It was at the top of the list of healthcare regulatory developments for 2026. The Change Healthcare meltdown in 2024 and a spate of ransomware attacks lit a fire under HHS and the industry to tighten up the HIPAA Security Rule. A proposed updated HIPAA Security Rule was issued in January, 2025. Over 4000 public comments were submitted.
The final HIPAA Security Rule was slated to come out in the Spring or Summer of 2026. Then, without a word or announcement … HHS put the Rule on its “long-term action” list, noting that the final Rule would be delayed until July, 2027.
And that is the very earliest we are likely to see it. “Long-term action” is what it sounds like. It could be a while.
What happened? Why did HHS abandon this top regulatory project?
The HIPAA Security Rule is known for its flexibility, including its “addressable” implementation standards. That means that organizations have a lot of leeway to interpret and apply the standards in keeping with the size, scale, risk level, and other factors pertinent to their business.
The proposed Rule was going to make a lot of those “addressable” standards mandatory. And it was going to mandate measures like multi-factor authentication, encryption everywhere (at rest and in transit), testing, and more. Many in the industry were concerned about there sources that this would require, and the accompanying price tag estimated to be up to $9 billion of initial investment and significant additional resources to maintain.
It is likely that the HIPAA Security Rule update will reappear. It might be in 2027. It might be later. Ghosting regulators do not necessarily abide by the mortal rulemaking calendar.
Should your organization prepare for the Rule? I think it is always wise to tighten up security measures. However, I like to know what’s in a rulemaking, and when it will become effective, before putting a lot of time into complying with that specific rulemaking. To do otherwise can waste precious resources, including those resources designated for reducing the top legal and business risks specific to your organization.
It is possible that another significant security event or trend could accelerate the progress of the HIPAA Security Rule update. Barring that, we will have to wait and see.

