HHS Corrects And Republishes Proposed HIPAA Security Rule Text
Updated:
September 15, 2026
HHS has proposed technical corrections and a complete republication of the HIPAA Security Rule text as part of its sweeping cybersecurity overhaul, but the changes have not become law. The correction and republication language comes from the proposed rule published on January 6, 2025, while the latest federal regulatory agenda now targets July 2027 for final action.
The distinction is important in 2026 because the proposal contains a near-complete replacement for 45 CFR Part 164, Subpart C. It would introduce mandatory multi-factor authentication, recurring vulnerability scanning, annual penetration testing, network mapping, compliance audits and tighter recovery requirements. The existing HIPAA Security Rule remains in effect while HHS considers the final rule.
What Did HHS Correct And Republish In The HIPAA Security Rule Proposal?
HHS proposed technical corrections to existing HIPAA terminology and instructed the Federal Register to “revise and republish” the complete text of 45 CFR Part 164, Subpart C. The republished proposal covers applicability, definitions, administrative safeguards, physical safeguards, technical safeguards, organizational requirements, documentation, transition provisions and a new Security Standards Matrix.
One specific correction concerns the definition of electronic media at 45 CFR 160.103. The first paragraph of that definition refers to electronic storage material, while the second paragraph still refers to transmission media used to exchange information already in electronic storage media. HHS proposed replacing the older term in the second paragraph so both paragraphs use the same language.
The proposal would separately revise the description of transmission media to recognize that data now moves almost entirely in electronic form. HHS pointed to handwritten paper that is hand-delivered or mailed as the remaining case where information never sits on electronic storage material before transmission.
The much larger change is the republication of Subpart C itself. Rather than presenting scattered amendments throughout the current rule, HHS published the proposed Security Rule structure as a consolidated regulatory text.

Is The Republished HIPAA Security Rule A New 2026 Final Rule?
The republished HIPAA Security Rule is not a new 2026 final rule. HHS announced the proposed changes on December 27, 2024, published the NPRM on January 6, 2025, and continues to list that action as a proposed rule. The Security Rule currently in force therefore remains the legal compliance standard.
The regulatory timetable has changed since the NPRM appeared. The Unified Agenda issued in September 2025 listed May 2026 as the planned final-action date, but no final Security Rule was published that month.
The 2026 Unified Agenda moved the rulemaking from the Final Rule Stage to Long-Term Actions and lists July 2027 as the new planned final-action date under RIN 0945-AA22. Placement on the Long-Term Actions list generally signals that the agency does not expect to act within the next 12 months. The agenda contains no legal deadline, so July 2027 is a regulatory planning target rather than a guaranteed publication date.
Healthcare organizations therefore should distinguish between controls that HIPAA requires now and controls that appear only in the pending proposal.
What Cybersecurity Requirements Would The Proposed HIPAA Security Rule Add?
The proposed HIPAA Security Rule would make cybersecurity requirements substantially more prescriptive for covered entities and business associates. HHS proposes removing the distinction between “required” and “addressable” implementation specifications while adding detailed requirements for asset management, authentication, encryption, vulnerability management, recovery, incident response, documentation and recurring compliance reviews.
Covered entities and business associates would need a written technology asset inventory and a network map showing how ePHI moves through their electronic information systems. The inventory would record information such as asset identification, version, accountable person and location.
Both records would need review on an ongoing basis, at least every 12 months, and after environmental or operational changes that could affect ePHI.
The proposal would require multi-factor authentication across relevant electronic information systems, subject to specific exceptions and compensating-control requirements.
HHS proposes a new annual Security Rule compliance audit as well. Each regulated entity would need to document its compliance with every applicable standard and implementation specification at least once every 12 months. Organizations that already run recurring internal reviews can compare their current cadence against the proposed requirement using this guide to HIPAA audit automation.
For health technology companies that handle ePHI, these changes would make several existing HIPAA compliance requirements for SaaS providers considerably more specific, particularly around authentication, documentation, risk analysis and technical safeguards.
How Would The HIPAA Security Rule Change Vulnerability Scanning And Penetration Testing?
The proposed HIPAA Security Rule would explicitly require recurring vulnerability scans and penetration tests. Covered entities and business associates would conduct automated vulnerability scanning according to their risk analysis or at least once every 6 months, whichever is more frequent, while a qualified person would perform penetration testing at least once every 12 months.
HHS treats the two security activities as separate requirements. That distinction reflects the practical difference between a pen test and a vulnerability scan: automated scans search systems broadly for technical weaknesses, while penetration testing uses qualified personnel to examine whether weaknesses can be exploited.
The proposed penetration-testing requirement defines a qualified person as someone with appropriate knowledge and experience in generally accepted cybersecurity principles and methods for protecting the confidentiality, integrity and availability of ePHI.
Testing would occur more frequently when the organization’s risk analysis requires it. The proposed 12-month interval therefore operates as a minimum rather than a universal schedule, making penetration testing frequency dependent on both the regulatory baseline and the organization’s actual risk.
The vulnerability-management section would further require ongoing monitoring of authoritative sources for known vulnerabilities and timely installation of software patches and critical updates.
Which Healthcare Organizations Would Fall Under The Proposed HIPAA Security Rule?
The proposed HIPAA Security Rule would apply to HIPAA covered entities and business associates, including health plans, healthcare clearinghouses, most healthcare providers and organizations that create, receive, maintain or transmit ePHI for covered entities. Business associates would remain directly responsible for applicable Security Rule requirements.
The proposal gives third-party relationships greater attention. Covered entities would need written verification that business associates have deployed required technical safeguards, while business associates would face corresponding responsibilities concerning subcontractors.
HHS estimated that 1,822,600 regulated entities would be affected across several proposed compliance activities. The agency used that population when estimating costs for MFA, network segmentation, penetration testing, policy changes and other requirements.
For startups entering healthcare markets, the regulatory scope remains significant because HIPAA compliance for startups can extend beyond hospitals and medical practices to software vendors and other companies that handle ePHI as business associates.
How Fast Would Healthcare Organizations Need To Comply With A Final HIPAA Security Rule?
HHS proposed making a final HIPAA Security Rule effective 60 days after publication, followed by the standard 180-day compliance period for most new and modified requirements. The actual calendar deadlines cannot be determined until a final rule exists, and HHS can revise the transition provisions before publication.
Business associate agreements would receive additional transition treatment under the proposal at 45 CFR 164.318.
Qualifying existing agreements could remain in place until the earlier of their renewal after the compliance date or 1 year after the final rule’s effective date. Other Security Rule obligations would still become applicable on the normal compliance date.
The proposed timeline means the July 2027 Unified Agenda target should not be interpreted as the date when every new control would immediately become mandatory.
What Would The HIPAA Security Rule Require For Backup And Recovery?
The proposed HIPAA Security Rule would impose detailed backup and recovery requirements for ePHI and critical information systems. HHS proposes that critical relevant electronic information systems and data be restored within 72 hours after a loss, while other systems would be restored according to the organization’s documented criticality analysis.
The 72-hour requirement concerns recovery after loss. It is not a new 72-hour HIPAA breach-notification deadline.
HHS would require ePHI backups that are no more than 48 hours older than the information maintained in relevant systems. Regulated entities would need real-time monitoring of backup failures and error conditions.
A representative sample of backed-up ePHI would need to be restored and documented at least monthly under the proposed technical safeguards. Information-system backup and recovery controls would require effectiveness testing at least every 6 months or after relevant environmental or operational changes. Teams reviewing their current program against those intervals can start with the existing HIPAA backup and recovery requirements that apply today.
How Much Could The Proposed HIPAA Security Rule Cost?
HHS estimated approximately $9.3 billion in first-year costs for regulated entities and affected health plan sponsors under the proposed HIPAA Security Rule. The agency put roughly $4.655 billion of that total on regulated entities and roughly $4.659 billion on plan sponsors. Recurring compliance activities would cost approximately $6 billion per year from years 2 through 5.
The estimate covers compliance audits, business associate verification, MFA, network segmentation, penetration testing, workforce training, policy updates and changes to business associate agreements.
Penetration testing alone accounted for an estimated $655.8 million in annual costs for regulated entities. HHS calculated that figure using 1,822,600 regulated entities, an estimated 3 hours of testing-related labor per entity and an hourly labor rate of $119.94. The agency acknowledged a wide range of potential testing effort, citing 2 to 10 hours depending on organization size and technical complexity.
HHS estimated that the complete proposal could pay for itself when stronger controls reduce the number of individuals affected by breaches by roughly 7% to 16%, based on the agency’s break-even analysis.
How Has The Healthcare Industry Responded To The Proposed HIPAA Security Rule?
Healthcare organizations have raised concerns about the cost, feasibility and prescriptive nature of the proposed HIPAA Security Rule. The American Hospital Association has repeatedly urged HHS to withdraw the proposal and has singled out requirements such as the 72-hour restoration period as potentially unworkable during complex cyber incidents.
The AHA made that request in its February 23, 2026 response to an HHS request for information on artificial intelligence, then reiterated the position on June 15, 2026 while commenting on a separate CMS interoperability and prior-authorization proposed rule.
The association said the HIPAA proposal contained policies it considered technically infeasible and argued that requiring complete restoration of critical systems within 72 hours could create problems during complicated attacks. It also warned that the requirement could push hospitals to bring systems back online before a full threat assessment is finished.
That June 2026 letter was not a new public-comment submission on the HIPAA Security Rule NPRM itself. It was a separate healthcare-policy filing in which the AHA restated its opposition to the pending Security Rule proposal.
HHS has not publicly attributed the move to July 2027 to those objections. The current Unified Agenda provides the new timetable without explaining why the rule was moved to Long-Term Actions.
What Should Healthcare Organizations Do Before The HIPAA Security Rule Is Final?
Healthcare organizations should continue complying with the existing HIPAA Security Rule while preparing for the areas HHS has signaled could become more prescriptive. The OMB regulatory agenda now targets July 2027 for final action and lists the amendments under Long-Term Actions, and more than 100 hospital systems and provider associations signed a CHIME-led letter on December 8, 2025 asking HHS to withdraw the proposal. Preparation should center on controls that hold value under the current rule.
- Maintain A Documented HIPAA Risk Analysis: Risk analysis remains an existing Security Rule obligation and would become more detailed under the proposal, so teams running HIPAA compliance automation should confirm the platform captures asset-level risk decisions with supporting evidence.
- Inventory Technology Assets And Map ePHI Movement: Record hardware, software, cloud systems and third-party technology that could affect protected information, then document where ePHI enters, where it is stored and how it reaches business associates. The proposal treats the asset inventory and the network map as a single requirement reviewed at least once a year.
- Review Encryption Coverage At Rest And In Transit: Removal of the addressable designation would make encryption mandatory across systems that create, receive, maintain or transmit ePHI. Document current gaps and the legacy systems that cannot support it.
- Review MFA Coverage: Determine which relevant systems already support MFA and where technical limitations remain.
- Maintain Recurring Vulnerability Scanning: Compare the current program with the proposed minimum 6-month scanning interval.
- Plan Qualified Penetration Testing: Determine whether testing scope, personnel and scheduling could support the proposed 12-month minimum.
- Test Backup And Recovery Procedures: Measure actual recovery times for critical systems against the proposed 72-hour restoration standard rather than relying solely on written contingency plans.
- Review Business Associate Oversight: Document how technical safeguards are assessed across vendors and subcontractors, since the proposal would require written verification from each business associate every year.
When Will HHS Finalize The HIPAA Security Rule?
HHS currently targets July 2027 for final action on its proposed HIPAA Security Rule overhaul. The rule appears under Long-Term Actions in the 2026 Unified Agenda, replacing the previous May 2026 target. No final version of the cybersecurity overhaul has been published as of September 14, 2026.
The timing remains uncertain because Unified Agenda dates are agency planning estimates rather than binding legal deadlines.
The final text is another unresolved issue. HHS received extensive stakeholder feedback after publishing the NPRM, and the current administration could retain, revise or remove individual provisions before final action.
Organizations therefore should not treat proposed MFA, 6-month vulnerability scanning, 12-month penetration testing or 72-hour system recovery as current HIPAA mandates. The existing Security Rule remains enforceable until HHS completes the rulemaking process.
How Bright Defense Helps Healthcare Organizations Prepare for the HIPAA Security Rule Overhaul
The July 2027 projection gives healthcare teams runway on the proposal while OCR keeps enforcing the rule in force today. Bright Defense covers the controls that carry weight under both: accurate risk analysis, encryption coverage, MFA rollout, and audit-ready documentation.
Penetration Testing Services expose weak segmentation, access-control failures, and attack paths that reach ePHI systems. Continuous Cybersecurity Compliance keeps risk analyses current and evidence ready for an OCR request.
Work started now counts twice. Every control in the proposal maps to a gap that already carries exposure under the current Security Rule.
Sources Cited In This HIPAA Security Rule Report
- HHS Office for Civil Rights: HIPAA Security Rule Notice Of Proposed Rulemaking To Strengthen Cybersecurity For Electronic Protected Health Information (December 27, 2024)
- Federal Register: HIPAA Security Rule To Strengthen The Cybersecurity Of Electronic Protected Health Information (January 6, 2025)
- HHS Office for Civil Rights: HIPAA Security Rule NPRM Fact Sheet (December 27, 2024)
- HHS Office for Civil Rights: Summary Of The HIPAA Security Rule (2026)
- eCFR: 45 CFR 160.103, Definition Of Electronic Media (Current)
- Office Of Information And Regulatory Affairs: HIPAA Security Rule To Strengthen The Cybersecurity Of Electronic Protected Health Information, RIN 0945-AA22 (2026 Unified Agenda)
- CHIME: Stakeholder Letter Requesting Withdrawal Of The Proposed HIPAA Security Rule (December 8, 2025)
- American Hospital Association: Response To HHS Request For Information On Artificial Intelligence In Health Care (February 23, 2026)
- American Hospital Association: Comments On CMS Interoperability And Prior Authorization Proposed Rule (June 15, 2026)
- Holland & Knight: HIPAA Security Rule Amendments Now Projected For July 2027 (July 6, 2026)
- Davis Wright Tremaine: HHS Updates Rulemaking Timeframes (July 8, 2026)
- Fierce Healthcare: Feds Push Back HIPAA Security Rule Overhaul To July 2027 (July 10, 2026)


