in public comments will be addressed

Because of this uncertainty, avoid making big purchases solely on the basis of the proposal. Focus instead on practices that are valuable regardless.

Sensible Preparation Today

Many proposed items match existing recommendations from the HHS 405(d) program and the NIST Cybersecurity Framework. Steps worth taking regardless of the final outcome:

Build a technology asset inventory and a simple data flow diagram

Update your risk analysis so it reflects current systems and threats

Enable multi-factor authentication on email, remote access and clinical systems

Encrypt laptops, mobile devices and backups

Test your backups and document how long recovery takes

Segment your network to separate clinical, guest and building systems

Review business associate agreements and vendor security practices

Write and practice an incident response plan

Stay Informed

Follow official HHS announcements and guidance from trade associations in long-term care. Pay attention to any final rule and its effective dates. If your organization submitted or considered comments, keep those materials for reference.

Don't Panic, Don't Ignore

The current Security Rule remains in effect, and its requirements, including the risk analysis, still apply. Organizations that already maintain good fundamentals will be in a better position whatever happens.

UnityCare IT can help you compare your current practices against the proposal, identify gaps worth closing now and keep your compliance documentation organized as the rulemaking progresses.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172