There is a HIPAA Security Rule update that healthcare practices have been hearing about, often described with a confidence the actual situation does not support. It is worth being precise, because the precision is the point: this is a proposed rule. It has been published as a Notice of Proposed Rulemaking. It is contested. And as of early 2026, it is not final, and its final form is genuinely uncertain.
That precision is not a hedge. It is the correct way to read regulatory change, and a practice that understands the difference between a proposed rule and a final rule is a practice that will make better decisions than one reacting to a headline.
Here is what the proposal actually says, what would change if it is finalized substantially as proposed, and what is still genuinely unsettled.
What was actually published.
On January 6, 2025, HHS published in the Federal Register a Notice of Proposed Rulemaking titled "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information" (90 FR 898). An NPRM is exactly what its name says: a proposal, opened for public comment, that an agency may finalize, modify, or withdraw. It is not a regulation in force. HHS also published a fact sheet summarizing the proposal.
This matters for how a practice should respond. A final rule has a compliance date and an enforcement consequence. A proposed rule has a comment period and an uncertain future. The correct posture toward a proposed rule is to understand it, prepare for the likely direction, and avoid both complacency and panic. Both are easy to fall into when the proposal is described as if it were already law.
The headline change: the end of "addressable."
The single most consequential element of the proposal, and the one that drives most of the commentary, is the elimination of the distinction between "required" and "addressable" implementation specifications.
Since the Security Rule took effect, its safeguards have come in two flavors. Required specifications must be implemented. Addressable specifications must be implemented, or an equivalent alternative adopted, or a documented determination made that neither is reasonable and appropriate. In practice, "addressable" gave organizations, especially small ones, latitude to document why a safeguard like encryption at rest on workstations was not implemented.
The proposal would remove that latitude. Bradley's legal analysis of the NPRM summarizes the direction clearly: implementation specifications that were addressable would become mandatory, with limited exceptions. Encryption, multi-factor authentication, and other safeguards that many small practices have treated as discretionary under the addressable framework would, if the rule is finalized as proposed, become required.
The other proposed changes worth knowing.
The NPRM is broad. Beyond the addressable elimination, the legal analyses of the proposal flag several other significant proposed requirements:
- Asset inventory. A proposed requirement to maintain a written inventory of technology assets and a network map showing how ePHI moves through the environment.
- Network segmentation. Proposed requirements around segmenting networks to limit the blast radius of an intrusion.
- Multi-factor authentication. MFA proposed as a mandatory control rather than an addressable one.
- Encryption. Encryption of ePHI at rest and in transit proposed as mandatory, with narrow exceptions.
- Mandatory audits and testing. Proposed requirements for regular compliance audits and security testing on a defined cadence.
- Documentation and timelines. Proposed specific timeframes for restoring systems and for certain compliance activities.
If finalized substantially as proposed, this would be the most significant overhaul of the Security Rule since the original rule took effect in 2003. The direction is unambiguous: less discretion, more prescription, more documentation, more testing.
The part the headlines leave out: it is contested.
Here is the element a practice most needs to understand, and the one most often omitted from confident descriptions of "the 2026 HIPAA rule."
The proposal has drawn organized, substantial industry opposition. As HIPAA Journal reported in December 2025, more than 100 hospital systems and provider associations formally called for the withdrawal of the proposed rule, citing cost, implementation timeline, and operational burden: particularly for smaller and rural providers. That is not fringe grumbling. It is a coordinated response from a meaningful share of the regulated community during the rulemaking process.
Organized opposition of that scale does not guarantee the rule will be withdrawn or substantially softened. Agencies finalize contested rules regularly. But it does mean the proposal's final form, its compliance timeline, and even its survival are genuinely uncertain as of early 2026. A practice that has been told "the 2026 HIPAA Security Rule requires X by this summer" has been told something the regulatory record does not support. The accurate statement is: HHS has proposed X; the proposal is contested; the final rule, if finalized, may differ from the proposal in scope and timing.
What a practice should actually do about a proposed rule.
The right response to a significant proposed rule is neither to ignore it nor to treat it as settled law. It is to read the direction and prepare for it on its own merits.
Here is the useful reframe. Almost every safeguard the proposal would make mandatory (MFA enforced everywhere, encryption at rest and in transit, an asset inventory, tested backups, regular security testing) is a control a practice should arguably have regardless of whether this specific proposed rule is finalized. Cyber insurance carriers already require most of them. The current Security Rule, even with the addressable framework, expects a documented risk-based justification for not implementing them. The proposal would remove the discretion; it would not invent new controls out of nothing.
So the defensible posture is independent of the rule's final fate:
- Conduct a current, real Security Risk Analysis. This is required under the Security Rule as it exists today, proposal or no proposal. It is also the document that would tell you exactly which proposed-mandatory safeguards you are currently treating as addressable.
- Close the gaps that are good practice regardless. MFA everywhere, encryption at rest and in transit, an asset inventory, tested backups. These are defensible investments whether or not the specific NPRM is finalized as written.
- Track the rulemaking, don't react to the headline. Watch for the final rule and its actual compliance dates. Make timeline decisions based on the final rule, not the proposal.
The proposed 2026 Security Rule update is significant and worth understanding precisely. It is also proposed, contested, and not yet final. The practice that reads it accurately, preparing for the direction without mistaking the proposal for the law, is the practice that will be ready whatever the final rule turns out to say.