
What’s Actually Happening
Nothing says “fun Tuesday afternoon” like a 300+ page federal proposal with a title longer than most root canals. But here we are: the HIPAA Security Rule 2027 update has been the subject of a lot of hallway chatter, half-right blog posts, and at least one office manager convinced the sky is falling by August. The good news is the actual details are a lot less dramatic than the rumor mill — and a lot more useful once you know what’s really in them. Here’s the accurate picture, and why your practice should start preparing now regardless of the exact date.
In January 2025, the U.S. Department of Health and Human Services (HHS) proposed the biggest overhaul of the HIPAA Security Rule in more than two decades. This is still a proposed rule — it has not been finalized. HHS’s current target for finalizing it is July 2027, though that date has already been pushed back once (it was originally expected in May 2026), and it could move again.
Here’s the part most practices get wrong: even if HHS finalizes the rule exactly on schedule in July 2027, that doesn’t mean practices have to be compliant 60 days later. Under the proposal, a final rule would become effective 60 days after publication — and then there’s a separate 180-day compliance period on top of that. Realistically, that puts full compliance somewhere around early-to-mid 2028, not mid-2027.
The bottom line: you likely have more runway than the internet rumor mill suggests — but not unlimited runway, and definitely not a reason to wait.
What’s Actually Changing
The proposed rule would close a loophole that’s existed since the Security Rule was written: right now, many safeguards are labeled “addressable,” meaning practices can choose not to implement them if they document a reasonable justification. The proposal eliminates that distinction almost entirely — nearly every safeguard becomes required, with only narrow, documented exceptions.
Here’s the full scope of what HHS has proposed:
- Multi-factor authentication (MFA) across systems that touch electronic protected health information (ePHI)
- Encryption of ePHI at rest and in transit, with very limited exceptions
- Network segmentation to contain a breach if one system is compromised
- A full technology asset inventory and network map, updated at least once every 12 months — and after any major change
- Vulnerability scanning at least every 6 months
- Penetration testing at least once every 12 months, performed by a qualified tester
- Annual review and testing of whether your security measures are actually working — replacing today’s vague “just maintain them” language
- Separate, dedicated technical controls for backup and recovery of ePHI and the systems that touch it
- A 24-hour notification window for business associates when a contingency plan is activated — a major tightening from today’s much looser timelines
- An annual Security Rule compliance audit of your own program
- Annual written verification from every business associate — an actual analysis and certification, not just a signed attestation
Where SIEM comes in
The proposal also raises the bar significantly on logging and monitoring: comprehensive audit logging across every system touching ePHI, automated real-time monitoring for anomalies (not just an occasional manual glance at logs), and tamper-evident log protection so an attacker can’t quietly erase their tracks after the fact.
The rule itself never uses the word “SIEM” — regulations don’t typically mandate specific product categories. But doing all of that manually, across every system in a practice, isn’t realistic. In practice, this combination of requirements is what pushes most practices toward SIEM-class tooling (or a managed equivalent) to actually stay compliant — even though it’s a functional outcome of the rule, not a literal line item in it.
In short: the rule is designed to turn “best practices we know we should be doing” into “requirements we’re audited against.”
Why Practices Shouldn’t Wait for the Final Rule
Two things are true at the same time:
- The proposed rule isn’t law yet, and the date could shift again.
- The current HIPAA Security Rule is already fully in force, and OCR has said its cybersecurity enforcement is already looking beyond paperwork — auditors want to see that identified risks are actually being managed, not just written down in a binder.
That means most of what the 2027 update would require is already good practice today. Waiting for a final rule to force your hand just means doing the same work later, under more time pressure, possibly during an active audit or after a breach.
How to Get Ahead of It Now
If you want to be in a strong position well before any compliance date locks in, focus on these:
- Get a current risk analysis. Not the one from three years ago — a fresh, documented risk assessment is the foundation everything else builds on.
- Roll out MFA everywhere it touches ePHI. Email, EHR access, remote logins — all of it.
- Confirm encryption coverage. Laptops, servers, backups, and anything ePHI passes through in transit.
- Build (or update) your asset inventory and network map. You can’t protect what you don’t know you have — every device, server, and system that touches patient data should be on a list, refreshed at least yearly.
- Put real monitoring in place. Centralized, automated logging with anomaly detection — not a spreadsheet someone checks when they remember to.
- Start scanning and testing on a schedule. Regular vulnerability scans and an annual penetration test, done by a qualified outside party, not a one-time checkbox.
- Test your incident response plan. Don’t wait for a real breach to find out your backup and notification process doesn’t actually work.
- Review your business associate agreements. Make sure vendors touching your ePHI can actually back up their compliance claims, not just sign a form.
The Real Timeline
- Now: Existing HIPAA Security Rule still applies — full stop.
- July 2027 (target, not guaranteed): HHS’s current estimate for finalizing the new rule.
- ~60 days after finalization: Rule becomes effective (if finalized on schedule).
- ~180 days after that: Compliance deadline under the proposal — landing around early-to-mid 2028.
That’s roughly a year and a half from HHS’s own target date — assuming it doesn’t move again, which it already has once.
Frequently Asked Questions
Is the HIPAA Security Rule update final? No. As of now, it’s a Notice of Proposed Rulemaking (NPRM) issued by HHS in January 2025. It has not been finalized, and the current HIPAA Security Rule remains fully in effect in the meantime.
When do practices actually have to comply with the new HIPAA Security Rule? There’s no confirmed compliance date yet. HHS’s current target for finalizing the rule is July 2027 — a date that has already slipped once from an original May 2026 target. Even if that holds, the proposal includes a 60-day effective-date delay plus a 180-day compliance period after that, putting realistic full compliance around early-to-mid 2028.
What’s new in the proposed 2027 HIPAA Security Rule? The proposal eliminates the current “addressable vs. required” distinction, making nearly all safeguards mandatory. Key additions include mandatory MFA, encryption, network segmentation, an annual asset inventory and network map, vulnerability scanning every 6 months, annual penetration testing, a 24-hour business associate breach notification window, and an annual internal compliance audit.
Does the new HIPAA rule require a SIEM? Not by name — the rule doesn’t mandate a specific product category. But it does require centralized audit logging, automated real-time anomaly detection, and tamper-evident log protection across every system touching ePHI. In practice, most practices will need SIEM-class tooling (or a managed equivalent) to meet that bar.
Is the current HIPAA Security Rule still in effect? Yes. The proposed changes have no legal effect until a final rule is published and its compliance period passes. Practices are still fully bound by, and OCR still fully enforces, the existing HIPAA Security Rule today.
Don’t Wait to Find Out the Hard Way
Whether the final compliance date lands in 2028 or shifts again, the safeguards this rule is built around are already the standard a breach investigation, an audit, or a cyber-insurance renewal will hold you to today. Getting ahead of it now isn’t about beating a deadline — it’s about not being the practice still scrambling when the deadline finally does arrive.
Not sure where your practice stands? Concierge IT offers a free IT assessment that shows you exactly where you’re covered, where you’re exposed, and what it would take to close the gap — before it’s a problem. Schedule yours today.
Last updated: 08/31/2026

Chris Jeanguenat is the co-founding CEO of Concierge IT, bringing over 20 years of healthcare IT experience to medical practices across Palm Beach County and the Treasure Coast.