HIPAA

HHS Has Proposed the First Real Rewrite of the HIPAA Security Rule Since 2013

Key Takeaways

  • The proposal is at 90 FR 898, published 6 January 2025 under RIN 0945-AA22; the comment period closed on 7 March 2025
  • It would remove the distinction between required and addressable implementation specifications and make all of them required, with limited exceptions
  • New standards would cover technology asset inventories, network maps, encryption of ePHI at rest and in transit, multi-factor authentication and a compliance audit every 12 months
  • HHS estimated first-year costs of roughly $9 billion, and about $6 billion annually in years two through five
  • No final rule has been published. The Unified Agenda lists the rulemaking as a long-term action with a projected final action date of July 2027

What Was Proposed, and What It Is Not

On 6 January 2025 the Office for Civil Rights (OCR) at the Department of Health and Human Services published a notice of proposed rulemaking titled “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information.” It appears at 90 FR 898, runs to 125 pages of the Federal Register, and carries RIN 0945-AA22. The document is styled a notice of proposed rulemaking and notice of Tribal consultation.

That status is the single most important fact about it. A proposed rule states what an agency is considering and invites comment on it; it does not change the Code of Federal Regulations and it imposes nothing on anyone. Everything described below is a proposal that HHS put out for comment. The Security Rule in force today is the one codified at 45 CFR part 160 and subparts A and C of part 164, unchanged by this document.

Comments were due by 7 March 2025, and a Tribal consultation meeting was held on 6 February 2025. Comments were filed under docket HHS-OCR-2024-0020 on regulations.gov.

Why HHS Reopened the Security Rule

The Security Rule was published in 2003 (68 FR 8334) and last substantially revised in 2013 (78 FR 5566), when it was extended to apply directly to business associates. In the NPRM, HHS said it considered modification appropriate to address significant changes in technology, changes in breach trends and cyberattacks, OCR's own enforcement experience, other published cybersecurity guidelines and best practices, and court decisions affecting enforcement of the rule.

The document also situates the proposal against the designation of Healthcare and Public Health as a critical infrastructure sector, with HHS as the Sector Risk Management Agency. HHS noted that several states have promulgated or are developing their own security regulations, and said none focus specifically on ePHI and the information systems that handle it.

Removing the Addressable and Required Distinction

The existing rule sorts implementation specifications into two categories. Required specifications must be implemented. Addressable specifications must be assessed, and implemented where reasonable and appropriate; where they are not, the entity documents why and implements an equivalent alternative measure if reasonable and appropriate. HHS introduced that structure in the 2003 final rule to add flexibility.

The NPRM states that the Department “proposes to remove the distinction between required and addressable implementation specifications and make all implementation specifications required, with specific, limited exceptions.” HHS wrote that it must “squarely confront the problem of regulated entities treating addressable implementation specifications as optional,” and that the addressability feature provided a level of flexibility it now believes inadequate. The document notes that a commenter asked HHS to remove the addressable designation in 2013 and that the Department declined at the time out of concern for scalability.

Asset Inventories and Network Maps

The NPRM observes that while the current regulatory text does not say so expressly, an accurate and thorough risk analysis already requires an entity to inventory its technology assets and determine how ePHI moves through its systems. The proposal would put both in the regulatory text as express obligations: a written inventory of technology assets, and a network map showing the movement of ePHI through the entity's electronic information systems, including how ePHI enters and exits those systems and is accessed from outside them.

Under a proposed maintenance specification at 45 CFR 164.308(a)(1)(ii)(C), an entity would review and update the inventory and the map on an ongoing basis but at least once every 12 months, and again whenever a change in its environment or operations may affect ePHI. The NPRM gives examples of such a change: adopting new technology assets, upgrading or patching them, newly recognised threats, a sale or merger, a security incident, and relevant changes in federal, state, Tribal or territorial law.

Encryption and Multi-Factor Authentication

Encryption is currently an addressable implementation specification under the access control standard at 45 CFR 164.312(a)(2)(iv). The proposal would move it into its own standard: proposed 45 CFR 164.312(b)(2) would require regulated entities to encrypt all ePHI at rest and in transit, subject to limited exceptions, each of which would apply only to the ePHI directly affected and only where the entity documents the circumstances. The NPRM states that HHS was not proposing to define “prevailing cryptographic standards” in regulatory text.

The proposal would add a definition of multi-factor authentication, to be applied when meeting a proposed authentication requirement at 45 CFR 164.312(f)(2)(ii). The definition would call for verification of at least two of three categories of factors: information known by the user, such as a password or PIN; an item possessed by the user, such as a token or smart card; and a personal characteristic of the user.

A Compliance Audit Every Twelve Months

Proposed 45 CFR 164.308(a)(14) would add a new standard for compliance audits, under which a regulated entity would perform and document an audit of its compliance with each standard and implementation specification of the Security Rule at least once every 12 months. The NPRM acknowledges that the Security Rule does not currently require internal or third-party compliance audits.

HHS wrote that audits are typically conducted independently of information security management and that an internal audit may be performed by a business associate of a covered entity or a subcontractor of a business associate. The Department said it was not proposing to specify who must conduct the audit.

Business Associate Verification

The current organisational requirements turn on obtaining satisfactory assurances that a business associate will comply with the Security Rule. The proposal would go further and require the regulated entity to verify that the business associate has actually deployed the technical safeguards required by 45 CFR 164.312.

A proposed implementation specification at 45 CFR 164.308(b)(2)(ii) would require obtaining written verification from the business associate that it has deployed those safeguards, at least once every 12 months. Under the proposal that verification would include a written analysis of the business associate's relevant electronic information systems, performed by a person with appropriate knowledge of and experience with generally accepted cybersecurity principles, and would be accompanied by a written certification from someone with authority to act for the business associate that the analysis was performed and is accurate. The NPRM states that the parties could decide who performs the analysis, and that the person may be a member of either party's workforce or an external party.

What HHS Said It Would Cost

In the regulatory impact analysis, HHS estimated first-year costs attributable to the proposed rule of approximately $9 billion, and annual costs of approximately $6 billion for years two through five arising from recurring compliance activities. Using a 2 percent discount rate over a five-year horizon covering 2026 to 2030, the Department estimated annualised costs of $6.8 billion for regulated entities and health plan sponsors combined.

The activities driving the first-year figure, as the NPRM lists them, include conducting a Security Rule compliance audit, obtaining and providing verification of business associates' compliance with technical safeguards, deploying multi-factor authentication and penetration testing, segmenting networks, disabling unused ports, and removing extraneous software.

Status of the Rulemaking

No final rule has been published. A search of the Federal Register by regulation identifier number returns exactly one document under RIN 0945-AA22: the January 2025 proposed rule itself. Nothing has been issued withdrawing it either.

The Unified Agenda entry for the rulemaking lists its agenda stage as Long-Term Actions, its priority as economically significant, and its timetable as an NPRM on 6 January 2025 at 90 FR 898 followed by a projected final action date of July 2027. A projected date in the Unified Agenda is a planning estimate rather than a commitment, and the entry records no legal deadline for the rulemaking.

Until a final rule issues, the obligations in force are those of the existing Security Rule, including the addressable category the proposal would retire.

Background

For the underlying law rather than this development: Healthcare privacy law.

Frequently Asked Questions

Does the proposed Security Rule apply to anyone now?
No. The January 2025 document is a notice of proposed rulemaking. It solicited comment and did not amend the Code of Federal Regulations. The Security Rule in force is the existing text at 45 CFR part 160 and subparts A and C of part 164.
Has the proposal been finalised or withdrawn?
Neither, as of this writing. The Federal Register carries only the proposed rule under RIN 0945-AA22, and the Unified Agenda lists the rulemaking as a long-term action with a projected final action date of July 2027.
What is the difference between a required and an addressable implementation specification?
Under the existing rule, a required specification must be implemented. An addressable one must be assessed and implemented where reasonable and appropriate; where it is not, the entity documents why and implements an equivalent alternative measure if reasonable and appropriate. The proposal would eliminate that second category.
Where were comments on the proposal filed?
Under docket HHS-OCR-2024-0020 on regulations.gov. The NPRM directed commenters to that docket and set a closing date of 7 March 2025; comments submitted by fax or email, or after the closing date, were not accepted.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.