
NOT Playing It Loose
February 10, 2026
Maryland in a Minute – June
June 11, 2026What Healthcare Organizations Should Know
On January 6, 2025, the HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) to strengthen the HIPAA Security Rule, signaling one of the most significant regulatory updates to healthcare cybersecurity requirements in decades. Although still in the proposal stage, finalization is currently anticipated around May 2026, making early preparation essential for healthcare organizations, business associates, and leadership teams.
Key Regulatory Shifts Proposed
The proposed rule would modify requirements under 45 CFR Part 164 Subpart C (HIPAA Security Rule) by tightening expectations and removing long-standing flexibility in how safeguards are implemented. Many safeguards previously labeled as “addressable” would effectively become mandatory, increasing clarity for enforcement and raising compliance expectations.
Key elements of the proposed rule include:
- Mandatory encryption of electronic protected health information (ePHI)
- Required multi-factor authentication for system access
- Formal technology asset inventories and expanded risk analysis documentation
- Routine vulnerability scanning (every six months) and annual penetration testing
- Defined response timelines, including 24-hour security incident notification and the ability to restore critical ePHI systems within 72 hours
- Strengthened business associate agreement (BAA) oversight requirements
- Required annual compliance reviews and documentation
Implementation Timeline Considerations
If finalized as proposed, organizations may have fewer than 250 days to implement substantial technical, administrative, and operational changes. For many healthcare entities, especially those without mature cybersecurity infrastructure, this timeline would be extremely compressed.
Recommended Early Preparation Steps
Organizations should treat this proposal as a strategic signal to begin readiness planning now rather than waiting for the final rule. Priority actions include:
- Conducting formal Security Risk Assessments aligned with OCR expectations
- Updating incident response and disaster recovery frameworks
- Validating asset inventories and access controls
- Strengthening vendor oversight and revising BAAs
- Enhancing workforce cybersecurity training and monitoring
Strategic Perspective
Historically, once HIPAA regulatory updates are finalized, enforcement activity accelerates quickly. Organizations that proactively align policies, safeguards, and documentation ahead of regulatory deadlines are significantly better positioned to demonstrate compliance, withstand audits, and reduce enforcement risk. Proactive preparation now will be critical for compliance readiness, operational resilience, and protection of patient data.
Julie Irvine MSHCM, BSN, RN, CCRN, CSSBB is a Healthcare Operations & Performance Improvement leader and critical care nurse with 30 years of experience driving hospital operations and advancing strategic initiatives to improve quality outcomes. She is passionate about fostering a culture of continuous improvement and is recognized for providing expert training, mentorship, and leadership in performance excellence. Julie specializes in transforming organizational culture to strengthen patient safety, enhance compliance, and ensure accreditation readiness. Her work aligns clinical operations with evidence-based practices to reduce risk, eliminate inefficiencies, and lower costs, delivering sustainable results in complex healthcare environments while promoting accountability and operational excellence.
If your organization could benefit from additional support or guidance, our team is here to help. Contact us at [email protected] to learn more about our healthcare consulting, interim support, and advisory services.

