We were literally mid-setup on the morning of July 15 when the news dropped.

An Office of Management and Budget notice announced that the finalization of the new HIPAA Security Rule was being pushed back. Again. The revised timeline: July 2027.

The notice offered no explanation. Just a new date.

OrbitalFire CEO Reg Harnish and healthcare compliance attorney Kurt Bratten of O’Connell & Aronowitz were scheduled to present on the update that afternoon. They went ahead anyway, because a one-year delay doesn’t change what’s coming, and it doesn’t change what healthcare organizations should be doing right now. If anything, it changes the calculus in ways worth thinking through carefully.

This post is a summary of that conversation. If you’d rather watch the full session, it’s on YouTube: HIPAA Security 2.0: What to Expect from the Impending Update — Watch Now

What the delay actually means

Reg’s read on the pushback was characteristically direct:

“We just went from being late to being on time.”

For most smaller covered entities and their business associates (organizations that have been building toward HIPAA compliance without necessarily hitting every milestone), another year of runway is genuinely good news. More time to prepare, more time for OCR to clarify what they actually mean by some of these requirements, more time for the industry to adapt.

But Reg and Kurt were careful to say what the delay is not: permission to stop.

OCR is already factoring proposed-rule standards into corrective action plans right now, in 2026. Kurt has seen it firsthand: investigators asking covered entities about compliance with proposed changes before those changes are finalized. Not to fine them, but to track where the industry stands. Organizations that end up on OCR’s radar more than once tend to get less benefit of the doubt.

And enforcement overall is climbing. The number of OCR enforcement actions has been trending up sharply year over year. The Wall of Shame (the public database of declared breaches and enforcement actions) is worth bookmarking if you haven’t.

The upshot: July 2027 is when the rule finalizes. A grace period for enforcement will likely follow, as it has with prior HIPAA updates like HITECH. But the organizations that use the next year well will be in a fundamentally different position than the ones that don’t.

The five major changes coming in HIPAA Security 2.0

Some of these may still be modified before finalization, and Kurt and Reg were clear about that. But these are the themes OCR has committed to consistently throughout the rulemaking process, and they’re unlikely to disappear.

1. Continuous risk management replaces point-in-time risk analysis

This is the biggest operational change for most organizations.

The original HIPAA Security Rule required periodic risk analyses: structured reviews of where ePHI lives, what threats exist, and what controls are in place. That was a standard the industry mostly understood, even if many organizations did a poor job of it.

The updated rule shifts the model to continuous risk management. Any material change to your ePHI environment (a new cloud application, a new vendor with access to patient data, a significant organizational change) triggers a new analysis. And it’s not enough to produce a risk analysis anymore. You have to demonstrate ongoing remediation: documented assignments, accountability, evidence of progress over time.

Kurt put the baseline requirement bluntly:

“I have yet to see a single OCR investigation in which the very first request is not: give us your documented risk analyses or assessments. This is number one on the priority list for the federal regulator, and it always will be.”

If the first thing OCR asks for is your risk analysis documentation, and you can’t produce it, or what you produce shows no follow-through, that’s where examinations go sideways.

2. Addressable controls become required — including encryption

For years, HIPAA’s “addressable” standards gave covered entities flexibility. If implementing a control as written wasn’t reasonable or appropriate for your organization, you could document an alternative approach. A lot of organizations took advantage of that flexibility, especially on encryption.

That flexibility is going away. Under the proposed rule, those controls, including encryption of ePHI at rest and in transit, become fully required, no alternatives.

Kurt was direct about the impact:

“I can’t think of a HIPAA safeguard where I’ve seen clients implement a wider variety of compliance approaches than encryption… I’m unfortunately here to tell you, I think that is going away as of next summer.”

Reg added a note of hope: OrbitalFire’s position is that documented, tested, time-limited compensating controls should still be an option for organizations that genuinely cannot implement a control as specified. That’s a reasonable interpretation of good risk management. But OCR hasn’t confirmed it, and the current text of the proposed rule doesn’t carve it out.

If your encryption posture isn’t where it needs to be — this is the change to prioritize.

3. Business associate requirements tighten significantly

Change Healthcare is the case that defines this moment. Dozens of providers couldn’t bill, couldn’t get paid, couldn’t operate for weeks because of a single vendor failure. The proposed rule’s response: make covered entities formally responsible for the cybersecurity of every business associate with access to ePHI.

What that looks like in practice: formal Third Party Risk Management, questionnaires, scoring, documented review, and regular reassessment. Business associates must notify covered entities of material incidents within 24 hours. Business associate agreements will need to be refactored to reflect these obligations. And business associates themselves must provide annual attestations of compliance.

Kurt’s framing for what this means for covered entities:

“Everybody doesn’t get into the party anymore. Being able to provide a good service is not enough. They’re going to need to have security.”

The 24-hour notification requirement concerns Reg. In a real incident, useful information often isn’t available within 24 hours. He hopes OCR revisits this before finalization. But the direction (covered entities serving as the accountability layer for their vendor ecosystem) isn’t going away.

4. Contingency planning gets a hard requirement

The proposed rule includes a requirement that organizations maintain a business continuity plan capable of restoring ePHI within 72 hours. Business associates that activate their contingency plans must notify their covered-entity clients.

This is the right direction, Reg argued, and it’s aligned with how mature organizations approach operational resilience. Business impact analysis (BIA) is the methodology the rule draws on, and the OrbitalFire team runs tabletop exercises with customers specifically because practicing the response matters more than having a document.

“Wouldn’t it be nice to have the confidence that your organization has practiced responding to ransomware — or a critical third party like Change Healthcare just disappearing for months?”

The 72-hour recovery window may be adjusted in the final rule. The requirement for tested, documented contingency plans almost certainly won’t be.

5. Personal accountability — a senior officer puts their name on it

NYSDFS Part 500 already does this: a senior officer certifies annual compliance, personally. The proposed HIPAA rule appears to be moving in the same direction.

The implication, as Kurt described it: it’s not the act of signing that matters. It’s the culture change the signing is supposed to force. When a person’s name is attached to a certification, the calculus around whether the work actually got done changes.

The False Claims Act is in the background here. There’s precedent (from CMMC enforcement in the defense supply chain) for federal contractors facing personal liability when they certify compliance they can’t demonstrate. OCR is watching how that model plays out.

What we’re telling customers

The foundation hasn’t changed. The controls that make a strong HIPAA cybersecurity program (a current risk assessment, documented remediation, encrypted ePHI, tested backups, a realistic incident response plan) are the same ones they were before this rule was proposed. If you’ve been building toward compliance with the current HIPAA Security Rule, you’re building toward compliance with the update.

What changes is the bar for evidence. The era of “we have a policy” as an answer to an examiner’s question is ending. OCR wants auditable proof that you did the work, and that you held your organization accountable for following through.

Kurt’s summary of what matters most, whether the final rule arrives in 2027 or gets pushed again:

“If it isn’t documented, it wasn’t done. That is how a lot of New York state agencies view it. And it appears as though the federal government is headed in that direction.”

If you’ve been reading this and wondering where your organization stands, that’s exactly what we’re here to help figure out. We’ll be running more sessions as the rule evolves and new guidance comes out. Subscribe to the OrbitalFire CyberView Newsletter if you want to stay current.

Want to talk through how these impending changes can impact your

This post is a summary of the July 15, 2026 webinar “HIPAA Security 2.0: What to Expect from the Impending Update,” presented by Reg Harnish, CEO of OrbitalFire, and Kurt E. Bratten, ESQ, Shareholder at O’Connell & Aronowitz. Watch the Full Session.

Frequently asked questions

When does the new HIPAA Security Rule take effect?
An OMB notice issued July 15, 2026 indicates the rule is now projected to finalize in July 2027. A grace period for enforcement is expected after finalization, consistent with how prior HIPAA updates like HITECH were rolled out.

Does the HIPAA Security Rule delay mean I can wait until 2027 to start preparing?
No. OCR is already asking covered entities under investigation about compliance with proposed-rule standards, even before those standards are finalized. Organizations that are building toward compliance now will be in a fundamentally different position than those who wait.

What are the addressable controls that are becoming required?
Addressable controls were HIPAA provisions that allowed covered entities to use documented alternatives when implementing the control as written wasn’t reasonable. Under the proposed rule, those controls, including encryption of ePHI at rest and in transit, become fully required, with no alternatives.

How does the update affect business associates?
Business associates will face tighter requirements: 24-hour incident notification to covered entities, annual attestation of compliance, and coverage under formal Third Party Risk Management programs conducted by their covered-entity clients. Business associate agreements will need to be updated to reflect the new obligations.

What should smaller healthcare organizations focus on right now?
Three areas: update your risk assessment to reflect your current ePHI environment and document a remediation plan with follow-through; review your encryption posture and close gaps; and examine your business associate roster with the question “would they survive a real Third Party Risk Management review?”