Healthcare Cybersecurity Guidance Updates: Where the Proposed HIPAA Security Rule Actually Stands

Healthcare Cybersecurity Guidance Updates: Where the Proposed HIPAA Security Rule Actually Stands

Healthcare cybersecurity content frequently references “updated regulatory guidance” without specifying which regulation, at what stage, or with what actual legal force. The most significant relevant development, HHS’s proposed overhaul of the HIPAA Security Rule, was published as a Notice of Proposed Rulemaking in January 2025 and, as of this writing, remains unfinished nearly two years later, having already missed its original target date. This paper reports what the proposed rule actually contains, its current regulatory status, and what that status does and doesn’t obligate healthcare organizations to do right now, alongside the underlying investment gap that gives the proposal its urgency regardless of when, or whether, it is finalized.




Introduction

Guidance describing “updated cybersecurity requirements for healthcare” is only useful if it specifies what changed, under what authority, and whether the change is actually in force. This paper names the specific development most current content in this space is likely referring to, HHS’s proposed HIPAA Security Rule update, and reports its status precisely, because the distinction between a finalized legal requirement and an eighteen-month-old proposal still under review is not a technicality. It determines what a healthcare organization is actually obligated to do versus what it would be prudent to prepare for.




What the Proposed Rule Actually Changes

HHS’s Office for Civil Rights published a Notice of Proposed Rulemaking in the Federal Register on January 6, 2025, proposing the first substantial overhaul of the HIPAA Security Rule since 2003. The proposal’s central structural change is the elimination of the rule’s long-standing distinction between “addressable” and “required” implementation specifications, a distinction that has historically allowed covered entities to treat certain safeguards as optional if they documented a reasonable alternative. Under the proposal, several previously addressable safeguards become mandatory outright: encryption of electronic protected health information both at rest and in transit, multi-factor authentication for any system accessing ePHI, network segmentation, regular vulnerability scanning, and annual penetration testing. The proposal also shortens incident reporting timelines, requiring notification to HHS within 72 hours in specified circumstances, and imposes enhanced oversight obligations on relationships with business associates.




Where the Rulemaking Process Actually Stands

The proposal is not finalized, and understanding why matters as much as understanding what it contains. The public comment period closed on March 7, 2025, drawing more than 4,700 comments, a volume that reflects substantial industry engagement, including organized opposition from groups such as CHIME and a coalition of more than 100 hospital and provider organizations that formally requested HHS reconsider or withdraw parts of the proposal. OCR’s regulatory agenda originally targeted spring 2026 for a final rule; that date passed with nothing published, and the current tracked target under OMB’s Unified Agenda has moved to July 2027.

Timeline of the proposed HIPAA Security Rule update, from NPRM publication to current status. Sources: HHS/OCR Federal Register filing; OMB Unified Agenda (RIN 0945-AA22), as tracked by Medcurity, 2026.
Figure 1. Timeline of the proposed HIPAA Security Rule update, from NPRM publication to current status. Sources: HHS/OCR Federal Register filing; OMB Unified Agenda (RIN 0945-AA22), as tracked by Medcurity, 2026.

Until a final rule is published, the proposal has no legal force. The current HIPAA Security Rule, with the addressable-versus-required distinction intact, remains the operative law. This is a meaningfully different situation than “new requirements have taken effect,” and healthcare cybersecurity guidance that doesn’t make this distinction risks organizations either treating unfinished proposals as binding prematurely or, in the opposite direction, assuming no meaningful change is coming and deferring preparation entirely.




Why Healthcare Remains a Specific Target Regardless of the Rule’s Status

The regulatory timeline doesn’t track the underlying threat environment, which has continued to worsen independent of whether HHS finalizes new requirements. Healthcare breach reporting for 2025 describes it as the worst year on record for large healthcare data breaches, with several hundred reported incidents affecting well over 100 million individuals combined. This is the environment the proposed rule is responding to, and it doesn’t wait for a final rule to be published.




The Cybersecurity Investment Gap Behind the Regulatory Push

Part of what makes the proposed rule’s mandatory-safeguard approach notable is the documented gap in security investment the sector currently operates under. Industry benchmarks put healthcare cybersecurity spending at roughly 4 to 7 percent of overall IT budget, compared to approximately 15 percent in financial services, a sector facing broadly comparable regulatory scrutiny and threat actor interest.

Cybersecurity spending as a share of overall IT budget, healthcare versus financial services. Source: Industry benchmarks cited in 2026 HIPAA Security Rule analysis, MetricStream.
Figure 2. Cybersecurity spending as a share of overall IT budget, healthcare versus financial services. Source: Industry benchmarks cited in 2026 HIPAA Security Rule analysis, MetricStream.

This gap is relevant to the proposed rule’s design specifically: moving safeguards from addressable to mandatory is, in part, a regulatory response to the fact that voluntary, risk-based flexibility has not produced investment levels comparable to other regulated sectors handling similarly sensitive data.




What Organizations Can Responsibly Do Before a Final Rule Exists

Given the rule’s unfinished status, the responsible posture is neither full implementation of an unfinished proposal nor deferral until a final rule appears. HHS’s own enforcement posture under the current rule already signals reduced tolerance for treating encryption and MFA as optional in practice, even before any rule change, since recent enforcement actions and OCR’s own NPRM preamble have questioned whether a risk analysis that supports deferring these controls would continue to hold up. Organizations reasonably positioned for either outcome, the rule finalizing substantially as proposed or being narrowed after further comment, are those already treating a current, thorough risk analysis as the foundation for prioritizing encryption and MFA as high-impact controls, rather than either racing to implement every proposed provision or waiting for legal certainty that has now been delayed for over a year past its original target.




Limitations and Open Questions

This paper’s argument has specific limits. First, rulemaking timelines are inherently uncertain, and the July 2027 target cited here is itself a projection subject to further change; by the time this is read, the rule’s status may have moved again. Second, the 2025 breach statistics cited above come from breach reporting aggregation rather than a single authoritative real-time source, and exact figures vary slightly across secondary reporting of the same underlying HHS breach portal data. Third, the healthcare-versus-financial-services budget comparison reflects industry benchmark estimates rather than a single controlled study measuring both sectors on identical methodology, and should be read as directionally indicative rather than precise.




Conclusion

The most significant actual regulatory development behind most current “updated healthcare cybersecurity guidance” content is HHS’s proposed HIPAA Security Rule overhaul, which would convert encryption, MFA, and several other safeguards from addressable to mandatory. As of this writing, that proposal remains unfinished nearly two years after publication, having already missed its original target date, which means organizations are operating in a period of genuine regulatory uncertainty rather than one with a settled new requirement to implement. The underlying investment gap and worsening breach environment that motivated the proposal in the first place do not wait for that uncertainty to resolve.




References

  1. U.S. Department of Health and Human Services, Office for Civil Rights. HIPAA Security Rule Notice of Proposed Rulemaking, Federal Register, January 6, 2025.
  2. Office of Management and Budget. Unified Agenda of Regulatory and Deregulatory Actions, RIN 0945-AA22.
  3. Medcurity. 2026 HIPAA Security Rule Update: New Requirements to Prepare For, and HIPAA Security Rule 2026: What to Expect When OCR Finalizes.
  4. MetricStream. 2026 HIPAA Updates: Key Changes Every Organization Must Know (cybersecurity budget allocation benchmarks; 2025 breach statistics).



Frequently Asked Questions

Not yet. HHS published a proposed update (a Notice of Proposed Rulemaking) in January 2025, but as of this writing no final rule has been published. The current HIPAA Security Rule, with its existing “addressable” versus “required” safeguard distinction, remains the law in force.
It would convert several currently addressable safeguards into mandatory requirements, including encryption of ePHI at rest and in transit, multi-factor authentication for systems accessing ePHI, regular vulnerability scanning, annual penetration testing, and a 72-hour breach notification timeline to HHS in specified circumstances.
The original target was spring 2026, which passed without a final rule. The current tracked target under OMB’s Unified Agenda is July 2027, though rulemaking timelines are frequently revised and this date is not guaranteed.
The proposed rule has no legal force until finalized, but the underlying safeguards, particularly encryption and multi-factor authentication, are increasingly treated as baseline expectations by regulators and enforcement actions even under the current rule. A current, thorough risk analysis is a reasonable foundation for prioritizing these controls regardless of the rule’s final status.
Healthcare organizations spend an estimated 4 to 7 percent of IT budget on cybersecurity, compared to roughly 15 percent in financial services, even though both sectors handle highly sensitive regulated data and face comparable regulatory and threat actor attention.
Over 4,700 comments were submitted during the public comment period, which closed March 7, 2025, including organized opposition from groups such as CHIME and a coalition of more than 100 hospital and provider organizations.