

The proposed overhaul of the HIPAA Security Rule has slipped to roughly July 2027. Almost every organization I have spoken with since the announcement is treating those twelve months as breathing room. They are not. Here is what actually moved, what did not, and what to do with the year you were just handed.
A behavioral health group with six locations and about ninety employees called me in the spring. Not because of a breach. Because of a form.
Their cyber insurance renewal questionnaire had a field on page two: Date of most recent security risk analysis. The practice administrator went looking for the answer and came back with a certificate from an online compliance portal, dated 2019, generated after someone on staff completed a series of multiple-choice modules. It had a seal on it. It was framed in the billing office.
It was not a risk analysis. Nobody at the organization had ever conducted one.
In the six years since that certificate was printed, the group had stood up telehealth across all six sites, adopted an AI clinical documentation assistant, changed revenue cycle management vendors twice, and moved its scheduling system to a platform that nobody could confirm had signed a business associate agreement. Not one of those changes had been assessed. There was no asset inventory. There was no network diagram. Multi-factor authentication was enabled on the EHR and on nothing else — including email, which is how nearly every one of these stories actually begins.
Here is what makes that group representative rather than negligent: everyone involved believed they were compliant. They had a certificate. They had policies in a binder. They had passed something.
They had also, without knowing it, been carrying the single most-cited violation in HIPAA enforcement for six consecutive years.
The proposed overhaul of the HIPAA Security Rule was published in the Federal Register on January 6, 2025. It was the first serious modernization of the rule in two decades, and it was originally targeted for finalization in May 2026.
That target has moved. The Office of Management and Budget’s agenda now shows the final rule pushed to roughly July 2027 — about twelve additional months (HIPAA Journal; Clark Hill).
The delay is not surprising. HHS itself estimated the proposed changes would cost the industry roughly $9 billion in the first year and $6 billion annually thereafter, and the comment file reflected an industry that found the compliance lift steep.
What the proposed rule would require is worth reading as a list, because it doubles as a gap assessment:
Every item on that list has a lead time measured in quarters, not weeks. Asset inventories take months in a multi-site organization. Segmentation is a project. Getting MFA onto every system without breaking clinical workflow is change management, not a checkbox.
Twelve extra months is not a cushion. For most organizations of the size we work with, it is approximately the amount of time the work actually takes. If you want to know where you stand against the proposed requirements before the clock runs out, that is exactly what a HIPAA Security Rule gap assessment is for.
This is the part the industry keeps missing. The delay applies to new requirements. It applies to nothing about the rule that has been in force since 2005 — and that rule is being enforced with more focus than at any point in its history.
The Office for Civil Rights’ Risk Analysis Initiative has now produced twelve announced enforcement actions (McDonald Hopkins). The eleventh, announced in February 2026, involved an Illinois substance use disorder treatment provider whose breach began with a successful phishing email to a single workforce member. The twelfth involved a software company serving dental practices.
In a separate action, OCR resolved four ransomware investigations together, collecting $1,165,000 across breaches affecting more than 427,000 individuals (HHS):
| Organization | Settlement | Individuals affected | Cited finding |
|---|---|---|---|
| Assured Imaging (affiliated covered entities) | $375,000 | 244,813 | Impermissible disclosure, failed risk analysis, delayed breach notification |
| Regional Women’s Health Group / Axia Women’s Health | $320,000 | 37,989 | Failed risk analysis |
| Star Group Health Benefits Plan | $245,000 | 9,316 | Impermissible disclosure, failed risk analysis |
| Consociate Health | $225,000 | 136,539 | Failed risk analysis |
Look at the right-hand column. Every one of them cites risk analysis. Not an unpurchased next-generation firewall. Not a missing SIEM. The assessment — the document — is what OCR asks for first and what these organizations could not produce.
Then look at the third column. Star Group’s breach affected 9,316 people. That is a small-organization incident, and it still resulted in a $245,000 settlement. The comfortable belief that a practice is simultaneously too small to be targeted and too small to be penalized does not survive contact with this data.
OCR Director Paula M. Stannard put the agency’s position plainly in announcing the settlements: “Proactively implementing the HIPAA Security Rule before a breach or an OCR investigation not only is the law but also is a regulated entity’s best opportunity to prevent or mitigate the harmful effects of a successful cyberattack.”
Hacking and IT incidents now account for more than 80% of large healthcare data breaches. In 2025, large breaches were reported at an average of 2.1 per day, affecting roughly 379,000 individuals daily. Since the breach portal opened in October 2009, it has recorded 7,670 large breaches affecting more than 1.01 billion individuals (HIPAA Journal).
Healthcare has now been the costliest industry for data breaches for thirteen consecutive years, at an average of $6.64 million per incident (IBM Cost of a Data Breach Report 2026, conducted by Ponemon Institute; see also Becker’s).
Two honest caveats, because you deserve the whole picture rather than the frightening half of it. Healthcare’s average breach cost actually fell 10.5% from $7.42 million in 2025. And large breach counts for January through April 2026 came in 9.5% below the same period in 2025. Both are real, and both are good news.
Neither is a trend you can budget against. The U.S. average across all industries rose to $11.5 million, and global breach costs climbed 12%. One favorable year in a fourteen-year series is not a change in direction.
This is the one that should concern you most, and it is the reason the behavioral health group above was in more danger in 2026 than it was in 2019 despite doing nothing wrong in the interim.
AI-driven attacks rose 56% year over year, with roughly one in four organizations experiencing one. Deepfake and impersonation attacks accounted for 45% of them — a direct threat to any organization where a phone call or a video call can authorize a payment or a records release.
More consequentially for healthcare: shadow AI incidents more than doubled, reaching 43% of all security incidents, at an average breach cost of $5.39 million. One in five of those breaches resulted in a regulatory fine (IBM via HIPAA Journal).
Translate that into your building. Over the last eighteen months, your clinicians started using AI scribes. Someone in billing began pasting denial letters into a consumer chatbot to draft appeals. Your EHR vendor shipped an AI summarization feature you did not evaluate. Your RCM partner added a model you were never told about.
Every one of those is a new flow of protected health information. None of them appear in a risk analysis conducted in 2019 — or in one that was never conducted at all. Evaluating those tools before they touch ePHI is the entire point of an AI governance and vendor risk assessment.
Here is the part that matters. The work below is sequenced deliberately, and it is sized for an organization with a practice administrator and an outsourced IT provider — not a security operations center.
Recognized Security Practices — Public Law 116-321, signed January 5, 2021
If you can demonstrate that recognized security practices — the NIST Cybersecurity Framework, or the Section 405(d) Health Industry Cybersecurity Practices — have been fully implemented and continuously in use for the twelve months preceding a security incident, HHS must take that into account when determining fines, and in limiting the scope and duration of an audit (Public Law 116-321; OCR guidance summary).
It is not a safe harbor. It creates no immunity, and its absence cannot be used to increase a penalty. But it is the only mechanism in the statute that converts security investment directly into regulatory downside protection.
Note the twelve-month look-back. Standing up controls the week after an incident is worth nothing under this provision. The value exists only if the clock is already running — which is precisely the argument for starting during a regulatory delay rather than at the end of one.
If you want a free, prioritized place to begin, use the HHS Cybersecurity Performance Goals. The ten Essential goals are the shortest defensible starting list in healthcare security: mitigate known vulnerabilities, email security, MFA, basic workforce training, strong encryption in transit, revoke credentials for departing staff, basic incident planning, unique credentials for every user, separate user and privileged accounts, and vendor security requirements. Ten more Enhanced goals follow, including asset inventory, network segmentation, and cybersecurity testing (HIPAA Journal; HHS 405(d)).
They are voluntary. They also map almost directly onto what the delayed rule makes mandatory. That is not a coincidence, and it is the closest thing to a published answer key you are going to get.
If you run a practice, clinic, or agency: your exposure is the risk analysis and the evidence file behind it. Every enforcement action cited above turned on that document. Start there, not with a product purchase.
If you build health technology: you are increasingly the breach vector rather than the bystander, and OCR is now naming software vendors directly in its enforcement actions. The next post in this series covers what that means for your security program and your enterprise sales cycle.
If you invest in healthcare: cyber diligence has moved from post-close cleanup to pre-LOI underwriting, and a 2027 or 2028 exit will be diligenced against the new rule rather than the current one. The third post in this series covers the portfolio math.
The behavioral health group completed their risk analysis in eleven weeks. It found gaps they expected and four they did not, including an AI documentation tool that had been retaining transcripts far longer than anyone at the practice believed. They are now most of the way through the remediation roadmap, they answered their insurance questionnaire honestly, and their Recognized Security Practices clock has been running since March.
None of that was driven by the Security Rule overhaul. It was driven by the rule that has been in effect the entire time.
July 2027 is when the ceiling rises. The floor has not moved, and OCR is enforcing it now.
Cybersecurity Advisory Group provides healthcare cybersecurity consulting without the Fortune 500 price tag. Our HIPAA Risk Assessment & Compliance Program delivers a genuine gap analysis, a prioritized remediation roadmap, and audit-ready documentation — sized and sequenced for what your organization can actually absorb.
For organizations that need the roadmap executed rather than just written, the CyberAdvisor vCISO Retainer provides ongoing security leadership: policies, risk management, board reporting, vendor oversight, and incident response.
Book a free 30-minute Security Clarity Session. We’ll go through where your controls actually stand, what the proposed Security Rule would require of an organization your size, and what a realistic first year looks like. No pressure, no jargon, and no homework before we talk.
Book Your Free 30-Minute Security Clarity Session →
Regulatory status
Enforcement
Breach and cost data
Frameworks and statute
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn
