For more than a decade, the HIPAA Security Rule has told regulated entities to implement “addressable” safeguards — or document why they didn’t. That built-in flexibility is exactly what the U.S. Department of Health and Human Services (HHS) now says has become a loophole. On January 6, 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) in the Federal Register proposing the most significant rewrite of the Security Rule since 2013. It is important to be precise about what this is: a proposed rule, not a final one. Nothing in it is currently enforceable, and the rule could be revised, narrowed, delayed, or withdrawn before — or instead of — taking effect. This article walks through what OCR proposed, why, and what regulated entities were watching for as of 2025. It is general background information, not legal or compliance advice; organizations should consult qualified counsel for guidance specific to their situation.

Why OCR Says the Current Rule Needs an Update

The Security Rule, codified at 45 CFR Part 164, Subpart C, was built around a flexible, risk-based framework: covered entities and business associates assess their own risk and decide which safeguards are “reasonable and appropriate” for their environment. OCR’s NPRM fact sheet and preamble describe two problems with that model after two decades of experience enforcing it.

First, the volume and severity of large breaches reported to OCR — many stemming from ransomware, phishing, and unpatched systems — have climbed sharply, particularly since 2018. OCR points to this trend as evidence that voluntary, judgment-based compliance is not producing consistent baseline security across the industry.

Second, OCR has concluded that regulated entities often treat “addressable” implementation specifications as effectively optional, even though the rule never intended that reading. The agency’s stated goal with this NPRM is to close that gap by making the floor of required safeguards explicit and largely uniform, while still allowing some flexibility in how a given safeguard is implemented.

Eliminating the “Addressable” vs. “Required” Distinction

The single biggest structural change in the proposal is the removal of the addressable/required distinction that has defined the Security Rule since 2003. Under the current rule, “required” specifications must be implemented as written, while “addressable” specifications can be replaced with an equivalent alternative — or skipped entirely — if an entity documents that the specification isn’t reasonable and appropriate for its circumstances.

The NPRM would eliminate that second category almost entirely. With narrow, specifically defined exceptions, every implementation specification would become mandatory. OCR’s framing is that flexibility should remain in how an organization meets a requirement — the specific tools, configurations, and vendors it chooses — but not in whether it meets the requirement at all. For organizations that have long treated certain addressable items (like encryption of data at rest) as optional based on their own risk analysis, this is the change with the broadest practical reach.

Proposed Mandatory Technical Safeguards

Several specific technical requirements would move from “consider it” to “you must do this,” including:

  • Encryption of ePHI both at rest and in transit, with limited, defined exceptions
  • Multi-factor authentication (MFA) for access to systems that create, receive, maintain, or transmit ePHI
  • Network segmentation, to limit how far an intruder can move laterally after an initial compromise
  • Anti-malware protection deployed across the network
  • Vulnerability scanning at least every six months, and penetration testing at least annually
  • Patch management timelines tied to risk severity — proposals discussed in commentary on the rule cite windows as tight as 15 days for critical vulnerabilities and 30 days for high-severity ones

Asset Inventories, Network Maps, and Annual Audits

Beyond specific technical controls, the NPRM would require regulated entities to build and maintain a written technology asset inventory and a network map showing how ePHI moves through their systems — including where it enters, moves within, and exits the network. Both documents would need to be reviewed and updated at least annually, and sooner if there’s a material change to the environment (a new EHR module, an acquisition, a significant vendor change).

The proposal also introduces a standing obligation to verify Security Rule compliance in writing at least once every 12 months — effectively a mandatory annual self-audit against every applicable standard and implementation specification, not just a periodic risk analysis.

Business Associates Would Face More Direct Verification

The current rule relies heavily on contractual assurances — a business associate agreement that says the vendor will safeguard ePHI. The NPRM would tighten that relationship considerably. Covered entities would need written verification, at least annually, that their business associates have deployed the required technical safeguards, and commentary on the proposal describes this verification potentially requiring a subject-matter-expert analysis or formal certification rather than a signed attestation alone. Business associates would also face new obligations to notify covered entities within a short window — commentary describes 24 hours — when they activate a contingency or incident response plan.

Incident Response and Contingency Planning Get Teeth

The proposal would impose concrete, numeric expectations on disaster recovery and incident response — a departure from the current rule’s more general contingency-planning language. Provisions discussed in the NPRM and summarized by legal commentators include restoring critical systems within a defined window (72 hours has been cited), maintaining backup copies no older than a set interval, and testing incident response and contingency plans on a defined annual cadence rather than leaving the testing frequency to the entity’s discretion.

The Comment Period, Cost Estimates, and the Debate Over Burden

OCR opened a public comment period that ran through March 7, 2025 — the standard 60 days from Federal Register publication. HHS’s own regulatory impact analysis, cited in multiple legal-industry summaries of the rule, estimated first-year implementation costs across the regulated industry in the range of several billion dollars, with lower but still substantial recurring costs in subsequent years. HHS’s stated rationale is that these costs would be offset if the rule meaningfully reduces the frequency and severity of breaches industry-wide.

That cost estimate — combined with the proposed compliance timeline of 180 days after a final rule’s effective date — has drawn significant pushback. Hospital associations, health IT executive groups, and dozens of individual health systems submitted comments arguing that the rule’s costs and implementation timeline would fall disproportionately hard on smaller, under-resourced providers: rural hospitals, small physician practices, and safety-net clinics that lack dedicated security staff or capital budgets for rapid infrastructure changes. Some industry coalitions went further, formally requesting that the rule be withdrawn or substantially rewritten rather than finalized as proposed.

It bears repeating: as of this writing, HHS has not issued a final rule. The comment period has closed, but whether, when, and in what form any final Security Rule update takes effect remains genuinely open. Regulated entities watching this process should treat every specific number and requirement described here — deadlines, hour windows, cost figures — as part of a proposal that could change materially between now and any final rule.

What Regulated Entities Can Reasonably Do Now

Even with the outcome uncertain, the direction of travel is informative. Organizations that already treat “addressable” specifications as genuinely optional — skipping encryption at rest, for instance, without a documented and current risk-based justification — are in the proposal’s crosshairs regardless of whether it is finalized as written. Building or updating a technology asset inventory, testing incident response plans regularly, and confirming MFA coverage across ePHI-adjacent systems are all steps that align with cybersecurity best practice independent of any specific regulatory deadline, and they reduce exposure to breach litigation and enforcement risk under the existing rule in the meantime.

Frequently Asked Questions

Is the 2025 HIPAA Security Rule update final?

No. As of this writing, it is a Notice of Proposed Rulemaking (NPRM) published by HHS OCR in the Federal Register on January 6, 2025. The public comment period closed March 7, 2025, but HHS had not issued a final rule. Proposed requirements, deadlines, and cost figures could change before or if a final rule is issued.

What is the biggest change in the proposed HIPAA Security Rule update?

The proposal would eliminate the current distinction between “required” and “addressable” implementation specifications. With limited exceptions, nearly all specifications would become mandatory, removing the flexibility organizations previously had to skip or substitute certain safeguards based on their own risk analysis.

Would the proposed rule require encryption and multi-factor authentication?

Yes, as proposed. The NPRM would make encryption of ePHI at rest and in transit, along with multi-factor authentication for systems handling ePHI, mandatory technical safeguards rather than optional, risk-based considerations, with only narrow defined exceptions.

Why are hospitals and industry groups pushing back on the proposal?

Critics, including hospital associations and health IT executive groups, argue the proposed compliance timeline and estimated implementation costs would disproportionately burden smaller and under-resourced healthcare organizations, such as rural hospitals and small practices, that lack dedicated cybersecurity budgets or staff.

Where can I read the actual proposed rule?

The full NPRM is published in the Federal Register at federalregister.gov, and HHS OCR maintains a summary fact sheet on the proposal at hhs.gov. Reviewing the primary source is the most reliable way to track any updates as the rulemaking process continues.