2026 HIPAA Security Rule Update
Whatβs actually landed in healthcare IT at 90 days at Final Rule
The HIPAA Security Rule is about to undergo the most significant update since its original adoption. Expected to be finalized in May 2026, the proposed changes will introduce mandatory requirements that many healthcare organizations are not prepared to meet.
This isnβt a minor regulatory tweak. The updated rule will require mandatory annual security risk assessments, universal encryption of ePHI, multi-factor authentication across all systems, regular vulnerability scanning, and substantially more detailed compliance documentation. For organizations that have been treating HIPAA security as a periodic checkbox exercise, the compliance gap is about to get very real, very quickly.
The good news: The organizations that start preparing now will be well-positioned when the final rule takes effect. The ones that wait until after publication will be scrambling. Hereβs what you need to know.
The current HIPAA Security Rule, adopted in 2003 and largely unchanged since, was written for a different era. It predates cloud computing, telehealth expansion, AI adoption, ransomware as a business model, and the proliferation of connected medical devices. The proposed update reflects the reality that healthcare cybersecurity in 2026 bears almost no resemblance to healthcare cybersecurity in 2003.
The Office for Civil Rights (OCR) has been signaling these changes for years. Recent enforcement actions have consistently cited security risk analysis failures, inadequate access controls, and insufficient encryption as primary violations. The proposed rule essentially codifies what OCR has been enforcing through penalties and settlements.