
For the past year and a half, healthcare organizations have been watching the HIPAA Security Rule update inch through the federal rulemaking process, wondering whether it would arrive on schedule. Now they have their answer.
Federal regulators at the U.S. Department of Health and Human Services (HHS) have officially pushed the Final Rule back to at least July 2027 — roughly 14 months later than the May 2026 target.
The delay is real, it is official, and for many organizations it comes as a relief. But the delay does not change the day-to-day reality for anyone responsible for HIPAA compliance: the existing HIPAA Security Rule remains fully in force, OCR’s Risk Analysis Initiative is actively issuing settlements, and the cyberattack landscape that necessitated the update in the first place hasn’t slowed down. Proceed with strengthening your data security and use the proposed updates as a guide.
Moreover, the Privacy Rule is changing. A Final Rule that expands patients’ rights is expected next month.
History of the Security Rule Update
We have covered this story in two earlier posts. The short version: in January 2025, HHS published a 125-page Notice of Proposed Rulemaking (NPRM) that would be the first significant update to the HIPAA Security Rule since 2013. Among the changes:
- eliminate the distinction between “required” and “addressable” implementation specifications;
- require comprehensive technology asset inventories;
- mandate multi-factor authentication (MFA) and stronger encryption; and
- impose more prescriptive requirements for risk analysis, contingency planning, and business associate oversight.
The NPRM landed with an estimated $9 billion first-year price tag and generated nearly 5,000 public comments, many of them sharply critical, particularly from rural hospitals and small practices that argued the costs were understated and the implementation timelines were unrealistic.
In March 2026, we reported that a delay appeared likely. The administration’s deregulatory posture, combined with industry pressure and the complexity of modernizing the rule, had already made the May 2026 deadline look like a long shot.
The deadline came and went without a Final Rule. This month, the federal regulatory tracking website reginfo.gov was updated to reflect what most observers had already concluded: the final action date has been moved to July 2027, and the rulemaking has been reclassified as a “long-term action” — a designation that signals HHS does not expect to finalize the rule within the next 12 months. HHS has not issued a public explanation for the delay.
What “Long-Term Action” Actually Means
The reclassification to “long-term actions” matters beyond just the date change. Regulatory timelines in federal rulemaking are estimates, not deadlines — but where a rulemaking sits on the agency’s agenda signals how actively it is being prioritized. Moving the Security Rule update out of the near-term agenda and into long-term actions means organizations should not assume finalization is imminent, and the July 2027 date should be understood as a floor rather than a firm commitment. Some legal observers expect the rule to slip further, or to be substantially narrowed before it is finalized.
One credible theory among regulatory attorneys is that HHS may ultimately finalize only the less controversial portions of the proposal — the elements with broad support and lower implementation costs — while deferring or modifying the more contested requirements. That is speculative, but it is consistent with how the Trump administration has approached other complex regulatory undertakings.
What is not speculative is this: the Privacy Rule is moving on a different, faster track.
Privacy Rule Changes Are Coming in August
While the Security Rule waits, HHS has signaled that a Final Rule modifying the HIPAA Privacy Rule is expected next month. This Privacy Rule update has been in the works since January 2021 and has been pending far longer than the Security Rule proposal.
The Privacy Rule updates are substantially different from the Security Rule: rather than strengthening cybersecurity requirements, the Privacy Rule changes are designed to expand patient rights and reduce administrative burden.
The forthcoming Privacy Rule changes are expected to strengthen patients’ ability to access their own health information, improve information sharing for care coordination and case management, facilitate greater family and caregiver involvement, and enhance flexibilities for disclosures in emergency or threatening circumstances. HHS has also described the changes as reducing administrative burdens on covered healthcare providers and health plans.
The specifics won’t be known until the Final Rule is published.
Separately, HHS has indicated it plans to issue a new Notice of Proposed Rulemaking in November 2026 to seek public comment on modifying the timeframe for covered entities to respond to patient requests for their records — potentially shortening the current 30-day response window. Right-of-access failures remain the largest category of HIPAA complaints OCR receives, and the agency has consistently used enforcement to drive compliance.
Organizations that have been focused entirely on the Security Rule update should now begin paying attention to the Privacy Rule changes. A Final Rule in August 2026 could mean compliance obligations follow on a relatively short timeline, so teams should start shifting attention now.
The Enforcement Environment Has Not Changed
The delay in the Security Rule update does not mean OCR has stepped back from enforcement.
OCR’s Risk Analysis Initiative has continued to produce enforcement actions in 2026, with the April settlements we covered in a recent post serving as the most recent examples. For organizations, the message is clear: the obligations already in place continue to drive settlements. In each of those cases, the violation cited first and most prominently was a failure to conduct a comprehensive, accurate risk analysis — an obligation that exists under the current rule, not the proposed one.
OCR Director Paula Stannard has been consistent and direct on this point: the cost of doing nothing is very high. Her office has also expanded its enforcement focus beyond risk analysis to include risk management — meaning OCR is not only asking whether you have a risk analysis on file, but whether you are actually acting on what it finds. A stale risk analysis, or one that was completed and shelved, may provide little more protection than having none at all.
The broader cyber threat environment reinforces why this matters. The ShinyHunters extortion group has continued to target healthcare throughout 2026. The group was behind the Medtronic breach that affected 3.8 million individuals and the DentaQuest incident in which 234 gigabytes of data were published after ransom negotiations failed. These are not abstract risks — they are active and ongoing.
What to Do with Extra Time on the Security Rule
The delay gives organizations that were not yet prepared for the proposed Security Rule changes a meaningful window to close gaps. But how that time is used matters enormously. Here is where compliance professionals should focus.
Complete or update your risk analysis now. The risk analysis is the foundation of HIPAA Security Rule compliance under the existing rule, and it is where OCR enforcement consistently begins. If your organization has not completed a comprehensive, enterprise-wide risk analysis recently — or if the one you have doesn’t cover all locations where ePHI is created, received, maintained, or transmitted — this is the highest-priority item on your list and the clearest next step.
Use the proposed rule as a gap assessment tool. The proposed Security Rule requirements may not yet be final, but the direction is clear. Organizations that evaluate their current security posture against the proposed measures — multi-factor authentication, network mapping, technology asset inventories, vulnerability scanning, incident response planning — will be better positioned when the Final Rule eventually arrives and better protected in the meantime.
Watch the Privacy Rule closely. With a final Privacy Rule expected in August, compliance teams should begin reviewing patient access procedures, right-of-access response workflows, and BAA provisions related to information sharing for care coordination. For organizations, that means privacy work may need attention before the Security Rule returns. The Security Rule delay does not mean a quiet regulatory year.
Don’t let the delay become inaction. The most dangerous interpretation of this news is that the pressure is off. Use the additional runway to strengthen your security posture now, because hackers do not follow the federal regulatory calendar and OCR’s enforcement program is not on hold.
How The HIPAA E-Tool® Can Help
Whether you are working to complete your first comprehensive risk analysis, update one that has fallen out of date, or prepare for the Privacy Rule changes expected this summer, The HIPAA E-Tool® provides a structured, internally manageable path forward.
Our compliance software guides your team through the risk analysis process with the specific questions OCR expects to see answered, step-by-step instructions, and built-in support for organizations with multiple sites. You do not need an outside consultant to do this well — you need the right framework and the discipline to use it.
HIPAA is dynamic, and staying on top of change is critical for complete compliance. We can help prioritize your steps to keep your data secure and avoid enforcement.

