On January 6, 2025, the U.S. Department of Health and Human Services published a notice of proposed rulemaking (NPRM) to update the HIPAA Security Rule. It is a proposal, not a final rule. Public comments, possible revisions and a final decision all lie ahead, and the timeline and final content are uncertain. Still, the proposal signals where regulators want healthcare security to go, and smart organizations are using it as a planning guide.
This post summarizes the themes in plain English. It is not legal advice, so check with your compliance counsel for specifics.
The Security Rule dates back to the early 2000s. Technology and threats have changed a great deal, and HHS has pointed to the growth in ransomware and breaches affecting health information. The proposal aims to make requirements clearer and stronger.
Today, many Security Rule specifications are labeled "addressable," which organizations have sometimes read as optional. The proposal would largely remove the distinction between required and addressable, making most safeguards required, with limited exceptions.
The proposal emphasizes written policies, procedures, plans and analyses, and would add more specific documentation expectations.
Organizations would be expected to keep an up-to-date inventory of technology assets and a map showing how electronic protected health information moves through systems.
The proposal describes more detailed risk analysis elements, tied to that inventory and map, and wants analyses reviewed and updated on a defined cycle.
The proposal would generally require multi-factor authentication and encryption of electronic protected health information at rest and in transit, with some exceptions.
Items discussed include vulnerability scanning, penetration testing at defined intervals, network segmentation, anti-malware protection, backup and recovery, and timelines for restoring critical systems after an incident.
Business associates would have to provide more regular written verification of their safeguards, and covered entities would need to be clearer about incident notification obligations between parties.
Written incident response plans and tested contingency plans would be more explicit requirements.
If finalized in anything like its proposed form, a skilled nursing or assisted living operator could expect:
More formal documentation to maintain
Greater need for technical controls like MFA, encryption and segmentation
More structured vendor management
More specific recovery planning
Small organizations may find the documentation and testing demands the heaviest. The details of any final rule, compliance timelines and exceptions remain to be seen.
None of these steps depends on the final outcome, since they are good practice already.
Build an asset inventory. List computers, servers, medical devices, network gear, cloud services and software that touch resident information.
Map your data flow. Sketch where ePHI enters, where it is stored and where it leaves.
Update your risk analysis. Make sure it is current and based on your inventory.
Turn on MFA for email, remote access and critical systems.
Encrypt laptops, mobile devices, backups and email containing sensitive information.
Test your backups and document how long a restore actually takes.
Review vendor agreements. Confirm business associate agreements are signed and that you know your vendors' security practices.
Write down your incident response plan and run a tabletop exercise.
Stay informed. Watch HHS Office for Civil Rights announcements and talk with your counsel and IT provider.
Because the rule is not final, avoid panic purchases. But early planning for items such as MFA, encryption and segmentation can be spread over time, and many of them also reduce cyber insurance risk.
UnityCare IT helps healthcare organizations compare their current safeguards with proposed and existing HIPAA expectations and turn the gaps into a realistic roadmap. If you would like help preparing, we are glad to start with an inventory and gap review.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172