Rule status

Is the 2026 HIPAA Security Rule update final?

Published July 24, 2026

Short answer: no. As of July 2026, the “2026 HIPAA Security Rule update” is still a proposed rule — not final, with no new deadline attached to it. The Security Rule that has been on the books for two decades remains fully in force, and that’s the one enforcement actually runs on today.

What the proposal actually is

In January 2025, HHS — the federal health department — published a proposed overhaul of the HIPAA Security Rule (90 FR 898, if you like citations). The public comment period closed in March 2025. If finalized as written, it would turn several judgment calls into explicit requirements: multi-factor authentication (a second step after your password), encryption, a written inventory of where patient data lives, and an annual written check that your business associates — the outside companies that handle patient information for you — have the required technical safeguards in place.

Those are reasonable things to do. Some of them — multi-factor authentication and encryption especially — are what a cyber-insurance application already asks about. But a proposal is not a rule.

Where it stands right now

The federal Unified Agenda — the government’s published to-do list for regulations — now files the update under “long-term actions,” with final action penciled in for around July 2027. An earlier spring-2026 target came and went without a final rule. A target is not a deadline: the update could be finalized largely as proposed, finalized in a slimmed-down form, or continue to sit. Nobody — including the vendors telling you otherwise — knows which.

Why you’ll see pages claiming otherwise

A deadline sells. Plenty of compliance-industry pages talk about the “2026 HIPAA Security Rule” as if it were final. It isn’t — it’s still a proposed rule. If a page gives you a hard 2026 date for it, that page is ahead of the facts, and you don’t need to buy anything against a deadline that doesn’t exist.

The part that’s already real: enforcement

While the proposed update waits, the enforcement arm has not been waiting. In October 2024, OCR — the federal office that enforces HIPAA — launched a Risk Analysis Initiative. Its target is one specific failure: never conducting, or never documenting, the security risk analysis the current rule already requires (45 CFR 164.308(a)(1)(ii)(A)). The initiative has produced more than a dozen enforcement actions since, including against small providers and business associates. And OCR’s 2026 guidance pushes the same lens into risk management — acting on what the analysis finds, not just filing it.

That’s the honest asymmetry: the scary-sounding 2026 update is not final, while the unglamorous requirement it builds on — a documented risk analysis — is one of the first things an investigation asks for, under the rule in force today.

What a small practice actually does with this

Skip the countdown anxiety; keep the substance. A documented security risk assessment is already required, and it’s what an investigation asks to see. It also happens to be the foundation you’d build on if the proposed update does finalize — the practices it would formalize are the ones a good assessment already asks about. Do it once, keep it dated, update it when your practice changes — and act on what it finds. If the rule finalizes, you’ll have runway and a running start instead of a scramble.

Start HIPAAPath free

Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.