Table of Contents
Federal regulators have delayed a final update to the HIPAA Security Rule until at least July 2027, marking a significant HIPAA Security Rule delay even as the agency continues work on other healthcare regulations focused on patient access and interoperability, BankInfoSecurity reported July 8.
Why the HIPAA Security Rule Delay Happened
In an updated federal regulatory agenda, the Department of Health and Human Services’ Office for Civil Rights pushed back final action on its proposed overhaul of the HIPAA Security Rule, which had previously been targeted for May 2026. This HIPAA Security Rule delay comes even as OCR still plans to finalize updates to the HIPAA Privacy Rule in August and pursue additional rulemaking related to health IT interoperability and certification requirements.
What the Delayed Update Would Have Required
The proposed Security Rule update, published in January 2025 in the waning days of the Biden administration, would substantially strengthen cybersecurity requirements for organizations that handle electronic protected health information. Among the proposed changes are eliminating the distinction between “required” and “addressable” implementation specifications, making safeguards such as multifactor authentication, encryption, vulnerability scanning and segmentation mandatory except in limited circumstances. The proposal would also require written documentation for all Security Rule policies, procedures, plans and analyses.
Industry Pushback Behind the HIPAA Security Rule Delay
According to BankInfoSecurity, OCR received nearly 5,000 public comments on the proposed Security Rule, with many healthcare organizations and industry groups arguing the requirements would be costly and difficult to implement. This volume of pushback likely contributed to the HIPAA Security Rule delay, as regulators weigh the proposal’s ambitious cybersecurity mandates against implementation concerns raised across the industry.
What Comes Next for the Privacy Rule
While the Security Rule has been delayed, OCR plans to finalize updates to the HIPAA Privacy Rule in August. The update, which dates back to a proposal issued in January 2021 near the end of President Donald Trump’s first term, is intended to strengthen patients’ rights to access their protected health information, improve information sharing for care coordination, expand family and caregiver involvement during emergencies, and make other modifications, according to the regulatory agenda.
A Separate Rule on Right-of-Access Timelines
OCR also plans to issue a proposed rule in November addressing the amount of time covered organizations have to respond to patient requests for their health information. The move follows years of OCR enforcement actions over right-of-access complaints, which the agency has said make up the largest category of HIPAA complaints it receives, a factor that adds urgency to this piece of the regulatory agenda even as the broader HIPAA Security Rule delay continues.
ONC’s Parallel Interoperability Efforts
Separately, the Office of the National Coordinator for Health IT is planning rulemaking aimed at advancing interoperability, addressing information-blocking issues, reducing certain health IT certification requirements, and expanding the use of application programming interfaces. According to the regulatory agenda, ONC also plans to remove certain longstanding certification criteria to reduce compliance burdens while allowing more flexibility for AI-enabled interoperability technologies.
What the HIPAA Security Rule Delay Means for Healthcare Organizations
With final Security Rule action now pushed to July 2027, healthcare organizations handling electronic protected health information have additional time before facing mandatory cybersecurity requirements like multifactor authentication and encryption. However, the HIPAA Security Rule delay does not mean organizations should deprioritize cybersecurity preparation, given the proposal’s clear direction toward stricter, less flexible safeguard requirements once finalized.
What to Watch Going Forward
As OCR moves forward with the Privacy Rule finalization in August and the right-of-access proposal in November, healthcare compliance teams will need to track multiple overlapping timelines simultaneously. The HIPAA Security Rule delay gives organizations breathing room on cybersecurity-specific mandates, but the broader regulatory agenda suggests HHS remains active on patient access and interoperability fronts in the near term.
