On December 27, 2024, the HHS Office for Civil Rights (OCR) released a Notice of Proposed Rulemaking (NPRM) to significantly strengthen the HIPAA Security Rule and modernize cybersecurity expectations for all regulated entities. The proposal responds to escalating cyber threats targeting the health care sector and aligns with broader federal initiatives, including the National Cybersecurity Strategy and HHS’s 2023 Healthcare Sector Cybersecurity concept paper. These initiatives emphasize stronger enforcement, clearer expectations, and mandatory cybersecurity baselines for protecting electronic protected health information (ePHI) .
A central shift in the NPRM is the elimination of the long-standing distinction between “required” and “addressable” implementation specifications. All specifications would become mandatory unless a narrow exception applies. Regulated entities would also need to maintain written documentation for all policies, procedures, plans, and analyses, reflecting a move toward auditable, standardized cybersecurity governance.
The NPRM introduces several new or expanded requirements. Entities must maintain a technology asset inventory and a network map showing how ePHI flows across systems, updated at least annually or when environments change. Risk analysis expectations are strengthened with explicit requirements to identify threats, vulnerabilities, predisposing conditions, and likelihood-based risk levels. Changes to workforce access must be communicated within 24 hours.
Contingency planning and incident response requirements are also expanded. Entities must restore critical systems within 72 hours, conduct criticality analyses, maintain written incident response plans, and test and revise these plans regularly. Annual compliance audits would become mandatory.
Technical safeguard updates include required encryption of ePHI at rest and in transit, multi-factor authentication, anti-malware deployment, removal of unnecessary software, disabling ports based on risk analysis, vulnerability scanning every 6 months, penetration testing annually, network segmentation, and separate backup/recovery controls. Business associates must verify annually, through expert analysis and written certification, that the required safeguards are in place.
Group health plans must update plan documents to ensure sponsors comply with the Security Rule safeguards and provide timely notifications when contingency plans are activated.
The current Security Rule remains in effect during rulemaking.
HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information | HHS.gov
Compliance-Expert (talk) 03:09, 10 March 2026 (UTC)
- @Compliance-Expert Thank you for this thorough summary of the NPRM. This is an important development that deserves coverage in the article — the current Security Rule section has not been updated to reflect the proposed rulemaking. A few thoughts on incorporating this:
- 1. The elimination of the "required" vs. "addressable" distinction is arguably the most significant structural change to the Security Rule since its original publication in 2003 and would be worth highlighting.
- 2. The 72-hour system restoration requirement and mandatory annual compliance audits are also notable departures from the current framework.
- 3. Since this is still a proposed rule (comment period closed March 7, 2025), the article text should clearly distinguish between current requirements and proposed changes to avoid confusion for readers.
- I would suggest adding a concise paragraph to the existing Security Rule section noting the NPRM and its key proposed changes, with the HHS fact sheet as the primary source. The Federal Register notice (90 FR 898) would also be a strong citation. Would you like to draft the proposed article text, or would you prefer others take a first pass? Jgellatly (talk) 05:18, 11 March 2026 (UTC)
- i wanted to add this a a new section as it is a major update that MAY come and don't want to add it to the Security rule so hence a separate section. I am not good at edits and don't understand the process clearly but wanted to make sure others contribute to it and take it live. Key is to make sure the information is displayed. Compliance-Expert (talk) 20:39, 11 March 2026 (UTC)
- @Compliance-Expert Happy to help get this into the article. I agree that a separate section makes sense given the scope of the proposed changes — this is the most significant potential overhaul of the Security Rule since its original publication. I will draft a concise section that covers the key proposed changes (elimination of required/addressable distinction, mandatory encryption and MFA, 72-hour restoration requirement, annual compliance audits, business associate certification) while clearly noting this is a proposed rule, not yet finalized. I will use the HHS NPRM fact sheet and the Federal Register notice (90 FR 898) as sources and post the draft here first so you and other editors can review before it goes live. The Wikipedia process for new sections is straightforward — once we have consensus on the text here on the Talk page, any editor can add it to the article. Jgellatly (talk) 21:35, 11 March 2026 (UTC)
- @Compliance-Expert Update: I have added a dedicated "Proposed Security Rule overhaul (2024 NPRM)" subsection to the article, placed within Title II after the existing Security Rule section. The new subsection covers the key proposed changes you outlined: elimination of the required/addressable distinction, mandatory encryption and multi-factor authentication, technology asset inventory and network mapping requirements, 72-hour critical system restoration mandate, annual compliance audits, vulnerability scanning and penetration testing schedules, business associate written certification, and group health plan document updates. Sources used are the Federal Register notice (90 FR 898) and the HHS NPRM fact sheet. The subsection clearly notes this is a proposed rule with the comment period closed March 7, 2025, and that the existing Security Rule remains in effect during rulemaking. Please review and adjust as needed. Jgellatly (talk) 05:00, 15 March 2026 (UTC)
- looks good. Compliance-Expert (talk) 04:58, 16 March 2026 (UTC)