Privacy Rule Changes

While the HIPAA Security Rule overhaul has dominated headlines this year, it isn’t the only major regulatory change on the horizon. HIPAA Privacy Rule changes are moving forward on their own track and are expected to arrive much sooner.

Unlike the Security Rule proposal, which focuses on cybersecurity controls, the Privacy Rule changes address a matter every covered entity and business associate deals with regularly: how patient information is accessed, shared, and disclosed. Other changes relate to care coordination and family involvement.

If you’ve been focused on Security Rule changes, it may be time to shift attention to a Privacy Rule update that could occur much sooner.

Where Things Stand

This proposal has a long history. The U.S. Department of Health and Human Services (HHS) first proposed these Privacy Rule changes in December 2020, and published the formal Notice of Proposed Rulemaking in the Federal Register in January 2021. The comment period closed that spring, but the rule sat largely untouched for years while other priorities took precedence.

That changed in 2026. HHS has advanced the update, and has said it plans to release a Final Rule this month.

As of this writing, the Final Rule has not been published, but it may arrive soon.

Regulated entities will have some time to update their policies after the Final Rule is published. Typically the “effective date” is 60 days after publication, and the “enforcement date” is another 180 days later.

What’s Changing

The proposed updates are extensive and affect several areas of the Privacy Rule. Some of the most significant changes on the table include:

  • Faster access to records. The current 30-day window for covered entities to respond to patient requests for their own records could shrink to 15 days.
  • Narrower third-party transfer rights. The right to direct a covered entity to send electronic PHI (ePHI) to a third party would be limited to ePHI maintained in an electronic health record (EHR), rather than to all forms of ePHI.
  • Clarity on personal health apps. The rule would confirm that individuals can direct a covered entity to send their ePHI to a personal health application, addressing a gray area that has caused confusion for years.
  • Expanded care coordination and family involvement. Changes are expected to make it easier for covered entities to share information for care coordination and case management and to involve family members and caregivers in a patient’s care, particularly in emergency or high-risk situations.
  • Reduced administrative burden. Several proposed changes are intended to simplify processes for covered entities and health plans, not simply expand patient rights, e.g., deleting the requirement for providers to obtain acknowledgment of receipt of the Notice of Privacy Practices.

The Final Rule’s exact language may differ from the original proposal’s. HHS has had years to review public comments, and final rules are often narrowed or adjusted before release. However, the general direction, including faster access, greater patient control, and administrative simplification, is unlikely to change.

Why This Matters for Business Associates, Too

Don’t assume Privacy Rule changes only apply to covered entities: business associates also face real exposure. If your organization handles PHI on behalf of a covered entity, changes to access timelines and disclosure rules can directly affect your business associate agreements (BAAs).

BAAs that describe specific response timeframes, disclosure procedures, or care coordination workflows may need revision once the Final Rule is published. Business associates who wait until a covered entity comes to them with updated contract language will be playing catch-up. Getting ahead of these changes now, understanding what’s likely coming, and flagging affected provisions internally puts you in a stronger position when covered entities request updates.

Why the Right of Access Timeline Matters

Right-of-access issues are not a minor footnote. Failures to respond to patient access requests within the required timeframe remain the largest category of complaints the HHS Office for Civil Rights (OCR) receives.

OCR has used its Right of Access Initiative for years to pursue enforcement actions against organizations that failed to provide patients with timely access to their records, often citing relatively small, correctable failures rather than large-scale breaches.

If the response window shrinks from 30 days to 15, organizations that already struggle to meet the current deadline will have even less margin for error. This isn’t a rule that affects only large health systems with complex records departments. Small and mid-sized practices, and the business associates that support them, are just as likely to face a complaint if their access procedures aren’t running smoothly.

How to Prepare Now

You have time, since the updates won’t be enforced for about eight months after the Final Rule is published. But you shouldn’t wait for the Final Rule to start getting ready:

  1. Review your current access procedures. Understand exactly how your organization handles patient requests for records today, including who is responsible, how requests are tracked, and how long the process actually takes in practice, not just on paper.
  2. Identify where you’d fall short of a 15-day standard. If your current process regularly takes closer to 30 days, look for bottlenecks now, before a shorter deadline becomes mandatory.
  3. Flag BAAs that reference access timelines or disclosure procedures. Business associates and covered entities alike should identify contracts that may need updates once the Final Rule is published.
  4. Watch for the Final Rule’s publication. When published, it will include an effective date and a compliance deadline, giving organizations time to revise policies, procedures, and training materials.

Keeping Ahead of a Changing Rule

HIPAA compliance is an ongoing commitment, not a static milestone. While the Security Rule update isn’t due for final action until mid-2027, the Privacy Rule changes could be finalized and move toward a compliance deadline much sooner. Organizations that start reviewing their access procedures and BAA language now will be in a far better position than those who wait for the Final Rule.

The HIPAA E-Tool® helps covered entities and business associates stay current with regulatory changes and build the internal processes needed to meet them, without requiring an outside consultant for every update. As the Privacy Rule moves toward finalization, we’ll continue to track developments and give practical guidance on what they mean for you.

Free HIPAA Checklist
What best describes you?