Feds delay HIPAA security rule overhaul to 2027

NEW YORK, UNITED STATES — Federal regulators have pushed the overhaul of the HIPAA Security Rule back by 14 months, with finalization now targeted for July 2027.
According to a report from Fierce Healthcare, the delay offers covered entities more runway — but does not reduce the scope of what is coming: the most sweeping update to healthcare data security requirements in over a decade.
Rule would mandate MFA and encryption
The proposed rule, published in the Federal Register on January 6, 2025, would eliminate HIPAA’s “addressable” designation and replace it with a mandatory control set: encryption of electronic protected health information (ePHI) at rest and in transit, multi-factor authentication (MFA) across all ePHI-handling systems, network segmentation, bi-annual vulnerability scanning, and annual penetration testing.
According to OCR’s regulatory impact analysis, the 2024 Change Healthcare ransomware attack — which exposed approximately 192.7 million individuals’ data — exemplifies the risks the rule is designed to address. Attackers gained access through a remote portal that lacked MFA: a control the proposed rule would now require.
OCR data shows substantial growth in breaches affecting 500 or more individuals between 2018 and 2023, underpinning the agency’s push to convert previously optional ePHI safeguards into enforceable mandates.
Once finalized, organizations will have approximately 240 days to comply — a clock that has not yet started.
Providers warn of $9 billion burden
HHS’s own regulatory impact analysis projects first-year industry compliance costs at approximately $9 billion, with annual costs of approximately $6 billion for years two through five. Industry groups contend those estimates undercount actual burdens, particularly for rural hospitals and small practices with limited margins.
A CHIME-led coalition of more than 100 organizations submitted formal concerns in December 2025, stating that a “compressed compliance window and the loss of tailoring represent core obstacles” to implementing the rule without diverting resources from patient care.
The rulemaking has moved into OCR’s “long-term actions” category on Reginfo.gov — though agency timelines carry no legal force, and finalization could still arrive ahead of or after July 2027.
A separate HIPAA Privacy Rule update remains on a faster track, with finalization scheduled for August 2026.
For healthcare outsourcing providers, the 14-month delay is a window, not an exemption. The proposed controls — MFA deployment, vulnerability scanning, asset inventory documentation, and annual compliance audits — are operational functions increasingly supported by offshore IT security and managed services teams.
Outsourcing partners with healthcare cybersecurity expertise offer covered entities and business associates a structured path to gap assessment, control implementation, and audit readiness. Organizations that begin preparation now will be better positioned when the compliance clock eventually starts.

Independent




