ServicesHow It WorksIndustriesResultsInsightsReactivate My List
HIPAA And Privacy

What are the new HIPAA compliance requirements for 2026?

Back to InsightsWhat are the new HIPAA compliance requirements for 2026?

What are the new HIPAA compliance requirements for 2026?

Key Facts

  • The HIPAA Security Rule overhaul was delayed from May 2026 to July 2027, per HIPAA Journal reporting.
  • February 16, 2026 is the only firm HIPAA deadline this year: updated Notices of Privacy Practices, per HHS.
  • 2025 saw a record 772 large healthcare breaches affecting roughly 138.5 million individuals, according to MetricStream's regulatory review.
  • The Change Healthcare attack exposed 192.7 million Americans' data through a portal lacking MFA, HIPAA Journal reports.
  • OCR issued 21 settlements totaling $8,330,066 in 2025 — the second-highest annual total on record, per enforcement tracking.
  • HHS estimates the proposed Security Rule would cost the industry $9 billion in year one alone, per HIPAA Journal.
  • 93% of healthcare organizations experienced a cyberattack last year, yet spend only 4–7% of IT budgets on security, per Ponemon Institute data.

What 2026 Actually Requires: The Deadline Correction Most Articles Miss

If you've been planning your HIPAA compliance calendar around a May 2026 Security Rule deadline, you're working from outdated information — and you're not alone. Most articles still circulating cite that date, but the regulatory picture has shifted significantly.

The headline change: the sweeping HIPAA Security Rule overhaul, originally targeted for finalization in May 2026, has been postponed to July 2027 according to the OMB website, as reported by The HIPAA Journal. Critically, the rule remains a Notice of Proposed Rulemaking (NPRM) — a proposal, not enforceable law. As MetricStream's analysis confirms, the May 2026 date passed with nothing published.

Industry pushback helped drive the delay. OCR received nearly 5,000 comments criticizing the 125-page rule as an "impossible mandate," and a coalition of more than 100 hospital and provider groups asked HHS to withdraw or scale it back, per industry reporting. HHS itself estimated the rule would cost the industry $9 billion in the first year and $6 billion annually for years two through five.

So what is actually confirmed for 2026? Two dates matter:

  • February 16, 2026 — the compliance deadline for the surviving Notice of Privacy Practices (NPP) modifications, after a federal court vacated most of the 2024 Reproductive Health Privacy Rule. This is confirmed by HHS's regulatory initiatives page and is the one firm, enforceable 2026 deadline.
  • August 2026 — the targeted date for a final HIPAA Privacy Rule update, per HIPAA Journal reporting. Note "targeted" — treat this as directional, not guaranteed.
  • July 2027 — the new target for the Security Rule final rule, which would eliminate "addressable" flexibility and mandate MFA, encryption, network segmentation, and defined testing cadences.

Here's the nuance that matters for clinics: delayed does not mean irrelevant. OCR's enforcement of the existing rule continues — 2025 saw 21 settlements and civil monetary penalties totaling $8,330,066, the second-highest annual total on record, according to enforcement tracking. OCR's January 2026 cybersecurity newsletter reinforces current obligations around patching, default credentials, and disabling unsecure services — obligations that apply today.

The proposed requirements also signal where enforcement is heading. One provision with direct operational impact: annual written verification of business associate safeguards, meaning a signed BAA alone won't suffice. As BD Emerson's analysis puts it, organizations "can no longer assume compliance by association." For dental, med spa, and wellness clinics that work with third-party outreach vendors, this makes vendor due diligence a near-term priority. It's why CallMyCustomers operates patient outreach under BAAs and HIPAA-aligned standards for clinic clients — verification-ready rather than paperwork-only.

The practical takeaway: update your NPP now, watch the August 2026 Privacy Rule target, and treat the proposed Security Rule safeguards as your preparation checklist — not your panic trigger.

The Proposed Security Rule: Mandatory Safeguards Coming Your Way

Even though the sweeping Security Rule overhaul has slipped to 2027, the proposed requirements tell you exactly where regulators are heading — and smart practices are treating them as a preparation checklist, not a someday problem.

The most structural change: the NPRM eliminates the "addressable" designation entirely. Under the current rule, organizations could document why they skipped certain safeguards. Under the proposal, every security control becomes mandatory regardless of practice size, shifting compliance from a checklist exercise to a continuous, technically verifiable process.

The proposed technical mandates are specific and consistent across every analysis of the rule:

  • Multi-factor authentication everywhere — for all systems that access electronic protected health information, no exceptions
  • Encryption of ePHI both at rest and in transit, aligned with NIST standards
  • Vulnerability scans at least every six months, plus annual penetration testing
  • Asset inventories and network maps showing how ePHI flows, feeding annual risk assessments and audits
  • Restoration of critical systems within 72 hours of a contingency event

The business associate requirement deserves special attention for clinics. The proposal calls for annual written verification of business associate safeguards — meaning a signed BAA alone will no longer be sufficient. Covered entities must actively validate that vendors handling patient data are actually enforcing security, not just promising it on paper. For dental, med spa, and wellness practices working with third-party outreach partners, this makes vendor due diligence an annual, documented routine. It's one reason CallMyCustomers operates patient outreach under proper privacy agreements from day one, rather than treating HIPAA as a checkbox.

Why is OCR pushing this hard? The Change Healthcare attack is the catalyst: 192.7 million Americans' records were stolen through a portal that lacked MFA. Add 2025's record year of 772 large breaches affecting roughly 138.5 million individuals, and the enforcement logic becomes clear.

Don't mistake the delay for a reprieve. Nearly 5,000 commenters criticized the 125-page rule as an impossible mandate, and a coalition of 100+ provider groups asked HHS to scale it back — but as the HIPAA trade analysis notes, OCR's enforcement pattern already reflects the direction it expects, with incomplete risk analysis remaining the most-cited deficiency in investigations. Waiting for the final text risks missing the 180-day compliance window once it lands, and rushing implementation later raises costs and breach exposure. A gap analysis against the proposed requirements is the recommended first step — the list above is your starting framework.

Why Waiting Is the Risk: Breach Data and OCR's Current Enforcement

It's tempting to read the Security Rule delay to July 2027 as permission to pause. The breach data says otherwise. 2025 was the worst year on record for healthcare data security, with 772 large breaches affecting roughly 138.5 million individuals — and enforcement of the existing rule never slowed down.

The clearest warning comes from the Change Healthcare attack, which exposed the protected health information of 192.7 million Americans. Attackers got in through a portal that lacked multi-factor authentication — the very safeguard the proposed rule would make mandatory everywhere. That incident is a big part of why OCR drafted the overhaul in the first place.

Meanwhile, OCR's enforcement activity in 2025 was the second-highest annual total on record: 21 settlements and civil monetary penalties totaling $8.3 million. The most-cited deficiency across those cases? An incomplete or outdated risk analysis. That matters because risk analysis is required under the rule as it stands today — no finalization needed.

In other words, compliance risk exists now, under the current rule, not just after the new requirements take effect. OCR's January 2026 cybersecurity newsletter reinforced that point, directing covered entities to patch systems, remove default credentials, and disable unsecure services like RDP, telnet, and FTP.

For clinics and practices that work with outside vendors — outreach partners, billing services, scheduling tools — the exposure compounds. As BD Emerson puts it, organizations can no longer assume compliance by association; they must actively validate it. That's why, for patient-facing work like reactivation and reminder campaigns, practices should confirm their vendors operate under a signed BAA and follow HIPAA and TCPA requirements — a standard CallMyCustomers applies to all dental, med spa, and clinic outreach.

The cost of waiting shows up in the numbers healthcare organizations already know too well. Consider what the sector is up against:

  • 93% of healthcare organizations experienced at least one cyberattack in the past 12 months, per Ponemon Institute data
  • 72% of those organizations reported disruption to patient care as a result
  • Healthcare spends only 4–7% of IT budgets on cybersecurity, compared with roughly 15% in finance

The CBIZ advisory team sums up the practical reality: waiting until deadlines are mandatory can raise costs, slow implementation, and increase the risk of a cyber incident. A gap analysis against the proposed safeguards — MFA, encryption, regular vulnerability scanning — is the sensible first step, and it doubles as protection against today's enforcement priorities.

The delay buys time. It doesn't lower the risk.

Your 2026 Preparation Plan: Gap Analysis to Vendor Verification

Knowing the Security Rule overhaul has slipped to July 2027 might tempt you to relax — but the one confirmed 2026 deadline is already here, and the proposed safeguards signal exactly where OCR enforcement is heading. The practices that start now will meet the final rule comfortably; the ones that wait will scramble.

Step one: run a gap analysis against the proposed safeguards. Map where you stand today on MFA, encryption, vulnerability scanning, and network segmentation. The proposed rule eliminates the required-versus-addressable distinction, making every control mandatory regardless of practice size, according to compliance advisors at CBIZ. As HIPAA Vault's analysis puts it, security is no longer about documenting intent — it's about proving technical enforcement.

Step two: update your Notice of Privacy Practices. This is the firm deadline: HHS confirms compliance with the surviving NPP modifications is required by February 16, 2026. If your NPP still reflects pre-2024 language, this comes before everything else.

Step three: audit every vendor that touches patient data. The proposed rule requires annual written verification of business associate safeguards — a signed BAA alone no longer suffices, per BD Emerson's guidance. Your gap analysis should cover:

  • MFA on every system accessing ePHI, including vendor platforms
  • Encryption at rest and in transit, aligned with NIST standards
  • Vulnerability scans every 6 months and annual penetration testing
  • Annual risk assessments with asset inventories and network maps
  • Documented annual verification from each business associate

The vendor question matters more than most practices realize. The Change Healthcare breach — which exposed 192.7 million Americans' data through a portal lacking MFA — was the catalyst for this entire rulemaking, as HIPAA Journal reports. Business associates are now squarely in scope.

This is where working with the right partners pays off. CallMyCustomers runs patient outreach for dental, med spa, and clinic clients under BAA/HIPAA agreements, with every script and message owner-approved before anything goes out — the kind of documented, verifiable arrangement the proposed annual verification requirement anticipates. And don't assume the delay means low risk: 2025 saw 21 OCR enforcement settlements totaling $8.3 million, the second-highest annual total on record, with incomplete risk analysis the most-cited deficiency, according to MetricStream's regulatory review. As HIPAA Journal's editor-in-chief warns, waiting for the final rule risks missing the implementation deadline entirely.

Frequently Asked Questions

Do I actually need to comply with the new HIPAA Security Rule in 2026?
No — the sweeping Security Rule overhaul is still a proposal, not enforceable law, and its finalization has been postponed from May 2026 to July 2027, per The HIPAA Journal. The one firm, enforceable 2026 deadline is February 16, 2026 for updated Notice of Privacy Practices language, confirmed by HHS.
If the Security Rule is delayed, can I just wait until 2027 to prepare?
Waiting is risky. OCR's enforcement of the existing rule never slowed — 2025 saw 21 settlements and penalties totaling $8.3 million, the second-highest annual total on record, with incomplete risk analysis the most-cited deficiency, according to MetricStream's enforcement tracking. Once the final rule lands, you'll only have a 180-day compliance window, so starting a gap analysis now is the safer play.
What specific safeguards would the proposed HIPAA Security Rule make mandatory?
The proposal eliminates the 'addressable' flexibility entirely, making every control mandatory: MFA on all systems accessing ePHI, encryption at rest and in transit, vulnerability scans every six months, annual penetration testing, asset inventories, and 72-hour restoration of critical systems, per CBIZ's analysis. None of this is enforceable yet, but it's the clearest signal of where enforcement is heading.
Is a signed BAA enough to cover my vendors under the new HIPAA requirements?
Under the proposed rule, no — it calls for annual written verification of business associate safeguards, meaning you must actively validate that vendors enforce security, not just promise it on paper, as BD Emerson's analysis explains. For clinics using third-party outreach partners, this makes documented vendor due diligence a near-term priority — which is why CallMyCustomers runs patient outreach under BAAs and HIPAA-aligned standards from day one.
Why is OCR pushing for these HIPAA changes in the first place?
The catalyst was the Change Healthcare attack, which exposed 192.7 million Americans' records through a portal that lacked multi-factor authentication, as reported by The HIPAA Journal. On top of that, 2025 was the worst year on record with 772 large breaches affecting roughly 138.5 million individuals.
What should my practice do first to get ready for the new HIPAA requirements?
Start with three steps: update your Notice of Privacy Practices before the February 16, 2026 deadline, run a gap analysis against the proposed safeguards (MFA, encryption, scanning cadences), and audit every vendor that touches patient data. A HIPAA Vault analysis frames the shift well: compliance is no longer about documenting intent — it's about proving technical enforcement.

The Deadline Moved. The Risk Didn't.

The 2026 HIPAA picture is clearer than most headlines suggest: the Security Rule overhaul is now targeted for July 2027, the February 16, 2026 NPP deadline is the one firm obligation on the books, and the proposed safeguards — MFA, encryption, regular vulnerability scanning, and annual vendor verification — are best treated as a preparation checklist rather than a panic trigger. What hasn't changed is the risk. With 21 OCR enforcement actions totaling $8.3 million in 2025 and incomplete risk analysis as the most-cited deficiency, compliance exposure exists under the current rule today. Start with a gap analysis, update your NPP, and audit every vendor touching patient data — including outreach partners. If your clinic runs reactivation or reminder campaigns, CallMyCustomers handles patient outreach under BAA/HIPAA agreements with every message owner-approved first, so vendor verification is one less thing to chase. Request a free list review to see exactly what compliant outreach could look like for your practice.

Stay in the Loop