What the Proposed HIPAA Security Rule Update Could Mean for You

On January 6, 2025, the U.S. Department of Health and Human Services published a notice of proposed rulemaking (NPRM) to update the HIPAA Security Rule. It is a proposal, not a final rule. Public comments, possible revisions and a final decision all lie ahead, and the timeline and final content are uncertain. Still, the proposal signals where regulators want healthcare security to go, and smart organizations are using it as a planning guide.

This post summarizes the themes in plain English. It is not legal advice, so check with your compliance counsel for specifics.

Why an Update at All

The Security Rule dates back to the early 2000s. Technology and threats have changed a great deal, and HHS has pointed to the growth in ransomware and breaches affecting health information. The proposal aims to make requirements clearer and stronger.

Themes in the Proposal

Fewer "addressable" gray areas

Today, many Security Rule specifications are labeled "addressable," which organizations have sometimes read as optional. The proposal would largely remove the distinction between required and addressable, making most safeguards required, with limited exceptions.

Written documentation

The proposal emphasizes written policies, procedures, plans and analyses, and would add more specific documentation expectations.

Technology asset inventory and network map

Organizations would be expected to keep an up-to-date inventory of technology assets and a map showing how electronic protected health information moves through systems.

Stronger risk analysis

The proposal describes more detailed risk analysis elements, tied to that inventory and map, and wants analyses reviewed and updated on a defined cycle.

Multi-factor authentication and encryption

The proposal would generally require multi-factor authentication and encryption of electronic protected health information at rest and in transit, with some exceptions.

Other technical expectations

Items discussed include vulnerability scanning, penetration testing at defined intervals, network segmentation, anti-malware protection, backup and recovery, and timelines for restoring critical systems after an incident.

Vendor oversight

Business associates would have to provide more regular written verification of their safeguards, and covered entities would need to be clearer about incident notification obligations between parties.

Planning for incidents

Written incident response plans and tested contingency plans would be more explicit requirements.

What It Could Mean for a Care Operator

If finalized in anything like its proposed form, a skilled nursing or assisted living operator could expect:

More formal documentation to maintain

Greater need for technical controls like MFA, encryption and segmentation

More structured vendor management

More specific recovery planning

Small organizations may find the documentation and testing demands the heaviest. The details of any final rule, compliance timelines and exceptions remain to be seen.

What You Can Do Now

None of these steps depends on the final outcome, since they are good practice already.

Build an asset inventory. List computers, servers, medical devices, network gear, cloud services and software that touch resident information.

Map your data flow. Sketch where ePHI enters, where it is stored and where it leaves.

Update your risk analysis. Make sure it is current and based on your inventory.

Turn on MFA for email, remote access and critical systems.

Encrypt laptops, mobile devices, backups and email containing sensitive information.

Test your backups and document how long a restore actually takes.

Review vendor agreements. Confirm business associate agreements are signed and that you know your vendors' security practices.

Write down your incident response plan and run a tabletop exercise.

Stay informed. Watch HHS Office for Civil Rights announcements and talk with your counsel and IT provider.

A Note on Budgeting

Because the rule is not final, avoid panic purchases. But early planning for items such as MFA, encryption and segmentation can be spread over time, and many of them also reduce cyber insurance risk.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations compare their current safeguards with proposed and existing HIPAA expectations and turn the gaps into a realistic roadmap. If you would like help preparing, we are glad to start with an inventory and gap review.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172