Federal regulators have delayed the most sweeping rewrite of the HIPAA Security Rule in two decades, giving healthcare providers and their business associates, including agencies that collect on medical debt, at least another year before new cybersecurity mandates arrive.
The Department of Health and Human Services’ updated 2026 regulatory agenda shows the Office for Civil Rights (OCR) will not take final action on the proposed overhaul until at least July 2027, a year past the previous May 2026 target. The proposal, published in January 2025 in the closing weeks of the Biden administration, drew nearly 5,000 public comments, with hospitals and industry groups arguing the requirements were too costly and the implementation timeline unworkable. HHS itself pegged first-year industry compliance costs at $9 billion, with $6 billion annually for the following four years.
Why it matters: The proposed rule would eliminate the longstanding distinction between “required” and “addressable” safeguards, making encryption, multifactor authentication, network segmentation, vulnerability scans every six months and annual penetration testing mandatory with limited exceptions. Those obligations reach business associates, a category that includes collection agencies handling electronic protected health information on behalf of providers. Business associates would also face annual verification of their technical safeguards by a subject matter expert and 24-hour notification requirements, obligations that flow down to their subcontractors.
The delay is relief, not repeal. Regulatory timelines are not binding, and observers see further slippage as likely. Rachel Seeger, a former longtime OCR adviser, noted the agency can push multifactor authentication, encryption and basic cyber hygiene through guidance without waiting on a multi-year rulemaking. Regulatory attorney Kirk Nahra of WilmerHale said the proposal’s prescriptive, one-size-fits-all standards marked a sharp break from HIPAA’s traditionally flexible approach, and pointed to tension between the administration’s deregulatory posture and its concerns about health data security.
The pressure is not hypothetical. The February 2024 Change Healthcare ransomware attack, which exposed data on an estimated 192.7 million Americans, began with stolen credentials on a remote access portal that lacked multifactor authentication.
What’s next:
OCR is prioritizing a final rule updating the HIPAA Privacy Rule, now slated for August 2026, that would strengthen patients’ rights to access their records and ease information sharing for care coordination. A separate November 2026 proposal would tighten response deadlines for patient records requests, likely below the current 30-day window. Right-of-access violations remain OCR’s largest complaint category and an active enforcement priority, a signal worth noting for any agency that touches provider record workflows.




