
What are the most recent HIPAA changes?
Key Facts
- Large HIPAA breach reports jumped 102% from 2018 to 2023, while affected individuals surged 1,002% according to OCR data.
- Over 167 million people were affected by large health data breaches in 2023 alone — a record high per HHS figures.
- The proposed HIPAA Security Rule would require encryption, MFA, vulnerability scans every 6 months, and annual penetration testing per the HHS fact sheet.
- HHS estimates first-year compliance costs for the new Security Rule at roughly $9 billion per industry analysis.
- A Texas court vacated the 2024 Reproductive Health Privacy Rule in June 2025, but NPP updates are still due February 16, 2026 per HHS.
- The expected August 2026 Privacy Rule would cut patient PHI access timeframes from 30 days to 15 per HIPAA Journal.
- Once finalized, the Security Rule becomes effective in 60 days with compliance required 180 days later per regulatory analysis.
The Regulatory Landscape: Why HIPAA Is Shifting Now
For over a decade, HIPAA remained largely unchanged — the Security Rule hadn't seen significant updates since 2003, and the last major overhaul arrived with the 2013 Omnibus Final Rule. That stability has shattered. Two major rulemakings now converge: a Privacy Rule final rule expected in August 2026 and a Security Rule Notice of Proposed Rulemaking issued in January 2025. The catalyst isn't abstract; it's measurable. Large breach reports jumped 102% from 2018 to 2023, while the number of individuals affected surged 1,002% over the same period, driven primarily by hacking and ransomware. In 2023 alone, over 167 million people were impacted — a new record.
The proposed Security Rule marks a fundamental shift from flexible, scalable guidance to prescriptive, mandatory technical standards. Where the current rule allows organizations to determine "reasonable and appropriate" safeguards, the NPRM would require encryption of ePHI at rest and in transit, multi-factor authentication, vulnerability scans every six months, penetration testing annually, and yearly compliance audits. Restoration of critical systems would need to happen within 72 hours, and workforce access changes or contingency plan activations would trigger 24-hour notification deadlines. These requirements align directly with the Biden Administration's National Cybersecurity Strategy and HHS's Healthcare Sector Cybersecurity concept paper, signaling that healthcare cybersecurity is now a national priority.
- Privacy Rule final rule expected August 2026 — shortening PHI access from 30 to 15 days
- Security Rule NPRM issued January 2025 — mandatory encryption, MFA, and defined testing schedules
- Reproductive health rule vacated June 2025 — partial NPP requirements survive with February 16, 2026 deadline
- 42 CFR Part 2 aligned with HIPAA in 2024 for Substance Use Disorder records
For CallMyCustomers clients in dental, med spa, and wellness clinics, these changes aren't theoretical. Reactivation campaigns that touch patient lists operate under BAAs and clinical-grade privacy standards, and the tightening access window — down to 15 days with a maximum 30-day total — means any process involving PHI requests must accelerate. The February 16, 2026 deadline for updated Notices of Privacy Practices is already fixed, regardless of the Security Rule's final timeline. HHS estimates first-year compliance costs across regulated entities at approximately $9 billion, with several billion more annually thereafter — a figure that underscores the scale of operational change ahead. The current Security Rule remains in effect during rulemaking, but early adoption of asset inventory and MFA enforcement is the practical starting point every expert recommends.
Privacy Rule Overhaul: Faster Access, Fewer Burdens
The proposed Privacy Rule changes aim to streamline patient access while reducing administrative burdens on providers. A key provision shortens the timeframe for providing protected health information (PHI) from 30 days to 15 days, with extensions capped at 15 days, resulting in a maximum total of 30 days according to industry analysis. This change responds to longstanding concerns about delays in patient access to their own health records.
Additionally, the rule eliminates the requirement for written acknowledgment of receipt of the Notice of Privacy Practices (NPP), simplifying a process that has often been seen as perfunctory per regulatory updates. The definition of healthcare operations is also expanded to include activities like case management and care coordination, reflecting evolving care delivery models. Furthermore, covered entities will be required to make their fee schedules for providing PHI copies publicly available, increasing transparency for patients as noted in recent commentary.
These adjustments will directly impact how healthcare providers manage patient information requests. Workflows for handling access requests will need to accelerate significantly, requiring staff training and potentially updated technology to meet the tighter deadlines as experts highlight. Providers must also revise NPPs and update business associate agreements to align with the expanded healthcare operations definition and fee transparency rules. For organizations like CallMyCustomers that support healthcare clients with patient outreach, understanding these shifts is essential to ensure any reactivation or engagement campaigns remain compliant when handling protected information. Preparing now—by reviewing request timelines, training teams, and updating documentation—will help mitigate disruption when the final rule takes effect.
Security Rule Modernization: From Flexible to Mandatory Standards
The HHS is proposing a significant modernization of the HIPAA Security Rule, shifting from flexible guidelines to prescriptive, mandatory cybersecurity standards. This change reflects the escalating threat landscape, with large breach reports increasing 102% from 2018–2023 and individuals affected by large breaches rising 1,002% over the same period, largely due to hacking and ransomware attacks. OCR data underscores the urgency for stronger safeguards across the healthcare sector.
Under the proposed rule, covered entities and business associates would be required to implement specific technical controls, including mandatory encryption of ePHI both at rest and in transit, and enforcement of multi-factor authentication for system access. Vulnerability scans would need to occur every six months, with penetration testing conducted annually, and organizations must restore critical electronic information systems within 72 hours of a disruption. Workforce access changes, such as terminations or role modifications, would trigger a 24-hour notification requirement to prevent unauthorized access. Additionally, annual compliance audits would become mandatory to verify ongoing adherence to these standards.
These prescriptive measures aim to align HIPAA security requirements with modern cybersecurity best practices and federal initiatives like the Biden Administration's National Cybersecurity Strategy. HHS estimates first-year compliance costs across regulated entities at approximately $9 billion, with several billion more annually thereafter, reflecting the scale of investment needed to meet the new benchmarks. Industry analyses suggest the rule, if finalized in 2025, could take effect in late 2026 or early 2027, though the current Security Rule remains in force during the rulemaking process. Experts advise a phased approach, beginning with asset inventory and MFA implementation to build foundational security posture.
For service businesses like those supported by CallMyCustomers—particularly dental clinics, med spas, and wellness providers handling ePHI—these changes highlight the growing importance of robust security protocols in patient outreach and data management. Ensuring that reactivation campaigns operate within compliant frameworks, from secure data handling to timely breach response, will be critical as these standards evolve. Proactive preparation now can help healthcare clients navigate the transition smoothly while maintaining trust and continuity in patient relationships.
Reproductive Health Rule Vacatur and the February 2026 NPP Deadline
Few areas of HIPAA have shifted as dramatically — or as confusingly — as reproductive health privacy. A single Texas court decision in June 2025 wiped out an entire federal rule, yet part of it still lives on with a hard compliance deadline in February 2026.
The Biden-era HHS published the Reproductive Health Privacy Rule on April 26, 2024 (89 FR 32976), restricting the use and disclosure of PHI for reproductive health care purposes. On June 18, 2025, a Texas court vacated the rule nationwide, invalidating its core provisions across the country. HHS has stated only that it "will determine next steps after a thorough review of the court's decision," leaving covered entities in regulatory limbo.
Here's where it gets complicated. While the broader rule was struck down, certain Notice of Privacy Practices modifications survived the vacatur. Covered entities must still comply with these surviving NPP requirements by February 16, 2026, despite the underlying rule's invalidation.
What that means in practice:
- Review and update NPPs to reflect the current legal status of reproductive health privacy provisions
- Remove or revise any language tied to vacated provisions before the February 16, 2026 deadline
- Coordinate with legal counsel to confirm which requirements apply post-vacatur
- Retrain staff on what the NPP now says — and doesn't say
For dental practices, med spas, and wellness clinics, the vacatur doesn't eliminate the compliance work — it changes it. The surviving NPP requirements still demand action, even though the rule that created them is gone. Practices that assumed the court decision ended their obligations risk finding themselves non-compliant in February 2026.
This is also a moment to verify that patient-facing communications stay aligned with your updated NPP. Vendors handling patient outreach — including reactivation partners like CallMyCustomers, which operates under BAA/HIPAA agreements for clinic clients — should be looped in so every message reflects the current privacy posture. When a practice's notice changes, its communication practices should change with it.
The broader lesson from the reproductive health rule saga: HIPAA compliance is no longer static. Between this partial vacatur, the expected August 2026 Privacy Rule finalization, and pending Security Rule modernization, covered entities face a regulatory landscape that can shift with a court ruling or a Federal Register notice. Treat your NPP as a living document — because right now, it has to be.
Preparation Roadmap: What Healthcare Businesses Should Do Now
With two major HIPAA rulemakings moving at once and deadlines already locked in, the smartest move healthcare businesses can make is to start preparing now — before the rules become mandatory. Industry experts put it plainly: the proposed Security Rule updates "shouldn't be scary. They're just catching up with modern security practices," and the best approach is to "chip away at it one step at a time" (HIPAA Vault).
Phase 1: Build your security foundation. Begin with a full asset inventory and enforce multi-factor authentication across your systems — experts recommend these as the first priorities because both are likely to become mandatory under the proposed Security Rule. Remember, the current Security Rule remains in effect during rulemaking, so there's no reason to wait.
Phase 2: Tighten your patient communication timelines. The expected Privacy Rule final rule, anticipated in August 2026, would shorten the PHI access timeframe from 30 days to 15 days, with extensions also cut to 15 days (30 days maximum total). Audit every process that touches patient information requests — including how your practice handles outreach and follow-up communications — and identify bottlenecks now.
Phase 3: Update your Notice of Privacy Practices by February 16, 2026. Although the 2024 Reproductive Health Privacy Rule was vacated by a Texas court in June 2025, HHS confirms partial NPP requirements survived and compliance is required by this date. This is the nearest hard deadline on the calendar.
Phase 4: Prepare for Security Rule compliance. Once finalized, the rule becomes effective 60 days after publication, with compliance required 180 days later — roughly 240 days total. HHS estimates first-year compliance costs near $9 billion, so budgeting early matters.
Your preparation checklist:
- Complete an asset inventory and enforce MFA organization-wide
- Map patient request workflows against the 15-day access standard
- Revise NPPs before the February 16, 2026 deadline
- Schedule vulnerability scans every 6 months and penetration tests annually
- Plan for 72-hour restoration and 24-hour notification requirements
For practices that rely on outside partners — whether billing vendors or patient reactivation services like CallMyCustomers — verify that business associate agreements reflect current requirements, since BAAs must be updated within one year of the rule's effective date. The practices that treat this as a phased project, not a last-minute scramble, will face August 2026 with confidence instead of panic.
Frequently Asked Questions
When is the new HIPAA Privacy Rule expected to be finalized?
What are the key cybersecurity requirements proposed in the updated HIPAA Security Rule?
Is the February 16, 2026 deadline for updating Notices of Privacy Practices still in effect after the reproductive health rule was vacated?
How much will HIPAA Security Rule compliance cost healthcare organizations in the first year?
What should healthcare businesses do now to prepare for upcoming HIPAA changes?
Does the current HIPAA Security Rule still apply while the new rule is being finalized?
Compliance Is a Moving Target — Aim Ahead of It
The message running through every recent HIPAA change is clear: the era of flexible, set-it-and-forget-it compliance is over. With PHI access windows shrinking to 15 days, the Security Rule shifting from guidance to mandatory technical standards, and the February 16, 2026 NPP deadline already locked in — despite the reproductive health rule's vacatur — healthcare businesses can't afford to wait for final rules to start preparing. The breach numbers explain why: over 167 million individuals were affected by large breaches in 2023 alone, a record high according to OCR data. Start with an asset inventory and MFA, map your patient request workflows against the tighter timelines, and update your notices before the deadline. And if patient outreach is part of your growth strategy, make sure your partners are part of that preparation — CallMyCustomers runs clinic reactivation campaigns under BAA/HIPAA agreements with every message owner-approved, so compliance and repeat revenue move forward together. Ready to see what your patient list could produce? Get a free list review before you spend a dollar.