HIPAA Security Rule Update: The 2026 Readiness Guide
The proposed HIPAA Security Rule update — the first major overhaul in over two decades — is still awaiting finalization at HHS, but the compliance clock will be short once it lands: roughly 240 days from publication to full compliance for most provisions. The highest-effort requirements are ones you should want anyway.
- The rule is still proposed — OCR is reviewing 4,700+ comments; the spring 2026 window passed.
- Once final: effective in 60 days, compliant in ~240 days for most provisions.
- “Addressable” disappears: encryption, MFA, asset inventory, and 72-hour recovery become required.
- Start with the asset inventory and network map — everything else depends on it.
Where the rule stands
| Milestone | Date / status |
|---|---|
| NPRM published in Federal Register | January 6, 2025 |
| Comment period closed | March 7, 2025 (4,700+ comments) |
| Final rule | Pending — no confirmed timeline |
| Effective date (if finalized) | 60 days after publication |
| Compliance date (most provisions) | 180 days after effective date — ~240 days total |
What the proposed rule actually changes
The defining shift: “addressable” implementation specifications disappear. Essentially all safeguards become required, with narrow exceptions. The headline requirements:
- Mandatory encryption of ePHI at rest and in transit.
- Multi-factor authentication across systems touching ePHI.
- Written technology asset inventory and network map tracing ePHI flows, refreshed annually and after material changes.
- Asset-based written risk analysis — closing the gap OCR cites most in enforcement.
- 72-hour restoration of critical systems, with tested incident response and contingency plans.
- Annual compliance audits, vulnerability scanning, and penetration testing.
- Business associate verification — BAs annually verify in writing, with expert attestation, that required safeguards are deployed.
- Network segmentation to limit lateral movement.
Prepare in this order (highest lead time first)
- Asset inventory and network map (start now; 3–6 months). The foundation everything else depends on — map every system that creates, receives, maintains, or transmits ePHI, including vendors.
- Encryption gap closure. Legacy databases, file shares, backups, and devices are the long pole.
- MFA to 100% of ePHI systems — with documented compensating controls where technically infeasible.
- Contingency and recovery testing. If you cannot demonstrate 72-hour restoration today, redesign backup architecture now.
- Business associate program upgrade. Template the annual attestation and update BAA language at renewal — if you are a BA, customers will demand this before the rule does.
- Rewrite the risk analysis last, on top of the finished inventory.
Don't forget the deadline already on the calendar
Separate from the Security Rule NPRM, revised 42 CFR Part 2 rules required Notice of Privacy Practices updates by February 16, 2026 for entities handling substance-use-disorder records. If that slipped past you, remediate now.
Compyl gives healthcare organizations a live asset inventory tied to controls, automated evidence collection against HIPAA safeguards, continuous monitoring for encryption/MFA/patching, and vendor workflows that operationalize BA verification — mapped once across HIPAA, HITRUST, SOC 2, and NIST CSF. Start from the Complete Guide to HIPAA Compliance for current-rule fundamentals.
Frequently asked questions
Is the HIPAA Security Rule update final?
How long will organizations have to comply once it's final?
Will encryption really become mandatory?
What changes for business associates?
Should we wait for the final rule before investing?
Get ahead of the Security Rule update
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.