Compyl

HIPAA Security Rule Update: The 2026 Readiness Guide

July 08, 2026
Regulation · HIPAA

HIPAA Security Rule Update: The 2026 Readiness Guide

By Compyl ResearchUpdated July 20265 min read

The proposed HIPAA Security Rule update — the first major overhaul in over two decades — is still awaiting finalization at HHS, but the compliance clock will be short once it lands: roughly 240 days from publication to full compliance for most provisions. The highest-effort requirements are ones you should want anyway.

Key takeaways
  • The rule is still proposed — OCR is reviewing 4,700+ comments; the spring 2026 window passed.
  • Once final: effective in 60 days, compliant in ~240 days for most provisions.
  • “Addressable” disappears: encryption, MFA, asset inventory, and 72-hour recovery become required.
  • Start with the asset inventory and network map — everything else depends on it.

Where the rule stands

Milestone Date / status
NPRM published in Federal Register January 6, 2025
Comment period closed March 7, 2025 (4,700+ comments)
Final rule Pending — no confirmed timeline
Effective date (if finalized) 60 days after publication
Compliance date (most provisions) 180 days after effective date — ~240 days total

What the proposed rule actually changes

The defining shift: “addressable” implementation specifications disappear. Essentially all safeguards become required, with narrow exceptions. The headline requirements:

  • Mandatory encryption of ePHI at rest and in transit.
  • Multi-factor authentication across systems touching ePHI.
  • Written technology asset inventory and network map tracing ePHI flows, refreshed annually and after material changes.
  • Asset-based written risk analysis — closing the gap OCR cites most in enforcement.
  • 72-hour restoration of critical systems, with tested incident response and contingency plans.
  • Annual compliance audits, vulnerability scanning, and penetration testing.
  • Business associate verification — BAs annually verify in writing, with expert attestation, that required safeguards are deployed.
  • Network segmentation to limit lateral movement.

Prepare in this order (highest lead time first)

  1. Asset inventory and network map (start now; 3–6 months). The foundation everything else depends on — map every system that creates, receives, maintains, or transmits ePHI, including vendors.
  2. Encryption gap closure. Legacy databases, file shares, backups, and devices are the long pole.
  3. MFA to 100% of ePHI systems — with documented compensating controls where technically infeasible.
  4. Contingency and recovery testing. If you cannot demonstrate 72-hour restoration today, redesign backup architecture now.
  5. Business associate program upgrade. Template the annual attestation and update BAA language at renewal — if you are a BA, customers will demand this before the rule does.
  6. Rewrite the risk analysis last, on top of the finished inventory.

Don't forget the deadline already on the calendar

Separate from the Security Rule NPRM, revised 42 CFR Part 2 rules required Notice of Privacy Practices updates by February 16, 2026 for entities handling substance-use-disorder records. If that slipped past you, remediate now.

Compyl gives healthcare organizations a live asset inventory tied to controls, automated evidence collection against HIPAA safeguards, continuous monitoring for encryption/MFA/patching, and vendor workflows that operationalize BA verification — mapped once across HIPAA, HITRUST, SOC 2, and NIST CSF. Start from the Complete Guide to HIPAA Compliance for current-rule fundamentals.

Frequently asked questions

Is the HIPAA Security Rule update final?
No. As of July 2026 it remains a proposed rule. OCR is still reviewing more than 4,700 public comments and the spring 2026 finalization window passed without a final rule.
How long will organizations have to comply once it's final?
About 240 days: the rule takes effect 60 days after Federal Register publication, and most provisions require compliance within 180 days after that.
Will encryption really become mandatory?
The NPRM makes encryption of ePHI at rest and in transit a required specification, eliminating the addressable flexibility — and OCR enforcement already treats unencrypted ePHI harshly.
What changes for business associates?
BAs would verify annually, in writing with expert attestation, that required technical safeguards are deployed — and covered entities must collect those verifications. Both sides need a workflow.
Should we wait for the final rule before investing?
No. Asset inventory, encryption, MFA, and recovery capability take longer than the ~240-day window and are near-certain to survive into the final rule in some form.

Get ahead of the Security Rule update

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies