OCR Delays Final Action on Proposed HIPAA Security Rule

By , | Published On: August 21, 2026

Health care providers awaiting final changes to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule may have to wait a little longer. According to Reginfo.gov, the federal government’s website for tracking regulatory actions, the anticipated date for final action on the proposed rule has been moved to July 2027.

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published its proposed HIPAA Security rule in January 2025 as part of an effort to strengthen cybersecurity protections for electronic protected health information (ePHI). Among other changes, the proposal would eliminate the distinction between “required” and “addressable” implementation specifications and establish more prescriptive cybersecurity requirements, including requirements related to encryption, network segmentation, compliance audits, and security risk analyses.

The proposal generated significant feedback from the health care industry and other stakeholders. Nearly 5,000 comments were submitted, with many commenters raising concerns about the proposed rule’s reduced flexibility and the financial and operational resources that could be required to comply with the new requirements.

Although the delay means regulated entities will have to wait longer to learn which provisions will be included in the final rule, it also provides additional time to evaluate and strengthen existing security practices. Organizations, particularly those operating with limited budgets and personnel, should consider using this time to: 

  1. Build out policies and processes to ensure that a security risk assessment happens annually;
  2. Evaluate security measures that can be implemented or strengthened by internal IT or security teams;
  3. Ensure the organization’s emergency preparedness and contingency plan addresses the backup and recovery of electronic health information;
  4.  Maintain appropriate Business Associate Agreements or Data Use Agreements for applicable vendors and contractors that have access to protected health information;
  5. Develop and implement required security training appropriate to employees’ roles and responsibilities; and
  6.  Review policies and procedures for responding to potential breaches of protected health information, including appropriate disciplinary processes when workforce members are responsible.

While the timeline for final action has changed, organizations remain subject to the current HIPAA Security Rule. The additional time before a final rule is anticipated provides an opportunity to assess existing safeguards and address potential gaps before new requirements are finalized.


Join Feldesman for our upcoming three-part HIPAA for Health Centers series:

HIPAA Privacy for Health Centers
November 2, 2026

HIPAA Security for Health Centers
November 9, 2026

Business Associates and Breaches
November 16, 2026

If you have any questions about the proposed changes or about the HIPAA Security Rule’s impact on your organization, please contact Andrea Harris and Natalie Lesnick.


Learn more about the Feldesman Team

Browse by News & Insights Category

Subscribe to Feldesman News & Resources

Archives

Federal Grant Updates:
Delivered to Your Inbox

Health Care Updates:
Delivered to Your Inbox

Education Updates:
Delivered to Your Inbox

Government Contracts Updates:
Delivered to Your Inbox

Recent Federal Grants Posts

Recent Health Care Posts

Recent Government Contracts Posts

Recent Litigation & Government Investigations Posts

Recent Client Alerts

Other Headlines

Connect with Feldesman