HIPAA Security Rule proposed update status 2026 ABA practices should use is clear: HHS still labels the January 2025 cybersecurity update a proposed rule. The HHS Security Rule history reviewed March 19, 2026 lists the proposal alongside the current rule history, and the NPRM page expressly says the current Security Rule remains in effect. Readiness work should label every proposed control accordingly.

Start with regulated-entity status

Determine whether the practice is a HIPAA covered entity, business associate, both in different activities, or outside those roles for a particular workflow. Map every place ePHI is created, received, maintained, or transmitted. The current HHS summary explains the flexible, scalable, technology-neutral current framework and warns that the regulation governs when a summary conflicts.

Document the role for each activity and relationship. A practice may act as a covered provider in one workflow and as a business associate in another. A vendor's product label supplies no answer by itself. Record the services, data, parties, contract, current legal analysis, and owner who approved the classification.

Keep the current rule as the legal baseline

Current 45 CFR 164.308 contains the administrative-safeguard standards, including risk analysis, risk management, assigned security responsibility, workforce security, information access management, training, incident procedures, contingency planning, evaluation, and business-associate arrangements. Use the full applicable rule, current guidance, and qualified counsel for the live compliance decision.

Separate the required risk analysis from the risk-management decisions that follow it. The analysis identifies potential risks and vulnerabilities to ePHI across the practice's actual environment. Risk management selects and maintains safeguards sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level under the current rule. Record the evidence, decision owner, implementation state, validation, residual issue, and next review.

Changes in systems, vendors, facilities, workforce, threats, data flows, or care operations can trigger a new assessment of affected controls. Keep the trigger beside the impacted asset and dependency. An annual calendar review can support governance, but the current decision should respond to material changes when they occur.

Label proposal items as readiness signals

The HHS proposal fact sheet describes more prescriptive proposals involving written documentation, asset and network information, periodic review, stronger authentication and encryption expectations, testing, and vendor verification. Record each item with its NPRM citation, current-rule relationship, readiness owner, cost, dependency, and final-rule recheck trigger. Never mark a proposal as an enacted universal duty.

Use three status labels: current requirement, current risk-based safeguard, and NPRM readiness item. A control may belong in more than one row when different authorities support it, but each row needs its own citation and decision. This prevents a future final rule from erasing the evidence that a safeguard was already selected under today's risk-management duty.

Prioritize controls through current risk management

A proposed status does not prevent a practice from adopting a useful safeguard. Use the current risk analysis and risk-management duties, applicable required or addressable specifications, state law, contracts, recognized security practices, and client-safety consequences to decide. Document the actual reason, implementation, validation, residual risk, and review date under the authority that applies today.

Avoid a shadow compliance program

Maintain one control register with current requirements, existing safeguards, proposed readiness items, contractual duties, state obligations, evidence, and gaps. Tag each row by authority and status. This prevents duplicate policies and helps the practice update a row when HHS publishes a final rule, changes the proposal, sets compliance dates, or withdraws an item.

Include systems, data repositories, interfaces, facilities, workforce roles, business associates, subcontractor dependencies, authentication, encryption, backup, restoration, incident response, and emergency operations. Link every high-risk workflow to a responsible person and tested evidence. A policy statement without an implemented and validated safeguard remains an open control.

Ask vendors for evidence within the real relationship

First determine whether the vendor is a business associate or subcontractor business associate for the activity. Then review the applicable agreement, permitted uses, safeguards, incident reporting, subcontractors, return or destruction, termination, and evidence rights. Product marketing or a security certificate can inform diligence while the actual relationship and current rule control the obligation.

Track vendor answers by service, environment, contract version, evidence date, exception, owner, and recheck trigger. Preserve shared-control boundaries. A practice retains responsibility for its own configuration, access, workforce use, integrations, recovery plan, and response decisions even when a vendor operates the platform.

A fictional status audit

Malik's practice locks 34 current-rule and proposal-readiness rows. Twenty-five have a classified authority, owner, evidence, validation date, and recheck trigger. Completion is 25 of 34, or 73.5%. The remaining nine stay visible. This administrative measure does not establish compliance, adequate security, legal privilege, or future final-rule content.

Malik reports the 25 complete controls by authority and keeps the nine gaps in the original denominator. He also shows how many current-rule gaps, current risk-treatment gaps, and proposal-only readiness gaps remain. Those counts guide different decisions and should never be pooled into a claim that the proposal has been implemented.

Prepare for a final-rule comparison

Keep a frozen copy of the proposal matrix, then compare it line by line with any final text. Record changes in entity scope, definitions, required and addressable structure, specifications, exceptions, effective date, compliance date, documentation, and transition rules. Update policies, contracts, systems, training, testing, and evidence only after the controlling text and implementation plan are approved.

Recheck before making a legal claim

Monitor the HHS Security Rule history and Federal Register docket. When a final rule appears, compare final text with the proposal, identify effective and compliance dates, confirm entity scope and exceptions, update the control register, test changes, and obtain required approvals. Preserve the proposal analysis as historical evidence without treating it as the final standard.

Related resources

Sources