fbpx
Contact us
Back to the list of entries

The New HIPAA Security Rule: What’s Proposed, Why It’s Changing, and What Healthcare Organizations Must Do Now

The healthcare industry is on the brink of the most significant regulatory shift in cybersecurity in over a decade.

On January 6, 2025, the Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), issued a Notice of Proposed Rulemaking (NPRM) to overhaul the HIPAA Security Rule. This is the first major update since the Rule was modified in 2013, and it arrives not a moment too soon. With ransomware attacks crippling hospitals and breaches affecting hundreds of millions of patients, the HHS is moving to eliminate ambiguity and mandate a proactive, resilient defense for electronic Protected Health Information (ePHI).

For compliance officers, IT leaders, and healthcare CISOs, this article breaks down the "why" behind the changes, the most impactful new requirements, and what your organization should be doing today to prepare for the final rule.

Why the Security Rule Is Being Overhauled

The existing HIPAA Security Rule was originally crafted in 2003, built for a different technological era. The proposed changes reflect a healthcare environment that has been fundamentally transformed in the years since.

The adoption of Electronic Health Records (EHRs) is now near-universal. Meanwhile, the explosion of cloud computing, telehealth, and interconnected medical devices has dramatically expanded the attack surface. The NPRM specifically calls out the dual-use nature of emerging technologies like Artificial Intelligence — while AI can revolutionize diagnostics and patient care, it can also be weaponized by bad actors to craft sophisticated phishing attacks or mishandled by insiders in ways that expose sensitive data.

The statistics driving this urgency are stark. According to the HHS Office for Civil Rights, there was a 93 percent rise in large data breaches between 2018 and 2022, with breaches involving ransomware experiencing a 278 percent increase during that period. The Change Healthcare attack in 2024 demonstrated how a single point of failure can disrupt the entire U.S. healthcare system, ultimately affecting approximately 190 million individuals according to UnitedHealth Group's final confirmation, making it the largest known breach at a HIPAA-regulated entity.

Perhaps most frustrating for regulators has been the widespread misinterpretation of "addressable" implementation specifications. Many entities treated critical safeguards like encryption and multi-factor authentication as optional, leading to inconsistent compliance and gaping holes in security postures that attackers have been all too happy to exploit.

The Most Significant Proposed Changes

The philosophical heart of the update is simple: the distinction between "required" and "addressable" implementation specifications will be eliminated. If finalized, every security measure becomes mandatory. Regulated entities must implement them unless they can provide documented, risk-based justification for adopting an equivalent alternative. This shift alone will transform how healthcare organizations approach compliance.

Several critical controls that were previously treated as flexible will now become non-negotiable. Multi-factor authentication will be required for all technology assets accessing ePHI, with very limited exceptions for legacy systems. Encryption becomes mandatory for ePHI both at rest and in transit — no more relying on compensating controls instead of encrypting laptops, databases, or emails. Organizations must also implement network segmentation, isolating systems that handle ePHI from the rest of the network to prevent lateral movement during an attack.

The new Rule also transforms risk management from a periodic checkbox exercise into a continuous, rigorous process. Entities must maintain detailed technology asset inventories and data flow maps illustrating how ePHI moves through their systems, updated at least annually. Penetration testing becomes required at least once every 12 months, with vulnerability scanning mandated every six months. Organizations must formally audit their compliance with the Security Rule on an annual basis.

Reaction time is everything in a breach, and the proposed rule sets strict new timelines. Contingency plans must ensure that critical systems and data can be restored within 72 hours of an incident. Business associates must notify covered entities of a breach or the activation of their contingency plan within 24 hours. Covered entities must also obtain annual written verification from business associates, validated by a cybersecurity expert and certified by senior leadership, confirming that technical safeguards are properly deployed.

What This Means for Healthcare Organizations

For the average healthcare organization, these changes represent a significant operational and financial lift. The comment period for the NPRM ended in March 2025 with thousands of submissions, many expressing concerns about the burden on small and rural providers. While the final rule, expected as early as May 2026, may see modifications, the direction of travel is unmistakable. HHS is mandating a state of continuous, auditable cybersecurity readiness.

The fundamental challenge is one of visibility. You cannot protect what you cannot see. The requirements for asset inventories and network mapping are not merely paperwork exercises. They demand a technical capability to discover, classify, and track ePHI across a sprawling digital estate — from endpoints and servers to cloud applications and email. Without automated tools, meeting these mandates is nearly impossible. According to The HIPAA Journal, network servers were the most common location of breached protected health information in 2024, while more than one-fifth of breaches involved data stored in email accounts, highlighting the need for strong password policies, multifactor authentication, and security awareness training. How do you enforce MFA on every system? How do you prove ePHI is encrypted everywhere? How do you conduct a compliance audit without centralized visibility into user activity and data movement?

How Zecurion Helps You Prepare

At Zecurion, we believe compliance should be a natural byproduct of effective security. As healthcare organizations brace for these changes, a modern Data Loss Prevention platform is no longer a luxury — it is the operational engine for compliance.

Our centralized discovery engine automatically scans structured and unstructured data to create precise technology asset inventories, identifying exactly where ePHI resides and providing the network maps the HHS is demanding. With granular policy controls, Zecurion enforces the now-mandated safeguards, ensuring encryption at rest and in transit, blocking unauthorized transfers, and enforcing access controls to meet the minimum necessary standard.

Our User and Entity Behavior Analytics establish baselines of normal activity to detect insider threats, compromised accounts, and potential breaches in real-time. When incidents occur, speed is critical. Zecurion provides detailed audit trails and forensic evidence to investigate breaches, document response efforts, and meet the proposed 72-hour restoration and 24-hour notification requirements.

Traditional DLP monitors email and USB drives, but what about a photo of a patient chart taken with a smartphone? Our Screen Photo Detector uses AI to detect and block unauthorized photography of sensitive data, addressing a critical blind spot that many healthcare organizations overlook.

Next Steps

The era of flexible, paper-based HIPAA compliance is ending. The future is automated, continuous, and technically enforced. While we await the final ruling, waiting is the riskiest strategy available.

Healthcare organizations should begin conducting a readiness assessment today. Compare your current technical controls against the proposed mandates. Can you inventory all your ePHI? Can you prove it's encrypted everywhere? Can you detect an insider threat before they exfiltrate data?

Zecurion is here to help you bridge the gap. Our platform is designed to turn complex regulatory requirements into automated, manageable security processes — so you can focus on delivering care, knowing your patient data is protected.

Subscribe to our blog updates

You will receive only really useful emails and will always be able to unsubscribe from this mailing if, suddenly, your interests change

Recommended resources