The New HIPAA Security Rule Is Delayed to 2027. OCR Enforcement Is Not.

The direct answer: the new HIPAA Security Rule is not final, and it is no longer expected to be final in 2026. In a Unified Agenda update reported in July 2026, HHS moved the rule to its Long-Term Actions list and pushed the anticipated final action to July 2027. That date is an estimate, not a deadline. The enforcement picture is the opposite story. OCR's Risk Analysis Initiative has reached at least 12 enforcement actions, and on April 23, 2026 OCR announced four ransomware settlements totaling more than $1 million. The rule is delayed. Enforcement is not.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
The proposed rule was published in the Federal Register on January 6, 2025. The comment period closed on March 7, 2025 with more than 4,000 comments, and a CHIME-led industry coalition petitioned HHS to withdraw the proposal entirely. HHS has not withdrawn it. It has parked it, which leaves healthcare leaders with a harder planning problem than a firm deadline would: a rule that is coming, on a date that keeps moving, while enforcement under the current rule accelerates.
This piece is about that decision problem. It is not a recap of every proposed change. We maintain a fuller HIPAA Security Rule compliance checklist for that.
Trying to decide what to move on while the rule sits in rulemaking?
Jason Lee is opening a limited number of free 30 minute HIPAA readiness reviews. Jason has spent 25+ years across cybersecurity, GRC, cloud security, and executive risk advisory.
Bring the questions your team is stuck on. You will leave with a clearer view of what to start now, what needs budget, and what can wait for the final text.
Book a Readiness ReviewWhere the rule actually stands
Here is the timeline as of August 27, 2026.
| Date | What happened |
|---|---|
| January 6, 2025 | Proposed rule (NPRM) published in the Federal Register: explicit MFA, encryption at rest and in transit, asset inventories and network mapping, annual penetration testing, and removal of the required versus addressable distinction. |
| March 7, 2025 | Comment period closed with more than 4,000 comments. A CHIME-led coalition petitioned HHS to withdraw the rule. |
| July 2026 | Unified Agenda update moved the rule to the Long-Term Actions list, with anticipated final action pushed from spring 2026 to July 2027. |
| July 2027 | Anticipated final action. An estimate, not a deadline. If finalized as proposed, publication would be followed by a 60 day effective date and a 180 day compliance window. |
Two things follow from the Long-Term Actions placement. First, that list generally signals the agency does not expect to issue a final rule within the next 12 months, so a 2026 final rule is effectively off the table. Second, no effective date and no compliance deadline exist yet. Any vendor or consultant telling you a specific compliance date is guessing.
The rule is delayed. OCR enforcement is not.
The mistake to avoid is reading the delay as a pause in obligations. OCR is enforcing the current Security Rule harder than it has in years, and the enforcement theme maps almost exactly onto what the proposed rule would formalize.
- The Risk Analysis Initiative keeps producing settlements. OCR launched the initiative in late 2024, signed 16 resolution agreements between January and August 2025, and has now announced its 11th and 12th initiative actions, one involving a substance use disorder provider and one involving a software company. The recurring deficiency is the same: no accurate, enterprise-wide risk analysis covering everywhere ePHI lives.
- Ransomware settlements landed in April 2026. On April 23, 2026, OCR announced four ransomware settlements totaling more than $1 million, covering incidents that affected over 427,000 individuals. Commentators reviewing the resolution agreements note that OCR treated the missing risk analysis and unpatched known vulnerabilities as the core violations, and that OCR now examines whether findings were actually acted on, not just whether an analysis document exists.
- 42 CFR Part 2 enforcement went live in February 2026. The compliance deadline for the Part 2 final rule was February 16, 2026. OCR announced its civil enforcement program on February 13, 2026 and began accepting complaints on February 16, 2026, which means substance use disorder treatment records now carry HIPAA-grade civil enforcement for the first time.
Put together, the enforcement record answers the "should we wait?" question. The control OCR checks first is the enterprise-wide risk analysis, and that obligation exists today under the current rule. Waiting for 2027 does not defer it.
Not sure where your risk analysis actually stands?
Start with our HIPAA Security Risk Assessment: 12 questions, 5 minutes, with a PDF report mapped to the Security Rule emailed to you.
Take the SRA →Start now, budget now, wait for final text
The delay changes the planning math less than it appears to. The runway to the final rule got longer, but the start-now bucket did not shrink, because that bucket is defined by current enforcement, not by the future rule. The useful model is still three buckets.
| Bucket | What goes here | Why it matters |
|---|---|---|
| Start now | Enterprise-wide risk analysis refresh, ePHI data flow review, MFA coverage, encryption gap review, access review, patching known vulnerabilities, incident response testing. | This is what OCR's Risk Analysis Initiative and the April 2026 ransomware settlements are enforcing today, under the current rule. |
| Budget now | Penetration testing, recurring vulnerability scanning, network mapping, backup and recovery testing, legacy system remediation, deeper vendor review. | These need people, tools, or outside support. The longer runway makes them fundable across normal budget cycles instead of an emergency spend in 2027. |
| Wait for final text | Exact policy language, final deadlines, narrow exceptions, business associate reporting details, documentation format. | These depend on the final rule, which may change after 4,000+ comments. Do not overbuild around proposed wording. |
If your last risk analysis was a lightweight questionnaire or a static annual document, that is the first place to look. Our breakdown of why spreadsheet risk assessments fail covers the common failure mode, and the same evidence that satisfies OCR is what supports a cyber insurance renewal, so the work compounds rather than duplicating. This is also where HIPAA and NIST CSF overlap heavily, which is why we map them together in HIPAA and NIST in one platform.
Business associates are already in scope
Business associates should not read the delay as breathing room. One of the two most recent Risk Analysis Initiative actions involved a software company, not a provider, and HIPAA already applies directly to any vendor that creates, receives, maintains, or transmits ePHI.
Customer pressure will also arrive before OCR does. Covered entities are translating the proposed rule and the enforcement record into their own vendor reviews now, through business associate agreements, RFPs, security questionnaires, cyber insurance renewals, and contract renewals. For healthtech, SaaS, billing, analytics, IT, and cloud vendors, HIPAA readiness becomes a revenue issue before it becomes a regulatory one. If the security story is not clear, sales cycles slow down.
Z Cyber's view
Use the delay to make the security program visible, not to shelve it. The practical work is understanding which parts of the proposed rule would create real operational effort inside your organization, which gaps are already material under the current rule and the current enforcement posture, and which items need budget before any deadline becomes official.
Z Cyber helps healthcare organizations and business associates make that concrete. The work usually starts with a focused review of the current program: risk analysis quality, ePHI data flows, MFA and encryption coverage, vendor exposure, incident response readiness, and the gap between policy language and implemented controls. You can see how we approach this on our healthcare cybersecurity page.
Jason Lee, Z Cyber's Managing Director, has spent more than 25 years across vulnerability management, GRC, cloud security, AI governance, and executive risk advisory. He is offering free 30 minute HIPAA readiness reviews for teams trying to understand where they stand while the rule is in rulemaking.
Book a free 30 minute HIPAA readiness review.
Pressure-test where you stand against current OCR enforcement and decide what should move before the final rule lands.
What to watch next
- S.3315, the Health Care Cybersecurity and Resiliency Act of 2026. Introduced in December 2025, the bill was advanced 22-1 by the Senate HELP Committee on February 26, 2026 and placed on the Senate calendar in March 2026. No floor vote has occurred as of late August 2026. If enacted, it would direct HHS toward MFA, encryption, and penetration testing requirements, meaning a statute could move faster than the delayed rule.
- The HPH Cybersecurity Performance Goals. Published in January 2024 and still voluntary, the CPGs are the blueprint HHS has repeatedly signaled it will build future mandates on. Benchmarking against the Essential CPGs now is the lowest-regret way to prepare for whatever the final rule requires.
- The next Unified Agenda update. July 2027 is the current estimate for final action. Watch whether the date holds, slips again, or the rule moves back to active rulemaking.
- OCR's enforcement cadence. The Risk Analysis Initiative is at 12+ actions and climbing. Each new settlement sharpens the picture of what OCR expects from a risk analysis today.
Related Resources
- HIPAA Security Rule: Complete Compliance Checklist for 2026
- Healthcare Cybersecurity: HIPAA + NIST in One Platform
- CIRCIA Incident Reporting: Where the Rule Stands
- Why Spreadsheet Risk Assessments Are Failing
- Cyber Insurance Readiness Guide
- AI Security Governance for Healthcare
- Take the HIPAA Security Risk Assessment
Sources
Frequently Asked Questions
Are the new HIPAA rules final in 2026?
No. The proposed HIPAA Security Rule update is not final, and it is no longer expected to be finalized in 2026. In a Unified Agenda update reported in July 2026, HHS moved the rule to its Long-Term Actions list and pushed the anticipated final action to July 2027. That date is an estimate, not a deadline. No effective date or compliance deadline exists yet for the proposed changes.
When will the new HIPAA Security Rule take effect?
There is no confirmed date. HHS currently estimates final action in July 2027, and placement on the Long-Term Actions list generally signals no final rule within the next 12 months. If the rule is finalized as proposed, publication would be followed by a 60 day effective date and a 180 day compliance window. Until the final rule is published, none of those clocks have started.
Why was the HIPAA Security Rule update delayed?
The proposal drew more than 4,000 comments before the comment period closed on March 7, 2025, and a CHIME-led industry coalition petitioned HHS to withdraw it, citing cost and feasibility concerns. In July 2026, HHS moved the rule to the Unified Agenda's Long-Term Actions list with anticipated final action in July 2027. HHS has not withdrawn the rule, and the proposal remains the clearest signal of where requirements are heading.
Should we wait for the final HIPAA rule before improving security?
No. OCR is actively enforcing the current Security Rule while the update sits in rulemaking. Its Risk Analysis Initiative has reached at least 12 enforcement actions, and on April 23, 2026 OCR announced four ransomware settlements totaling more than $1 million, covering incidents that affected over 427,000 individuals. The recurring finding is a missing or inadequate enterprise-wide risk analysis, which is required today, not in 2027.
Does HIPAA require MFA right now?
The current Security Rule does not name multifactor authentication as a universal requirement. The proposed update would make MFA explicit for systems that access ePHI, and pending legislation such as S.3315 would direct HHS toward MFA and encryption requirements as well. In practice, MFA is already expected in security reviews, cyber insurance applications, and customer questionnaires. Missing MFA on ePHI systems is a gap worth closing now.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


