15 min read
What HIPAA's 2027 Security Rule Overhaul Means for Your Organization
If you run IT or compliance for a healthcare organization, you've probably heard some version of "HIPAA is changing" over the past year. This is a...
6 min read
Jason Holmes
Sep 24, 2026, 8:00:02 AM
If you run IT or compliance for a healthcare organization, you've probably heard some version of "HIPAA is changing" over the past year. This is a guide to the HHS' first major overhaul of the HIPAA Security Rule since 2003. The direction is not in question, and organizations that start preparing now will have a far easier time than those who wait for the deadline to become real.
This guide breaks down what's actually changing, when it's expected to take effect, and how a managed IT partner can carry your organization from where you are today to where the rule is headed without scrambling around.
Key points:

The current Security Rule dates to 2003 and was last substantially updated in 2013. In that time, ransomware went from a rare event to the default threat healthcare organizations plan around, and large-scale breaches more than doubled between 2018 and 2023, with the number of people affected climbing more than tenfold over the same period (Perkins Coie). HHS's own reasoning for the overhaul is straightforward: the existing rule's flexibility — letting organizations decide whether a safeguard like MFA was "reasonable and appropriate" for them — made the rule hard to enforce and left too many organizations under-protected (Davis Wright Tremaine). The new rule closes that gap by making almost everything mandatory.
This is the part that gets misreported, so it's worth being precise:
It's important to note that July 2027 is a planning estimate, not a legal deadline. The HHS could move faster or slower. Second, and more important: the current HIPAA Security Rule is fully in force right now. Nothing about the delay changes what you're required to do today. The delay just gives you more runway to prepare for what's coming, rather than less.
If finalized as proposed, here's the core of what shifts:
| SAFEGUARD | TODAY | PROPOSED |
|---|---|---|
| MFA on systems accessing ePHI | Addressable (optional with justification) | Required |
| Encryption at rest & in transit | Addressable | Required, with limited exceptions |
| Technology asset inventory | Not explicitly required | Required, updated every 12 months |
| Network map of ePHI flow | Not required | Required, updated every 12 months |
| Vulnerability scanning | Not specified | At least every 6 months |
| Penetration testing | Not specified | At least every 12 months |
| Business associate assurances | Signed BAA | Signed BAA plus annual written technical verification |
| Contingency plan activation notice | Not specified | 24-hour notice to covered entity; 72-hour data restoration target |
A few of these deserve extra attention because of how much operational work they represent:
The asset inventory and network map are new administrative safeguards, not just documentation. OCR wants a written, maintained inventory of every piece of hardware, software, and electronic media that touches ePHI, plus a network map showing how that data actually moves through your systems. Most organizations with a strong compliance program don't currently maintain this at the level of detail proposed.
Annual business associate verification changes the vendor relationship significantly. It's no longer enough to have a signed BAA on file. Each business associate would need to provide, at least once every 12 months, a written analysis from someone with cybersecurity expertise confirming their technical safeguards are in place, plus a signed certification from someone authorized to speak for that organization. If you work with a billing service, a cloud EHR host, a telehealth platform, and an AI scribe tool, that's four separate annual verifications to track, request, and file, not a one-time signature.
The compliance clock, once the rule is finalized, is proposed at 240 days total: 60 days until the rule takes effect, plus 180 days to reach compliance. BAA-specific updates would get a somewhat longer runway, generally whichever comes first between your next BAA renewal after the compliance date, or one year after the effective date.
It's tempting to treat a 2027 target as "not our problem yet." Two reasons that's the wrong read:
Organizations that treat this as a two-to-three-year infrastructure project, done in phases, will barely notice when a final rule lands. Organizations that wait will be doing the same scramble in a compressed window at a higher cost, since vendors and consultants tend to raise rates once a compliance deadline is fixed and demand spikes industry-wide.
This is exactly the kind of transition a managed IT partner is built for: moving an organization from its current state to a defined future state, in planned phases, without disrupting patient care along the way.

A managed IT partner who's already tracking this rulemaking can build your roadmap around the proposed requirements now, so each phase of normal IT investment; a new EHR integration, a network refresh, a vendor contract renewal; moves you closer to compliance instead of creating more catch-up work later.
At Cobb Technologies, we've supported healthcare networks and mid-size practices across Virginia since 1990, and we're already helping clients build toward these proposed standards as part of their regular security roadmap, not as a separate, disruptive project. Our Cobb Connect managed IT services include 24/7 monitoring, MFA and encryption deployment, backup and disaster recovery, and vCIO strategic planning that map directly onto where the rule is headed.
We're independently owned and locally based, so you get a dedicated account manager who understands your environment and can walk you through exactly where your organization stands against the proposed rule today.
The HIPAA Security Rule overhaul isn't final, and the timeline has already moved once. But the direction is clear, and the organizations best positioned when it does land will be the ones that started building now, in manageable phases, rather than the ones waiting for a deadline to force their hand.
Want to see where your organization stands against the proposed rule?
Visit our Managed IT Services page to learn more about Cobb Connect, or reach out to talk with our team about a free network assessment to check your HIPAA compliance.
Citation List
No. It's still a proposed rule. HHS published the proposal in January 2025, and a final version isn't expected before July 2027 at the earliest.
The rule would eliminate the "addressable" safeguard category, making things like MFA, encryption, penetration testing, and asset inventories mandatory instead of optional.
Once a final rule is published, it takes effect 60 days later, with a further 180 days to reach compliance and 240 days total from publication.
Yes. The current Security Rule is already in force, and OCR's enforcement expectations are already trending toward these controls regardless of the final rule's timing.
It applies to all covered entities and business associates, regardless of size. Smaller organizations will need efficient, right-sized approaches to meet the same requirements.
Business associates would need to provide written technical verification at least once every 12 months, not just a signed BAA on file.
Likely yes. BAA-related updates would apply at your next renewal after the compliance date, or one year after the rule's effective date, whichever comes first.
Yes. It's HHS's current planning estimate, not a binding legal deadline, and it has already slipped once.
You'd be doing asset inventories, MFA rollouts, and penetration testing under a hard 240-day deadline, likely at a higher cost as demand for compliance help spikes industry-wide.
By running a gap analysis now, building the required asset inventory and network map, rolling out MFA and encryption, and setting up a vendor verification process — all as part of your normal IT roadmap rather than a rushed, separate project.
15 min read
If you run IT or compliance for a healthcare organization, you've probably heard some version of "HIPAA is changing" over the past year. This is a...
5 min read
Healthcare organizations don't just need IT support; they need a partner who understands compliance, security, and what's actually at stake when...
9 min read
Watch Our Patching and Updating Video Below