In early July 2026, the U.S. Department of Health and Human Services (HHS) quietly moved the big HIPAA Security Rule update to its 'Long-Term Actions' agenda on the federal regulatory calendar. The new working target for a final rule is July 2027, roughly fourteen months later than the May 2026 date HHS had projected before. The Notice of Proposed Rulemaking (NPRM) came out in January 2025 and would have required things like multi-factor authentication (MFA) on every system that touches electronic protected health information (ePHI), full encryption of ePHI at rest and in transit, network segmentation, an annual penetration test, a vulnerability scan every six months, a written technology asset inventory, and a network map that shows where ePHI actually flows in your practice.
For a small practice, the delay is real breathing room, but it is not a signal to stand down. The current HIPAA Security Rule has not changed and is still fully in effect. The Office for Civil Rights (OCR) has continued to open investigations and reach settlements this year on the same handful of issues, missing or stale risk analysis, no MFA, unencrypted laptops and phones, and weak vendor oversight, that the proposed rule would have written into black-letter regulation. In other words, most of what was going to be required in 2026 is already what OCR expects you to be doing today under the existing rule.
The practical read for a one to twenty person practice is this. Do not pause the risk analysis, do not pause the MFA rollout, and do not shelve the asset inventory. Use the extra runway to spread the cost and staff time over the next several quarters instead of skipping the work. Watch the HIPAA Privacy Rule update, which is on a separate track with an August 2026 target, and re-check the federal regulatory agenda each spring and fall in case the July 2027 date moves again or the proposal is narrowed.
What to check in your practice
- Keep your risk analysis current. Refresh it at least once a year and after any material change (new electronic health record (EHR), new location, new remote access, new vendor). This is the single biggest theme in OCR settlements.
- Turn on multi-factor authentication (MFA) everywhere your team logs in to systems that touch electronic protected health information (ePHI). Start with practice email, the electronic health record (EHR), remote access, and any admin account.
- Confirm full-disk encryption on every laptop, tablet, and phone that could hold ePHI, and confirm your EHR and email use encryption in transit.
- Build a simple, one page list of every system, device, and vendor that touches ePHI. A plain spreadsheet is fine. Keep it dated.
- Watch the federal regulatory agenda. The HIPAA Privacy Rule update is targeted for August 2026 and is moving. Re-check the Security Rule timeline each spring and fall.