Skip to content

HIPAA Security Rule update (NPRM)

Proposed United States ยท no upcoming deadlines

Deadlines

DateWhat happens
Mar 7, 20251 year agoComment period closes
Jan 6, 20251 year agoNPRM published

Summaries for reference, not legal advice. Check the official text.

What it does

Proposed overhaul of the HIPAA Security Rule. It would remove the addressable versus required distinction, and require a technology asset inventory and network map, encryption, multi-factor authentication, vulnerability scanning, penetration testing and 72-hour restoration planning. No final rule has been issued.

Who it applies to
HIPAA covered entities (health plans, clearinghouses, most providers) and their business associates.
Penalties
HIPAA civil money penalties under HITECH tiers once final.
Enforced by
HHS Office for Civil Rights
Official name
HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule)
Citation
90 FR 898 (RIN 0945-AA22); would amend 45 CFR Parts 160 and 164
Topics
health, cybersecurity, privacy
Verified 2026-09-25 reginfo.gov
Research notes

The Fall 2025 Unified Agenda lists this as a Long-Term Action with a final action targeted for July 2027 (no exact day, so not listed as a deadline). The proposal would give most entities 180 days after the final rule's effective date to comply.

Related

Questions about HIPAA Security Rule update (NPRM)
What are the HIPAA Security Rule update (NPRM) compliance deadlines?
Jan 6, 2025: NPRM published. Mar 7, 2025: Comment period closes.
Who does HIPAA Security Rule update (NPRM) apply to?
HIPAA covered entities (health plans, clearinghouses, most providers) and their business associates.
What are the penalties under HIPAA Security Rule update (NPRM)?
HIPAA civil money penalties under HITECH tiers once final.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.