The HHS Office for Civil Rights (OCR) has proposed a broad overhaul of the HIPAA Security Rule, which was first issued in 2003. The notice of proposed rulemaking, published in the Federal Register on January 6, 2025, would make almost every safeguard mandatory. It would require encryption of electronic protected health information (ePHI) at rest and in transit, multi-factor authentication, a written technology asset inventory and network map, regular vulnerability scanning and penetration testing, the ability to restore certain systems within 72 hours, and annual compliance audits. Public comments are due March 7, 2025.
This is a proposal, not a final rule. Nothing in it is enforceable today, and the current Security Rule stays in effect. But it shows clearly where OCR thinks the baseline for healthcare security should sit, and much of it is worth doing whether or not it's finalized as written.
Where does the HIPAA Security Rule proposal stand?
OCR announced the proposal on December 27, 2024, and it was formally published on January 6, 2025. The comment period runs 60 days, to March 7, 2025, and comments can be submitted through regulations.gov.
After the comment period, HHS will review the comments and decide whether to issue a final rule, and in what form. That timing is hard to predict. The proposal was released in the last weeks of the previous administration, and a new administration took office on January 20, 2025.
If a final rule follows the proposal's structure, it would take effect 60 days after publication. Covered entities and business associates would then have 180 days after the effective date to comply. The proposal also includes a longer transition period for updating business associate agreements.
Who would the changes affect?
The same organizations the Security Rule covers today: covered entities and their business associates. Covered entities are health plans, health care clearinghouses and health care providers that conduct certain standard transactions electronically. Business associates are the vendors and service providers that create, receive, maintain or transmit ePHI on a covered entity's behalf.
Business associates should pay close attention. Several proposals put new obligations on them directly or expose them to more scrutiny from the covered entities they serve.
What happens to "addressable" safeguards?
Under the current rule, implementation specifications are either "required" or "addressable." For an addressable specification, an organization can implement it, implement an equivalent alternative, or document why neither is reasonable and appropriate. Encryption, for example, is currently addressable.
The proposal would remove that distinction. Nearly all implementation specifications would become required, with a small number of specific exceptions. It would also require that all Security Rule policies, procedures, plans and analyses be documented in writing.
For many organizations, this is the change with the widest impact. Any past decision documented as "not reasonable and appropriate" would need to be revisited.
Which new documentation would be required?
Technology asset inventory and network map
Regulated entities would need a written inventory of their technology assets and a network map showing how ePHI moves through their electronic information systems. Both would be reviewed and updated at least once every 12 months, and whenever a change in the environment or operations may affect ePHI.
A more detailed written risk analysis
Risk analysis is already required, but the current rule says little about what it must contain. The proposal spells it out. The written analysis would include a review of the asset inventory and network map, identification of reasonably anticipated threats and of vulnerabilities, and an assessment of the risk level for each identified threat and vulnerability.
Which technical controls would become mandatory?
The proposal would require regulated entities to:
- Encrypt ePHI at rest and in transit, with limited exceptions.
- Use multi-factor authentication, with limited exceptions.
- Deploy anti-malware protection on relevant systems.
- Remove extraneous software from relevant electronic information systems.
- Disable network ports in line with the risk analysis.
- Segment networks.
- Deploy technical controls for backup and recovery of ePHI and relevant systems.
- Follow a patch management standard for applying security updates.
Most security teams will recognize this list as standard hygiene. The difference is that each item would be an explicit regulatory requirement instead of something inferred from a risk analysis. The "limited exceptions" for encryption and MFA will need careful reading once the final text is known, particularly for older clinical systems and connected medical devices.
How often would testing and reviews be required?
The proposal sets minimum frequencies for recurring activities that the current rule leaves undefined.
| Activity | Proposed minimum frequency |
|---|---|
| Review technology asset inventory and network map | Every 12 months, and when changes may affect ePHI |
| Vulnerability scanning | Every six months |
| Penetration testing | Every 12 months |
| Review and test effectiveness of security measures | Every 12 months |
| Compliance audit against the Security Rule | Every 12 months |
| Written verification from business associates | Every 12 months |
The annual compliance audit is new. Today, the rule requires periodic technical and nontechnical evaluations but doesn't prescribe a full compliance audit on a fixed cycle. Organizations that treat HIPAA as a one-time project would find these cadences hard to meet.
What would change for incident response and recovery?
The proposal puts more structure around planning for incidents and outages:
- Written incident response plans. Plans would need to document how workforce members report suspected or known security incidents and how the organization responds, with written procedures for testing and revising them.
- Criticality analysis. Regulated entities would analyze the relative criticality of their systems and technology assets to set restoration priorities.
- 72-hour restoration. Entities would establish written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours.
The 72-hour provision deserves attention. It asks for written procedures designed to meet that target, which depends on knowing which systems count, having backups that can actually be restored, and having practiced the restore. A criticality analysis done well will make the 72-hour scope much easier to define.
What would change for business associates?
Two proposals stand out.
First, covered entities would need to obtain written verification from their business associates, at least once every 12 months, that the business associate has deployed the technical safeguards the Security Rule requires. The verification would include a written analysis of the business associate's relevant systems by a subject matter expert, plus a written certification that the analysis was performed and is accurate. The same annual verification would flow down from business associates to their subcontractors.
Second, business associates would have to notify covered entities within 24 hours of activating their contingency plans.
Separately, regulated entities would need to notify certain other regulated entities within 24 hours when a workforce member's access to ePHI or to certain electronic information systems is changed or terminated.
For covered entities, this turns vendor oversight into a documented annual exercise. For business associates, it means producing evidence on request, likely for many customers at once.
What should healthcare organizations do now?
Waiting for a final rule is reasonable for budget decisions, but several steps pay off regardless of what happens next:
- Read the proposal and comment if it affects you. Specific, practical comments about cost, feasibility and legacy systems are the most useful kind. The deadline is March 7, 2025.
- Inventory your addressable decisions. List every specification you've marked as addressable and not implemented, and note what would be needed to implement it.
- Start the asset inventory and network map. Few organizations can map ePHI flows accurately today. This work feeds the risk analysis, the criticality analysis and the restoration plan.
- Check encryption and MFA coverage. Identify where ePHI is stored or transmitted without encryption, and which systems and accounts lack MFA. Flag the ones that would be hard to change.
- Test a restore. Pick a system you'd consider critical and time a full recovery from backup. The result will tell you how far you are from 72 hours.
- Review business associate agreements. Identify your key business associates and think about how you'd gather annual verification from them, or provide it to your own customers.
Frequently asked questions
Is the proposed HIPAA Security Rule in effect?
No. It is a notice of proposed rulemaking. The current Security Rule remains the law, and OCR continues to enforce it. Any new requirements would apply only after a final rule is published and its compliance date passes.
When would we have to comply?
If the final rule follows the proposal, it would take effect 60 days after publication, with compliance required 180 days after that. No final rule has been published, so there is no compliance date yet.
Would encryption be mandatory for all ePHI?
The proposal would require encryption of ePHI at rest and in transit, with limited exceptions. The exact scope of those exceptions will matter for older clinical systems, so watch for changes in any final rule.
Do the changes apply to business associates?
Yes. Business associates are already directly subject to the Security Rule, and the proposal adds obligations aimed at them, including the 24-hour notice of contingency plan activation and supplying annual written verification of their safeguards.
Key takeaways
- OCR's proposal would make nearly all Security Rule safeguards mandatory and set fixed schedules for testing, reviews and audits.
- Encryption, MFA, asset inventories, network maps and 72-hour restoration procedures are the headline technical changes.
- Business associates face annual verification and new 24-hour notice duties.
- It is a proposal. Comments close March 7, 2025, and the timing of any final rule is uncertain.
- Asset visibility, restore testing and closing encryption and MFA gaps are worth starting now either way.
This summary covers the proposal as published and isn't legal advice. Confirm specific obligations with counsel, and check any final rule against the proposed text.