The Proposed HIPAA Security Rule Refresh: What Practices Should Do Now

HHS has proposed the first major HIPAA Security Rule update in years. Here is what the proposal signals and why adopting these controls now is a low-regret move.

In early January 2025, the Department of Health and Human Services published a Notice of Proposed Rulemaking to update the HIPAA Security Rule. It is the most significant proposed refresh of that rule in years, and it deserves attention from every practice that handles protected health information, regardless of size.

The rule is not yet final, and the details could shift before it is. But the direction is clear, and much of what it proposes is simply good security. Waiting for a final rule to act would be a mistake.

What the proposal would change

The current Security Rule distinguishes between required safeguards and those that are merely addressable, a category many organizations have treated as optional. The proposal would remove much of that flexibility and make previously addressable safeguards mandatory.

It also spells out specific controls that many practices have put off, including explicit expectations around several core protections:

  • Multi-factor authentication for access to systems that handle protected health information.
  • Encryption of protected health information both at rest and in transit.
  • A maintained inventory of the assets and systems where regulated data lives.
  • Network segmentation so a single compromised device cannot reach everything.

Why timing should not change your decision

It is tempting to treat a proposed rule as something to monitor rather than act on. But whether this specific version becomes final this year, next year, or in a modified form, the expectation it reflects is not going away. Regulators, insurers, and business partners are all moving in the same direction.

That makes these controls a low-regret investment. If you adopt them now and the rule is finalized, you are ready. If the rule changes, you have still closed real security gaps that reduce your risk today.

There is also a practical benefit to moving early. Implementing these controls under a deadline, alongside every other covered practice scrambling to do the same, is harder and often more expensive than doing the work on your own schedule. Early movers get to plan the work rather than react to it.

Start with an honest inventory

Every one of these safeguards depends on knowing where your regulated data lives. You cannot encrypt, segment, or protect systems you have not accounted for. A working asset and data inventory is the foundation the rest of the work sits on.

List the systems that store or transmit protected health information, who can access each one, and how that data moves between them. This exercise almost always surfaces surprises, from forgotten shared drives to vendor tools no one formally approved.

Close the identity and access gaps

Multi-factor authentication is the single highest-value control in the proposal, and it is achievable for any practice. Enforce it on email, remote access, and any application that touches patient data. Pair it with a review of who has access to what, and remove permissions that are no longer justified.

Encryption and segmentation follow naturally once you understand your environment. Confirm that devices and backups are encrypted, and look for ways to separate the most sensitive systems from general network traffic.

A practical path forward

You do not need to implement everything at once. A sensible sequence is to build the inventory, enforce multi-factor authentication, verify encryption on devices and backups, then plan segmentation for your most sensitive systems. Document each step so you can demonstrate a deliberate process if you are ever examined.

The proposed refresh is best understood as a preview of expectations that are already forming. Acting now turns a looming compliance deadline into work you have already finished. A managed services partner can help you sequence these controls in the order that delivers the most protection first.