Are HIPAA Security Rule changes truly “imminent”? While the federal Office of Management and Budget (the OMB) did recently include HIPAA Security Rule Changes on its agenda of rules ready for finalization, please don’t panic.
Yes, the OMB cited a May 2026 finalization date on its agenda, prompting urgent drumbeats from vendors large and small that organizations need to be ready to move NOW!
However, a few points, and reasons, to avoid a HIPAA Policies & Procedures Revision frenzy. At least for a bit longer.
First of all, the Security Rule Notice of Proposed Rulemaking (NPRM) was extensive and touched on topics that ranged from security risk analysis, to multi-factor authentication, to encryption, to termination reporting timelines, to business associate certification attestations, to phishing training – and more, lots more.
Next, per the Office for Civil Rights (the OCR), the NPRM content received over 4,500 comments. Most of those comments objected to some (or many) aspects of the proposed Rule.
And the most noticeable point, in my opinion, nearly every single commenter was negative about the proposed Rule’s compliance date – a mere 180 days after the effective date of the Final Rule. (For those who don’t know Rule arithmetic, that amounts to 240 days after Final Rule publication.) Those objectors said it was too quick. For what it’s worth, I agree.
Plus, many of those commenters felt that the proposed Rule underestimated the fiscal costs of compliance. Again, FWIW, I agree.
Final HIPAA Security Rule Prediction Summation
All this to point out that:
- We don’t know what will actually be in the Final Rule, or
- What its’ compliance date will actually be, and
- We don’t even know that the Final Rule will really be published this Spring – or this year.
So – stop. Take a deep, “I’ve got time” breath. Yes, absolutely become familiar with the NPRM proposals. There are written materials. For my part, I’ve been providing webinar content to different organizations to help this consideration and preparation process.
But, please, no – don’t rush out to buy new tools and solutions right this second, because none of us who are outside of the actual rulemaking process know what the Final Rule will really require. Don’t rush to rewrite your security policies and procedures – because we don’t yet know what the Final Rule will truly require.
So, what do I do in my HIPAA Changes webinars?
I gaze into my crystal ball, roll the dice, and prognosticate a little bit (like in this HCCA webinar clip). But also, I make clear to folks that I’m reading the tea leaves, nothing more educated than that.
For now – just breathe. And if you’d like a free copy of my recent HIPAA Changes presentation, send me an email.