If you have been bracing for the biggest overhaul of the HIPAA Security Rule in twenty years, you just got a reprieve. HHS has moved final action on the proposed Security Rule update from May 2026 to a target of July 2027, shifting it to the long-term regulatory agenda. Nothing in that proposal is law today, and nothing in it is enforceable today.
The quieter development matters more in the short run: the long-pending Privacy Rule update is now expected in August 2026. That one has been sitting since 2021 and is aimed at patient access, care coordination, family and caregiver involvement, and reducing administrative burden. For a five-provider practice, a change to how fast you have to turn around a records request is a front-desk problem, not an IT problem, and it lands sooner.
The current Security Rule. Unchanged. And enforcement of it has not slowed down while the rulemaking stalls.
Two things worth knowing:
Penalties went up. HHS applied its annual inflation adjustment to HIPAA civil monetary penalties effective January 28, 2026. The top-tier annual cap for willful neglect that is not corrected now sits above $2.19 million per provision, per year.
Risk analysis remains one of OCR’s most recurring Security Rule findings. It remains the most frequently cited deficiency in OCR investigations. Not encryption. Not training. The documented, evidence-backed security risk analysis that every covered entity has already been required to perform for two decades. Small practices lose here constantly, usually because the analysis was done once, by a vendor, three EHR migrations ago, and no one has looked at it since.
The proposed Security Rule would eliminate the “addressable” category that small practices have leaned on for years. Encryption at rest and in transit becomes required. Multi-factor authentication becomes required. So do asset inventories, network maps showing where ePHI actually flows, vulnerability testing, tighter business associate oversight, and formal incident response and recovery plans.
Here is the part that gets missed. Under the proposal, a final rule would generally take effect 60 days after publication, followed by a 180-day compliance period, approximately eight months altogether. Certain existing business associate agreements could receive a longer transition period.
The delay is only useful to practices that use it.
None of that is contingent on the final rule. None of these steps needs to wait for a final rule. Risk analysis, appropriate business associate agreements, and security-incident procedures are current HIPAA obligations. Asset inventory and MFA are practical safeguards that support compliance and reduce risk, although the current rule does not mandate MFA everywhere.
Small practices tend to treat HIPAA as a periodic checkbox because the alternative feels like it requires a compliance department. It does not. It requires documentation discipline and a short list of controls applied consistently. Practices that build these habits now will be much better positioned for an eventual final rule. Practices that wait may face compressed budgeting, technology, contracting, documentation, and training work.
Regulatory target dates come from the federal Unified Agenda and are not legally binding. They have moved before and can move again. This article is general information, not legal advice.