On January 6, 2025, the Department of Health and Human Services published a notice of proposed rulemaking in the Federal Register that would update the HIPAA Security Rule. HHS announced the proposal in late December. It is the first major proposed overhaul of the Security Rule in many years, and it is worth understanding even though it is not yet final.
The key word is proposed. A proposed rule goes through a public comment period, review of those comments and possible revision before anything becomes final. The final version could differ from what was published, and timing is uncertain. Nothing in the proposal changes your legal obligations today. It does, however, signal where regulators are heading.
The current Security Rule treats many safeguards as addressable, which gives organizations flexibility to implement an alternative or explain why a safeguard is not reasonable. The proposal would reduce that flexibility by making many more requirements mandatory. It also aims to bring the rule closer to current cybersecurity practice, which has changed a great deal since the rule was written.
Based on the published proposal, areas of focus include the following:
Written documentation of policies, procedures, plans and analyses
A technology asset inventory and a network map showing how electronic protected health information moves through systems
More detailed risk analysis requirements
Stronger expectations around multi-factor authentication and encryption
Vulnerability scanning and penetration testing on a defined cadence
Network segmentation
Backup, recovery and incident response planning with defined recovery expectations
Stricter oversight of business associates, including written verification of their safeguards
Because details may change, review the notice itself or work with a qualified advisor before making plans based on specific numbers or deadlines.
Skilled nursing, assisted living and clinic operators often run lean IT operations. Many of the practices in the proposal, such as keeping an asset inventory or testing restores, are things well-run organizations already try to do, but they may not be documented or done on a regular schedule. If a final rule resembles the proposal, informal practices will need to become written and repeatable.
The best response to a proposal is to strengthen the fundamentals you will need under almost any version of the rule:
Inventory your technology. List servers, workstations, tablets, network devices, medical devices, cloud applications and where resident data lives.
Map your data flows. Note how information moves between your EHR, pharmacy, labs, billing and outside parties.
Update your risk analysis. If your last one is more than a year old or predates major changes, refresh it.
Turn on multi-factor authentication for email, remote access and administrative accounts.
Encrypt devices and backups, including laptops and portable media.
Test your backups and recovery plan and document the results.
Review business associate agreements and ask key vendors how they protect your data.
Document your policies and training so they are current and accessible.
These steps improve security today and put you in a good position for whatever final requirements emerge.
Stay informed through official sources such as HHS and the Federal Register, and through trade associations that represent long-term care and senior living providers. Many associations submit comments on behalf of their members, which is a way for operators to share concerns about cost and feasibility, especially for smaller facilities.
If additional requirements become mandatory, budgeting will matter. Start discussing with your leadership team now which gaps are likely to need investment, such as encryption, segmentation, testing or monitoring. Spreading improvements over several quarters is easier than a rushed effort later.
UnityCare IT can compare your current environment to the proposal, identify gaps and build a practical roadmap that improves your security posture now. We can also help organize the documentation that auditors and regulators expect to see.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034