HIPAA Updates and HIPAA Changes in 2026 (HIPAA Journal)
The HIPAA Security Rule Notice of Proposed Rulemaking (NPRM) was published in the Federal Register on January 6, 2025, opening a 60-day comment period. As of mid-2026, the proposed rule has not been finalized — OCR has not issued a final rule — and the Office of Management and Budget's unified regulatory agenda shows the final rule delayed until July 2027. A coalition of 100+ hospital and provider groups (led by CHIME) has formally asked HHS to withdraw or significantly scale back the rule, citing underestimated compliance costs for under-resourced providers.
Proposed changes (unchanged from prior reporting, still not final): elimination of the required/addressable safeguard distinction; mandatory MFA for all systems accessing ePHI; mandatory encryption at rest and in transit; 72-hour breach/incident reporting; annual penetration testing; enhanced business-associate oversight.
Relevance to constraint.hipaa-security-rule-2026. That node currently states as settled fact that "Final rule published early 2026; compliance deadline approximately September 2026." This is now contradicted — the rule is still a proposal, and the anticipated final-rule timeline has slipped to July 2027. This is a correction, not a refinement — see drafted candidate in evolution-log/2026-08-16/web-refresh.md.