Blog|Articles|July 24, 2026

Plot twist: HIPAA Security Rule final rule postponed, HIPAA Privacy final rule imminent

Fact checked by: Keith A. Reynolds

The HIPAA Security Rule won't be final until July 2027, but the HIPAA Privacy Rule's final rule is expected in August 2026.

The number of podcasts and webinars touting the “new HIPAA Security Rule” is mind numbing and inaccurate. It’s inaccurate because the Final Rule has not been issued yet and it will not be released until July 2027. In January 2025, the U.S. Department of Health and Human Services – Office for Civil Rights (HHS-OCR) published in the Federal Register a notice of proposed rulemaking (NPRM) to refine the Health Information Portability and Accountability Act of 1996 (HIPAA) Security Rule and to reiterate, the Final Rule is slated to be published a year from now. (90 Fed. Reg. 898 (Jan. 6, 2025)).

As inveigling as getting ahead of the curve and just implementing the NPRM items now, whether sua sponte or from an advisor, unnecessary overspending can arise, as changes could also occur, which often do, between the NPRM and Final Rule. Having said that, there are some proposed items that can be adopted including: (1) multi-factor authentication; (2) treating all requirements as either “standard” or “required”; and (3) focusing on how artificial intelligence intersects with the proposed Security Rule refinements/additions, as well as the HIPAA Privacy Rule’s Final Rule, which is anticipated to be released in August 2026.

The Final Rule - HIPAA Privacy Rule: Changes to Support Coordinated Care and Individual Engagement and Reduce Regulatory Burdens seeks to build on the notions of “strengthen[ing] individuals’ rights to access their own protected health information, including electronic information; improve information sharing for care coordination and case management for individuals; facilitate greater family and caregiver involvement in the care of individuals experiencing emergencies or health crises;” [and] other related patient disclosure considerations. Two notable items related to the Americans with Disabilities Act (ADA) are utilizing telecommunications relay services by individuals and workforce members of HIPAA covered entities and business associates that are deaf, hard of hearing, deaf-blind, or who have a speech disability.”

As HIPAA continues to evolve, so healthcare industry participants should stay abreast of proposed and actual changes. Being too preemptive can result in excessive costs and regulatory non-compliance, instead of the intended result.

Rachel V. Rose, J.D., MBA, advises clients on compliance, transactions, government administrative actions and litigation involving health care, cybersecurity, corporate and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases. She also teaches bioethics at Baylor College of Medicine in Houston. Rose can be reached through her website, www.rvrose.com.