HIPAA Security Rule overhaul pushed to July 2027 on the federal agenda
The federal Unified Agenda now lists July 2027 as the projected final action date for HHS Office for Civil Rights (OCR) rulemaking titled “HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information” (RIN 0945-AA22). The item is categorized as a long-term action.
OCR published the notice of proposed rulemaking on January 6, 2025. An earlier agenda entry had pointed to May 2026. Agenda dates are planning targets, not statutory deadlines, so the date can move again.
What is not changing today
The current HIPAA Security Rule remains in effect. Covered entities and business associates still need to run risk analysis, implement required and addressable safeguards as applicable, and meet existing Privacy and Breach Notification duties. The delay is about the proposed modernization package, not a pause on enforcement of today’s rule.
What the January 2025 proposal would have tightened
If finalized along the lines of the NPRM, the update would be the first major Security Rule rewrite since 2013. Among other items, the proposal would strengthen expectations around risk analysis, encryption, multi-factor authentication, vulnerability management, contingency planning, and business associate verification. Industry comments were extensive, and provider groups have publicly urged withdrawal or major revision.
What to do now
- Keep operating against the current Security Rule. Do not wait for 2027 to close known gaps in MFA, encryption, backup testing, or vendor oversight.
- Track both the Security Rule agenda item and any nearer-term Privacy Rule activity separately. They are related but not the same project.
- If you already gap-assessed against the January 2025 NPRM, keep that work as optional readiness, not as a compliance deadline.
- Follow HIPAA on this site (or OCR’s HIPAA pages) for a final rule, withdrawal, or further schedule change.