HIPAA Security Rule update (NPRM)
Proposed United States ยท no upcoming deadlines
Deadlines
| Date | What happens | When |
|---|---|---|
| Mar 7, 20251 year ago | Comment period closes | 19 months ago |
| Jan 6, 20251 year ago | NPRM published | 21 months ago |
Summaries for reference, not legal advice. Check the official text.
What it does
Proposed overhaul of the HIPAA Security Rule. It would remove the addressable versus required distinction, and require a technology asset inventory and network map, encryption, multi-factor authentication, vulnerability scanning, penetration testing and 72-hour restoration planning. No final rule has been issued.
- Who it applies to
- HIPAA covered entities (health plans, clearinghouses, most providers) and their business associates.
- Penalties
- HIPAA civil money penalties under HITECH tiers once final.
- Enforced by
- HHS Office for Civil Rights
- Official name
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule)
- Citation
- 90 FR 898 (RIN 0945-AA22); would amend 45 CFR Parts 160 and 164
- Topics
- health, cybersecurity, privacy
Research notes
The Fall 2025 Unified Agenda lists this as a Long-Term Action with a final action targeted for July 2027 (no exact day, so not listed as a deadline). The proposal would give most entities 180 days after the final rule's effective date to comply.
Related
Questions about HIPAA Security Rule update (NPRM)
- What are the HIPAA Security Rule update (NPRM) compliance deadlines?
- Jan 6, 2025: NPRM published. Mar 7, 2025: Comment period closes.
- Who does HIPAA Security Rule update (NPRM) apply to?
- HIPAA covered entities (health plans, clearinghouses, most providers) and their business associates.
- What are the penalties under HIPAA Security Rule update (NPRM)?
- HIPAA civil money penalties under HITECH tiers once final.