HHS HIPAA Security Rule Update Faces Continued Rulemaking Delays
Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.
The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.