Troutman Pepper Locke·HEALTHCARE

HHS HIPAA Security Rule Update Faces Continued Rulemaking Delays

Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.

The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.

hipaa-security-rulehealthcare-compliancecybersecuritybreach-notificationregulatory-delay
Read the original firm alert →Saturday, August 1, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.