6 min read

What HIPAA's 2027 Security Rule Overhaul Means for Your Organization

What HIPAA's 2027 Security Rule Overhaul Means for Your Organization
What HIPAA's 2027 Security Rule Overhaul Means for Your Organization
10:25

If you run IT or compliance for a healthcare organization, you've probably heard some version of "HIPAA is changing" over the past year. This is a guide to the HHS' first major overhaul of the HIPAA Security Rule since 2003. The direction is not in question, and organizations that start preparing now will have a far easier time than those who wait for the deadline to become real.

This guide breaks down what's actually changing, when it's expected to take effect, and how a managed IT partner can carry your organization from where you are today to where the rule is headed without scrambling around.

Key points:

  • HHS has proposed the most significant rewrite of the HIPAA Security Rule in over two decades, and has pushed its target for finalizing it to July 2027. (HIPAA Journal)
  • The proposal would eliminate the "addressable vs. required" distinction, making MFA and encryption mandatory rather than optional. (Bradley Law)
  • New requirements include a formal asset inventory, a network map of ePHI flow, regular penetration testing, and annual written verification from every business associate. (Bradley Law; Perkins Coie)
  • Once finalized, organizations would have a 240-day total window (60 days to effective date, plus 180 days to compliance) to comply. (Bradley Law)
  • The current Security Rule is still fully in force; however, this change isn't a "what if", it's where enforcement is already heading.

Why This Is Happening Now

HIPAABlogGraphic2

The current Security Rule dates to 2003 and was last substantially updated in 2013. In that time, ransomware went from a rare event to the default threat healthcare organizations plan around, and large-scale breaches more than doubled between 2018 and 2023, with the number of people affected climbing more than tenfold over the same period (Perkins Coie). HHS's own reasoning for the overhaul is straightforward: the existing rule's flexibility — letting organizations decide whether a safeguard like MFA was "reasonable and appropriate" for them — made the rule hard to enforce and left too many organizations under-protected (Davis Wright Tremaine). The new rule closes that gap by making almost everything mandatory.

Where the Timeline Actually Stands

This is the part that gets misreported, so it's worth being precise:

  • December 2024 / January 2025: OCR published the Notice of Proposed Rulemaking (NPRM) in the Federal Register.
  • March 2025: The public comment period closed with close to 4,745 submissions, many from hospital systems and provider associations (including Cleveland Clinic, Yale New Haven Health, and the American Medical Association) arguing the requirements would be too costly and difficult to implement on the original timeline. (Compliancy Group)
  • May 2026 (original target): HHS had initially aimed to publish a final rule.
  • July 2026: HHS pushed that target back a full year, to July 2027, moving the rulemaking into its "long-term actions" category, a signal that a final rule is likely still well over a year away, and could slip further. (Fierce Healthcare; HIPAA Journal)

It's important to note that July 2027 is a planning estimate, not a legal deadline. The HHS could move faster or slower. Second, and more important: the current HIPAA Security Rule is fully in force right now. Nothing about the delay changes what you're required to do today. The delay just gives you more runway to prepare for what's coming, rather than less.

What Would Actually Change

If finalized as proposed, here's the core of what shifts:

SAFEGUARD TODAY PROPOSED
MFA on systems accessing ePHI Addressable (optional with justification) Required
Encryption at rest & in transit Addressable Required, with limited exceptions
Technology asset inventory Not explicitly required Required, updated every 12 months
Network map of ePHI flow Not required Required, updated every 12 months
Vulnerability scanning Not specified At least every 6 months
Penetration testing Not specified At least every 12 months
Business associate assurances Signed BAA Signed BAA plus annual written technical verification
Contingency plan activation notice Not specified 24-hour notice to covered entity; 72-hour data restoration target

 

A few of these deserve extra attention because of how much operational work they represent:

The asset inventory and network map are new administrative safeguards, not just documentation. OCR wants a written, maintained inventory of every piece of hardware, software, and electronic media that touches ePHI, plus a network map showing how that data actually moves through your systems. Most organizations with a strong compliance program don't currently maintain this at the level of detail proposed.

Annual business associate verification changes the vendor relationship significantly. It's no longer enough to have a signed BAA on file. Each business associate would need to provide, at least once every 12 months, a written analysis from someone with cybersecurity expertise confirming their technical safeguards are in place, plus a signed certification from someone authorized to speak for that organization. If you work with a billing service, a cloud EHR host, a telehealth platform, and an AI scribe tool, that's four separate annual verifications to track, request, and file, not a one-time signature.

The compliance clock, once the rule is finalized, is proposed at 240 days total: 60 days until the rule takes effect, plus 180 days to reach compliance. BAA-specific updates would get a somewhat longer runway, generally whichever comes first between your next BAA renewal after the compliance date, or one year after the effective date.

Why Waiting for the Final Rule Is a Bad Bet

It's tempting to treat a 2027 target as "not our problem yet." Two reasons that's the wrong read:

  1. 240 days is not a lot of time for an asset inventory, network map, MFA rollout across every ePHI-touching system, and a first round of penetration testing, especially if you're doing it under deadline pressure alongside your existing responsibilities.
  2. OCR's enforcement posture is already shifting toward these controls, rule or no rule. Auditors and cyber-insurance underwriters increasingly treat MFA, encryption, and documented risk analysis as the baseline for "reasonable and appropriate" safeguards; the standard the current rule already requires. Building toward the proposed rule now is simply building toward what's already considered defensible practice; it's the same principle behind building a data security policy that maps each compliance requirement to a specific control rather than treating them as separate projects.

Organizations that treat this as a two-to-three-year infrastructure project, done in phases, will barely notice when a final rule lands. Organizations that wait will be doing the same scramble in a compressed window at a higher cost, since vendors and consultants tend to raise rates once a compliance deadline is fixed and demand spikes industry-wide.

How Managed IT Bridges the Gap

This is exactly the kind of transition a managed IT partner is built for: moving an organization from its current state to a defined future state, in planned phases, without disrupting patient care along the way.

5steproadmap

 

A managed IT partner who's already tracking this rulemaking can build your roadmap around the proposed requirements now, so each phase of normal IT investment; a new EHR integration, a network refresh, a vendor contract renewal; moves you closer to compliance instead of creating more catch-up work later.

How Cobb Technologies Can Help

At Cobb Technologies, we've supported healthcare networks and mid-size practices across Virginia since 1990, and we're already helping clients build toward these proposed standards as part of their regular security roadmap, not as a separate, disruptive project. Our Cobb Connect managed IT services include 24/7 monitoring, MFA and encryption deployment, backup and disaster recovery, and vCIO strategic planning that map directly onto where the rule is headed.

We're independently owned and locally based, so you get a dedicated account manager who understands your environment and can walk you through exactly where your organization stands against the proposed rule today. 

The Bottom Line

The HIPAA Security Rule overhaul isn't final, and the timeline has already moved once. But the direction is clear, and the organizations best positioned when it does land will be the ones that started building now, in manageable phases, rather than the ones waiting for a deadline to force their hand.

Want to see where your organization stands against the proposed rule?

Visit our Managed IT Services page to learn more about Cobb Connect, or reach out to talk with our team about a free network assessment to check your HIPAA compliance. 

Citation List

    1. HIPAA Journal, HIPAA Security Rule Update Postponed to July 2027
    2. Bradley Law,  Top 10 Takeaways from the New HIPAA Security Rule NPRM
    3. Perkins Coie, HHS Proposal To Strengthen HIPAA Security Rule
    4. Compliancy Group, The Proposed HIPAA Security Rule Update: What It Would Change and How to Prepare
    5. Fierce Healthcare, Feds push back HIPAA security rule overhaul to July 2027
    6. Davis Wright Tremaine, HIPAA Security Rule Resolves To Hit the Gym and Bulk Up

FAQs

Is the new HIPAA Security Rule final yet?

No. It's still a proposed rule. HHS published the proposal in January 2025, and a final version isn't expected before July 2027 at the earliest.

 

What exactly is changing?

The rule would eliminate the "addressable" safeguard category, making things like MFA, encryption, penetration testing, and asset inventories mandatory instead of optional.

When does compliance actually start?

Once a final rule is published, it takes effect 60 days later, with a further 180 days to reach compliance and 240 days total from publication.

Do we need to do anything right now?

Yes. The current Security Rule is already in force, and OCR's enforcement expectations are already trending toward these controls regardless of the final rule's timing.

Does this apply to small practices too, or just large health systems?

It applies to all covered entities and business associates, regardless of size. Smaller organizations will need efficient, right-sized approaches to meet the same requirements.

What changes for our business associates and vendors?

Business associates would need to provide written technical verification at least once every 12 months, not just a signed BAA on file.

Will our current BAAs need to be updated?

Likely yes. BAA-related updates would apply at your next renewal after the compliance date, or one year after the rule's effective date, whichever comes first.

Could the July 2027 date change again?

Yes. It's HHS's current planning estimate, not a binding legal deadline, and it has already slipped once.

What happens if we wait until the rule is final to start preparing?

You'd be doing asset inventories, MFA rollouts, and penetration testing under a hard 240-day deadline, likely at a higher cost as demand for compliance help spikes industry-wide.

How can a managed IT partner help before the rule is finalized?

By running a gap analysis now, building the required asset inventory and network map, rolling out MFA and encryption, and setting up a vendor verification process — all as part of your normal IT roadmap rather than a rushed, separate project.

What HIPAA's 2027 Security Rule Overhaul Means for Your Organization

15 min read

What HIPAA's 2027 Security Rule Overhaul Means for Your Organization

If you run IT or compliance for a healthcare organization, you've probably heard some version of "HIPAA is changing" over the past year. This is a...

What Healthcare Organizations Should Look For When Picking an IT Partner

5 min read

What Healthcare Organizations Should Look For When Picking an IT  Partner

Healthcare organizations don't just need IT support; they need a partner who understands compliance, security, and what's actually at stake when...

Demystifying Patches and Updates

9 min read

Demystifying Patches and Updates

Watch Our Patching and Updating Video Below