Medical consultation in front of laptop

The May 2026 target for the updated final HIPAA Security Rule has come and gone. The latest projected date for final action is now July 2027.

For healthcare groups that have been preparing for the proposed changes, that delay may seem like a reason to pause. It shouldn’t be.

The regulatory timeline may have shifted, but the security expectations behind the proposed rule are already reflected in how the Office for Civil Rights (OCR) is enforcing the HIPAA Security Rule today.

The New HIPAA Security Rule Could Be a Year Away

The Department of Health and Human Services (HHS) and its Office for Civil Rights are still working through more than 4,700 public comments on the proposed updates to the HIPAA Security Rule. The latest Unified Agenda now projects final action in July 2027.

At the same time, a coalition representing more than 100 hospitals and healthcare organizations has asked HHS to withdraw the proposal entirely, citing an estimated $9 billion in first-year compliance costs.

That leaves considerable uncertainty around what happens next.

The rule could ultimately be finalized as proposed. It could be narrowed significantly. Or it could be shelved altogether.

Nobody outside OCR knows which direction the rulemaking will take.

But healthcare organizations don’t have to wait for that answer to address the security gaps that matter most.

OCR Is Already Enforcing the Principles Behind the Proposed Rule

One of the most important things to understand about the delay is that enforcement has not been postponed.

OCR is already enforcing many of the principles emphasized in the proposed rule under the HIPAA Security Rule that is currently in force.

In April, OCR demonstrated that its cybersecurity enforcement remains active, announcing four ransomware settlements totaling more than $1 million. The resolutions brought OCR’s total to 19 completed ransomware investigations and 13 completed investigations under its Risk Analysis Initiative.

Those enforcement actions did not depend on the proposed Security Rule becoming final.

They happened under the rules healthcare organizations are already required to follow, and that enforcement continues today.

Risk Analysis Isn’t Enough

Deficient risk analysis, along with failure to implement risk management based on that analysis, remains one of the most common areas of concern in OCR enforcement.

And that highlights an important distinction for healthcare organizations.

The question isn’t simply:

Did you complete a Security Risk Analysis?

The more important question is:

What did you do about what the analysis identified, and can you prove it?

A risk assessment sitting in a document repository doesn’t protect patient data. It doesn’t demonstrate that identified vulnerabilities were addressed. And it doesn’t necessarily provide the evidence an organization needs when regulators come calling.

What matters is the connection between identified risk, documented decisions, remediation, and evidence.

What Healthcare Groups Should Do Now

Rather than waiting for the final rule, organizations should focus on closing the security gaps that matter under the HIPAA requirements already in place.

That means prioritizing fundamentals such as:

  • Maintain a current, documented risk analysis that reflects your actual environment.
  • Turn risk analysis into risk management by documenting remediation, mitigation, and acceptance decisions.
  • Implement MFA for remote and privileged access wherever appropriate.
  • Maintain a real asset inventory so you know what devices, systems, applications, and data exist in your environment.
  • Test recovery capabilities rather than assuming backups will work when they are needed.
  • Validate that security controls actually operate as intended.
  • Maintain evidence demonstrating that security activities are being performed consistently.

These aren’t simply preparations for a future regulatory change. They’re no-regret security investments.

If the final Security Rule arrives in 2027, groups that have already addressed these areas will be significantly better positioned to meet whatever requirements ultimately take effect.

And if the proposed rule is narrowed or never finalized, those organizations are still in a stronger and more defensible position under the HIPAA Security Rule that OCR is enforcing today.

Evidence Over Intent

Groups with mature HITRUST programs are already familiar with this approach.

Continuous evidence, documented risk treatment, and validated controls are foundational to a mature security and compliance program. The goal isn’t simply to say that a control exists. It’s to demonstrate that the control is operating, and that the organization can produce evidence to support it.

That’s the mindset healthcare organizations should be adopting regardless of what happens with the HIPAA Security Rule.

Don’t build your security program around the regulatory calendar. Build it around the risks you’re responsible for managing.

The final rule may be delayed until July 2027. The threats facing healthcare organizations aren’t waiting, and neither is OCR’s enforcement of the requirements already on the books.

Evidence over intent, regardless of where the rulemaking calendar lands.

Get in Touch With the Mobile Mentor Team to Learn More

Andrew Reade

Andrew Reade

Andrew is our Digital Marketing Manager and oversees web-based marketing strategies and content creation for the organization. As a marketing veteran, Andrew has worked with organizations of all sizes in a diverse group of industries, from Risk Management to Transportation. Joining the organization in 2021, Andrew is based in Mobile Mentor’s Nashville, TN office.