Skip to main content

The Proposed 2026 HIPAA Security Rule Overhaul: What Healthcare Teams Need to Know

Holly @ CoolHIPAA6 min read
HIPAASecurity RuleCompliance2026 Updates

If you work in healthcare IT, compliance, or privacy — you've probably heard the buzz. The Department of Health and Human Services (HHS) has proposed the most significant update to the HIPAA Security Rule since it was originally published in 2003.

This isn't a minor tweak. It's a structural overhaul.

Let's break down what changed, why it matters, and what your organization needs to do.

What Happened

In early 2025, HHS published a notice of proposed rulemaking (NPRM) to update 45 CFR Part 164 — the HIPAA Security Rule. The proposed changes reflect over two decades of lessons learned from healthcare data breaches, ransomware attacks, and the rapid adoption of cloud-based systems that the original rule never anticipated.

The rule is still working its way through the federal rulemaking process. A final rule was widely expected in 2026, but the timing has slipped and it remains pending. Once finalized, it's expected to carry a compliance window that gives covered entities and business associates a defined period to meet the new requirements.

The Big Changes

1. No More "Addressable" vs. "Required" Distinction

This is the headline change. Under the old rule, some safeguards were "required" and others were "addressable" — meaning organizations could decide whether to implement them based on their own risk analysis. In practice, many organizations treated "addressable" as "optional."

The proposed rule would eliminate this distinction. All safeguards would become required. If a specific implementation isn't reasonable for your organization, you would need to document an equivalent alternative measure. "We decided not to do it" would no longer be an acceptable answer.

2. Mandatory Encryption — Everywhere

The old rule listed encryption as "addressable." The proposed rule would make encryption of electronic protected health information (ePHI) mandatory — both at rest and in transit. No exceptions.

That would mean:

  • Databases containing ePHI must use encryption at rest
  • All data transmission (APIs, email, file transfers) must use TLS or equivalent
  • Portable devices and removable media must be encrypted
  • Backup systems must encrypt stored data

3. Multi-Factor Authentication (MFA) Required

MFA would be explicitly required for any system that accesses ePHI. The old rule required "unique user identification" and mentioned access controls, but never specifically mandated MFA.

The proposed standard is black and white: if a user can access ePHI through a system, that system would have to enforce multi-factor authentication.

4. Incident Response Timelines

The proposed rule would introduce specific timelines for incident response:

  • 72-hour notification requirement to HHS for breaches affecting 500+ individuals (reduced from the previous "without unreasonable delay" standard)
  • Mandatory incident response plans that must be tested and documented annually
  • Business associates must notify covered entities within 24 hours of discovering a breach

5. Technology Asset Inventory and Network Mapping

Organizations would need to maintain:

  • A complete, current inventory of all technology assets that create, receive, maintain, or transmit ePHI
  • A network map showing how ePHI moves through systems
  • Annual reviews and updates to both

This is a significant lift for many organizations that have grown organically and don't have a clear picture of where their ePHI actually lives.

6. Annual Security Risk Assessments — With Teeth

Risk assessments were always "required" under the old rule, but enforcement was inconsistent. The proposed update specifies:

  • Risk assessments must be conducted at least annually
  • They must be documented in writing with specific methodology
  • Results must be reviewed by leadership and signed off
  • Remediation plans must have defined timelines and accountability

7. Business Associate Requirements Tightened

Business associates (BAs) would face nearly identical requirements to covered entities. The days of BAs operating under lighter oversight would be over. Key changes:

  • BAs must conduct their own independent risk assessments
  • BAs must verify and document their compliance, not just sign a BAA
  • Covered entities must verify BA compliance, not just collect signatures

Why This Matters

The timing isn't coincidental. Healthcare has become the #1 target for ransomware attacks. The average cost of a healthcare data breach hit $7.42 million in 2025, per the IBM Cost of a Data Breach Report. And HHS has made it clear through recent enforcement actions that they're done accepting outdated security postures.

The proposed overhaul would bring the Security Rule into alignment with modern cybersecurity frameworks like NIST CSF 2.0. It also closes the gaps that allowed organizations to check boxes without actually securing their systems.

What Your Organization Needs to Do

Right Now

  1. Read the proposed rule. Not a summary — the actual regulatory text. Know what would apply to you.
  2. Assess your current MFA coverage. If any system that touches ePHI doesn't enforce MFA, that's your first gap to close.
  3. Check your encryption posture. Identify any ePHI at rest or in transit that isn't encrypted.

In the Next 90 Days

  1. Build or update your technology asset inventory. Map every system that creates, receives, maintains, or transmits ePHI.
  2. Review and update your incident response plan. Make sure it meets the new 72-hour and 24-hour notification timelines.
  3. Engage your business associates. Start the conversation about their compliance posture now.

Before the Rule Lands

  1. Conduct a full security risk assessment using the proposed requirements.
  2. Document everything. The new rule emphasizes written documentation and leadership sign-off.
  3. Train your workforce. New requirements mean new training. Your team needs to understand what's changed and why it matters.

How CoolHIPAA Is Updating

We've already updated our training content so your team is ready the day the rule lands. Module 2 (Locking It Down: Security Rule Fundamentals) covers the proposed requirements in depth, including:

  • The elimination of the addressable/required distinction
  • Mandatory encryption requirements
  • MFA mandates
  • Updated breach notification timelines
  • Asset inventory and network mapping requirements

Our scenario-based approach means your team won't just read about these changes — they'll work through realistic situations where they need to apply the new rules.

The Bottom Line

The proposed 2026 HIPAA Security Rule overhaul would be the most significant update to healthcare data security regulation in over 20 years. It would eliminate ambiguity, raise the bar, and bring the rule into the modern era.

Organizations that have been doing the right thing all along will find the transition manageable. Those that have been skating by on "addressable means optional" are in for a wake-up call.

Either way, the rule is coming, and the compliance clock will start the day it's final. Start now.


Want to make sure your team is ready for the proposed 2026 Security Rule updates? Request a demo of CoolHIPAA's updated training modules.