HIPAA Security Rule Update Slips to 2027: Now What?

The most ambitious rewrite of the HIPAA Security Rule in two decades has slipped by more than a year. According to the latest HHS and OMB Unified Agenda, final action on the proposed update has moved from May 2026 to July 2027, a delay documented by Davis Wright Tremaine's regulatory tracking in July 2026. Combined with an extraordinary volume of industry opposition, the delay raises a real question about whether the rule will survive in anything like its proposed form.
Here is the trap: the delay changes nothing about what healthcare organizations must do today. The existing Security Rule, including its security awareness and training requirement, remains fully in force and actively enforced. Organizations that read the headline as permission to slow down are learning exactly the wrong lesson.
The Delay: Final Action Moves to July 2027
The Office for Civil Rights (OCR) published its notice of proposed rulemaking (NPRM) to strengthen the Security Rule on December 27, 2024, with formal publication in the Federal Register on January 6, 2025 (90 FR 898). It was the first comprehensive attempt to modernize the rule since 2003, motivated by years of escalating breach numbers and ransomware disruption across the sector.
The original agenda anticipated final action in May 2026. The updated Unified Agenda now targets July 2027, a slip of fourteen months. Regulatory timetables are estimates, not commitments, and a rulemaking facing this much resistance can slip again, be substantially rewritten, or be withdrawn. What healthcare compliance teams have, in practice, is at least another year of the status quo, and no certainty about what follows it.
Why More Than 100 Hospital Systems Are Pushing Back
The scale of opposition is unusual even by healthcare rulemaking standards. More than 100 hospital systems and associations, including Cleveland Clinic, Yale New Haven Health, the American Medical Association and the American Academy of Pediatrics, have formally asked HHS to withdraw the proposal, as reported by HIPAA Journal.
The objections center on cost and feasibility rather than the goals themselves. Health systems argue that the compliance burden would divert resources from care delivery, that timelines are unrealistic for organizations running decades-old clinical systems, and that smaller providers would struggle most. Whatever one thinks of those arguments, their breadth means OCR faces a choice between substantial revision and a long, contested finalization, which is precisely what the new July 2027 date reflects.
What the Proposal Would Change
The NPRM is worth understanding even in limbo, because it signals where OCR believes current practice falls short. The headline structural change: every implementation specification would become required, ending the long-standing 'addressable' category that many organizations treated, incorrectly, as optional. On top of that, the proposal would mandate, among other things:
- Multi-factor authentication across systems handling electronic protected health information
- Encryption of ePHI at rest and in transit
- Annual penetration testing
- Stronger, role-relevant security awareness training aligned to the actual risks each workforce group faces
Notice what this list is: a description of what mature healthcare security programs already do. MFA, encryption and meaningful training are also the baseline that cyber insurers now demand of healthcare applicants, as we detailed in our review of 2026 cyber insurance requirements. An organization that builds toward the NPRM is not betting on a rulemaking; it is meeting the market's floor.
The Current Rule Is Still Being Enforced
While the future rule idles, the present one has teeth. Section 164.308(a)(5) of the current Security Rule requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management. It is a live OCR enforcement item: Clearwater's analysis of 2026 enforcement activity shows the Security Rule's core administrative safeguards, training among them, continuing to feature in OCR investigations and resolution agreements.
When OCR investigates a breach, the questions are concrete. Did the workforce receive security awareness training? When, and what did it cover? Can you produce records for the individuals involved in the incident? Organizations that answer with dated, per-user completion records and evidence of ongoing reinforcement, such as phishing simulation results showing measurable improvement, are in a categorically different position from those that produce a sign-in sheet from a single annual session.
Regulatory delay is not enforcement delay. OCR does not need the 2027 rule to penalize a training program that fails the 2003 rule.
There is also a pattern worth naming: organizations that pause security improvements because 'the rule slipped' tend to repeat known failures. Phishing remains the dominant entry point for healthcare breaches, and the human layer degrades quickly without reinforcement. A one-year regulatory delay, treated as a one-year training holiday, compounds directly into breach risk that the current rule already holds you accountable for.
What This Means for Your Organization
The rational response to this delay is to use the time, not to spend it waiting. For healthcare covered entities and their business associates:
- Keep the current program running at full strength. Section 164.308(a)(5) applies today, and OCR is enforcing it today.
- Upgrade your evidence, not just your content. Per-user, dated, role-relevant training records are what an OCR investigator asks for; make producing them a report export, not an archaeology project.
- Build toward the NPRM's direction anyway. MFA, encryption and role-based training are where regulation, insurers and attackers all point; none of them get cheaper by waiting.
- Measure behavior, not attendance. Ongoing phishing simulation gives you trend data that both demonstrates effectiveness and targets follow-up where it is needed.
- Track the rulemaking without depending on it. Watch for the revised final action date and any reproposal, and be ready to adjust, from a position of strength.
The organizations that will find July 2027 easy are the ones treating 2026 as if the rule were already final. Everyone else is accumulating a gap that no Unified Agenda entry will close for them.


