A dark tactical graphic comparing two columns: a greyed-out 'Addressable' column with struck-through items, and an amber 'Required' column listing encryption, MFA, segmentation, and asset inventory, with an arrow moving from optional to mandatory, alongside a compliance countdown element and the headline 'Addressable Is Becoming Required: The HIPAA Security Rule Overhaul.
SITREP // HEALTHCARE // HIPAA SECURITY RULE OVERHAUL

The HIPAA Security Rule Overhaul: A Readiness Roadmap for Healthcare Before the Clock Starts

For twenty years, "addressable" gave healthcare organizations room to hold a meeting, document a decision, and move on. The proposed HIPAA Security Rule overhaul closes that door. Encryption, multi-factor authentication, network segmentation, an annual asset inventory and network map, vulnerability scanning, penetration testing, and a 72-hour critical-system restoration capability all become mandatory — with a compliance window that starts running the moment the final rule takes effect. If your organization has been deferring controls under the addressable label, that runway is ending. This dossier is the readiness roadmap: how to build the asset inventory and network map everything else depends on, how to reopen and close the risk decisions you accepted years ago, and how to verify your business associates before the clock starts.

For two decades, one word gave healthcare organizations an escape hatch from their most expensive security obligations: addressable.

In practice, “addressable” was widely read as “optional.” A hospital could convene a meeting about encryption, document a reasoned decision not to implement it, file that decision away, and consider the requirement satisfied. Technically that was defensible under the rule. Operationally, it meant thousands of organizations formally accepted risks they never intended to revisit — and then didn’t, for years.

The proposed HIPAA Security Rule overhaul closes that door.

This is the single most consequential change in the proposal, and it reframes every other requirement in it. Under the new rule, the distinction between “required” and “addressable” implementation specifications is eliminated. Nearly everything becomes mandatory, with only narrow exceptions. Every risk your organization formally accepted under the addressable label is now a gap you have to fund, implement, and document — on a clock.

The companion episode of Status: Secure — Episode 025, Data Extortion, Credential Attacks, and the New HIPAA Security Rule Every Executive Must Know — walked through the threat environment driving this change and gave the foundational briefing on what the rule is and where it came from. This Sitrep is the readiness roadmap behind that briefing. If the episode told you what’s changing and why, this dossier is how you get ready before the compliance window starts running.

Where the Rule Actually Stands

Precision matters here, because a lot of healthcare leaders are hearing secondhand versions of this.

The HHS Office for Civil Rights announced the Notice of Proposed Rulemaking (NPRM) in December 2024, and it was published in the Federal Register on January 6, 2025 — the first major update to the Security Rule since the 2013 HIPAA Omnibus Rule. The proposal would modify 45 CFR Part 164. Twelve years is a long time in cybersecurity; the threat environment that produced the 2013 rule predates the modern ransomware economy, the credential-theft marketplace, and AI-assisted phishing entirely.

The comment period closed March 7, 2025, drawing more than 4,000 comments from across the healthcare industry.

Two sources worth bookmarking.

OCR published a plain-language fact sheet summarizing the NPRM, which is the fastest orientation for executives and board members. For compliance leads who need the actual regulatory language, the full NPRM text is available in the Federal Register. We recommend the people responsible for your Security Rule compliance read the primary source directly rather than relying on summaries — including ours.

Now the honest status, because the timeline has been widely misreported.

This is still a proposed rule. As of mid-2026, no final rule has been published. OCR had listed a final action target on its regulatory agenda, but that date has come and gone without publication. A regulatory freeze pending review, issued shortly after the NPRM published, further clouded the picture. The rule has drawn substantial industry pushback — OCR’s own regulatory impact analysis estimated first-year compliance costs across all regulated entities at roughly $9 billion, with several billion recurring annually, and organizations including the American Hospital Association and CHIME raised concerns about the burden on small and rural providers operating on thin margins.

So a final rule could arrive, could arrive substantially modified, or could stall further. Anyone telling you a specific date is guessing.

On timing, once it does land: a final rule would take effect roughly 60 days after Federal Register publication, with regulated entities then given a compliance window — the proposal contemplated 180 days from the effective date. Treat those numbers as directional until a final rule confirms them.

Here is why none of that uncertainty changes what you should do.

The direction of travel is unmistakable, and not just at OCR. Every major regulator is converging on the same move: away from “tell us you’re compliant” toward “show us you are.” The defense industrial base has been living through the identical transition with CMMC. Whatever the final HIPAA text says, verification is replacing attestation across the board.

And there’s a purely practical argument. Assume the rule finalizes and you get roughly six months of compliance runway. That is the window to complete a risk analysis, build an accurate asset inventory and network map, deploy encryption across your ePHI, implement MFA organization-wide, segment your network, stand up vulnerability scanning, arrange penetration testing, prove a 72-hour restoration capability, and re-paper every business associate agreement. Organizations that start when the clock starts will not finish.

A delayed rule isn’t a reprieve. It’s additional runway — and the organizations that use it will be the ones that finish comfortably instead of scrambling.

Why the Threat Environment Forced This

The overhaul isn’t regulatory appetite for its own sake. Healthcare is the most expensive target on the board, and it has been for a long time.

Healthcare has carried the highest average breach cost of any industry for fourteen consecutive years — currently around $7.42 million per incident. In the first half of 2026, the sector absorbed an average of 2.3 ransomware attacks per day. And the Change Healthcare attack reached roughly 192.7 million individuals, an event whose fallout reached congressional testimony and reshaped how seriously Washington treats healthcare cyber risk.

Layer on the attack pattern shift covered in the episode. Ransomware crews have evolved from encrypt-and-ransom to steal-and-extort — exfiltrating data first, then encrypting. That change guts the traditional defense: even flawless backups restore your operations while your patient data is being sold. And the entry vector has shifted with it. Attackers increasingly don’t break in; they log in, using credentials harvested at industrial scale — one exposed database alone held roughly 24 billion credential records — amplified by AI-assisted phishing that appeared in a substantial share of sampled emails in 2026.

The rule is the regulator’s answer to that reality. The controls it mandates — encryption, MFA, segmentation, asset visibility — are precisely the controls that blunt steal-and-extort and credential-based intrusion. Read that way, the overhaul isn’t arbitrary compliance burden. It’s the government codifying the defenses the current threat model actually requires.

What Becomes Mandatory

Here is the concrete list. Under the proposal, these move from addressable or absent to required:

  • Encryption of ePHI at rest and in transit
  • Multi-factor authentication
  • Network segmentation
  • An annual technology asset inventory and network map, maintained and kept current
  • Vulnerability scanning at least every six months
  • Annual penetration testing
  • A 72-hour capability to restore critical systems after an incident
  • Written documentation of security policies, procedures, and analyses
  • Business associate verification — BAs must confirm their safeguards are in place, and subcontractors are pulled directly into scope

Note what these have in common: none of them are exotic. Encryption and MFA aren’t new technologies — they’ve been recommended practice for well over a decade. What’s changing isn’t the state of the art. It’s that the option to formally decline them is going away.

// INCOMING TRANSMISSION

Status: Secure Episode 025 — Data Extortion, Credential Attacks, and the New HIPAA Security Rule Every Executive Must Know covers the shift from ransomware to steal-and-extort, the credential-based 'log in, don't break in' economy feeding it, and the foundational walkthrough of the Security Rule overhaul. Listen for the operator's view on why regulators everywhere are moving from attestation to verification.

INITIATE PLAYBACK »

Step 1: Build the Asset Inventory and Network Map Properly

Everything downstream depends on this, and it is where most organizations will discover their real problem.

The new rule mandates an annual technology asset inventory and a network map. That sounds like documentation busywork. It isn’t — it’s the foundation the entire rule rests on, because a risk analysis that isn’t tied to an accurate inventory is a risk analysis of an imaginary environment.

Asset Inventory

The asset inventory must account for every system that creates, receives, maintains, or transmits ePHI — and the systems that touch those systems. In a healthcare environment that’s a much longer list than most teams assume: EHR platforms, imaging systems, clinical workstations, connected medical devices, backup infrastructure, cloud services, third-party integrations, remote access paths, and the shadow IT a department stood up without telling anyone. If it can reach ePHI, it belongs on the list.

Network Map

The network map is where the standard is higher than most organizations realize. A network map is not simply a diagram of physical or logical topology. It must map your data flows. Where does ePHI originate, where does it travel, where does it rest, where does it leave your environment, and which third parties receive it? A topology diagram tells you what’s connected. A data-flow map tells you what’s exposed — and only the second one lets you make defensible decisions about encryption and segmentation.

Two practical notes. First, documentation is genuinely the least popular work in any technical organization, and this is the step teams will most want to shortcut. Resist that — the shortcut compounds into every later failure. Second, you don’t have to do it by hand. Modern discovery and asset-management tooling, including AI-assisted mapping, can build and maintain much of this automatically. Whatever you use, the requirement is that it stays current, not that it existed once.

Step 2: Reopen Every Risk You Accepted Under “Addressable”

This is the step that will surprise leadership, and it deserves a specific process.

Somewhere in your compliance files is a set of documented decisions where your organization considered an addressable specification, evaluated it, and formally accepted the risk of not implementing it. Encryption at rest on a legacy system. MFA for a clinical workflow where it seemed too disruptive. Segmentation deferred because the network refactor was too expensive.

Those decisions were legitimate under the old rule. Under the new one, they’re gaps.

Pull every accepted-risk decision and re-triage it.

For each one, answer three questions:

  1. Is the underlying control now mandatory under the proposal?
  2. If so, what does implementation actually require — technically, operationally, and financially?
  3. How long will it realistically take?

That last question is the one to take seriously. Encryption at rest on a legacy clinical system, or MFA across a workforce that includes shift-based clinical staff sharing workstations, is not a weekend project. These are multi-month efforts with budget cycles, vendor dependencies, workflow redesign, and change management attached. If you discover in month one of your compliance window that MFA rollout is a nine-month program, you have a problem that timeline cannot solve.

Doing this triage now, before the clock starts, converts an emergency into a plan. It also gives you something invaluable at budget time: a defensible, itemized cost of compliance, backed by a federal rulemaking, that finance can actually plan against.

Step 3: Fix Where Your Testing Regime Is Genuinely Insufficient

The rule sets floors: vulnerability scanning at least every six months, annual penetration testing, and a 72-hour restoration capability for critical systems. Meet them. But understand where the floor sits below what the threat environment demands.

Scanning every six months is a compliance minimum, not a security posture.

Attackers probe your environment continuously. Exploit windows after vulnerability disclosure have collapsed from months to days — Microsoft’s June 2026 Patch Tuesday addressed roughly 200 vulnerabilities including an actively exploited Exchange flaw hijacking Outlook Web Access sessions. A vulnerability disclosed the week after your scan gets five and a half months of runway before you look again. Continuous scanning and continuous penetration testing are the practices that actually match the adversary’s tempo.

There’s a related credibility gap worth naming: many organizations report a 30-day patch cycle and, on inspection, are actually patching every six months to a year. If your documented cycle and your real cycle diverge, the new rule’s written-documentation requirement turns that divergence into evidence.

The 72-hour restoration requirement demands functional testing, not tabletops.

A tabletop exercise is a conversation. It does not prove you can restore. And critically, real incidents don’t take down one system — they take down many at once, which surfaces the questions a single-system restore test never asks: What’s the recovery order? Which systems have dependencies on other systems being up first? Do your people know the sequence under pressure? Run comprehensive functional exercises that restore multiple systems simultaneously, and time them honestly against the 72-hour requirement.

Step 4: Re-Paper and Actually Verify Your Business Associates

The business associate provisions are where the new rule reaches furthest — and where most healthcare organizations have the least visibility.

Under the proposal, business associates must verify to covered entities that their safeguards are in place, and subcontractors of business associates are pulled directly into scope. That’s your fourth parties: the vendors your vendors use.

The work has three parts, and it requires your contracts team as much as your security team.

Inventory and reconcile.

Pull every BAA. Determine which are current and active, which are stale, and — critically — which correspond to relationships that have ended. A terminated vendor whose access was never revoked is both a security exposure and a compliance finding. Cross-reference your BAA list against your actual system access.

Extend to subcontractors.

For each active business associate, establish who their subcontractors are and confirm safeguards flow down. This is genuinely new visibility for most organizations, and it takes time to build.

Verify — don’t just collect.

Here is where most programs are weakest. The standard practice is to request a SOC 2 report, file it, and consider the vendor verified. A SOC 2 is useful evidence, but it is not verification of the specific safeguards protecting your ePHI. Your BAAs almost certainly contain a right-to-audit clause. Use it. Pick a business associate, pick one specific control, and ask them to demonstrate it. Something simple. The point isn’t to conduct a full audit — it’s to establish that verification is real in your program rather than theoretical, and to find out whether your vendors can actually produce evidence when asked. The organizations that discover a vendor can’t answer that question find out on their own terms rather than during a breach investigation.

The Real Shift: From Attestation to Verification

Step back and the pattern is bigger than HIPAA.

For years, most regulatory frameworks operated on a trust model: document your controls, attest that they’re in place, and enforcement arrives only after something goes wrong. That model is being retired across the board. The defense industrial base has been living through the same transition with CMMC — a move from self-attestation toward third-party and government verification. Healthcare is now on the same trajectory.

The reason is the same in both sectors: the gap between the security an organization documented and the security it actually ran turned out to be enormous, and adversaries were living in that gap. Paper compliance stopped correlating with actual defensibility.

So the practical translation of the HIPAA overhaul is this: the gap between what you documented and what you run is no longer a judgment call. It’s a finding. And with mandatory written documentation, your paper trail becomes the evidence — either your defense or the exhibit against you.

That reframe matters for how you approach the next several months. If you treat this as a documentation exercise, you’ll produce documents that prove your gaps. If you treat it as a security exercise, the documentation becomes a byproduct of work that actually made you harder to breach — which was the point before it was ever a rule.

Marching Orders

Start the risk analysis and asset inventory now.

Build the inventory and a data-flow-level network map, verify they’re accurate, and tie a genuine risk analysis to them. Everything else in the rule depends on this, and it’s the most-cited Security Rule failure in current enforcement.

Triage your accepted risks this quarter.

Pull every addressable specification you formally declined, determine which are now mandatory, and scope the time and cost to close them. Encryption, MFA, and segmentation are the big three. Get the number in front of finance before the clock, not after.

Re-paper and verify your business associates.

Reconcile your BAAs against actual access, extend visibility to subcontractors, and exercise your right to audit on at least one control with at least one vendor. Prove your verification process works while it’s still voluntary.

Fix the testing gap.

Move toward continuous scanning and testing rather than the six-month floor, and run a comprehensive multi-system functional restoration exercise against the 72-hour requirement.

Execute the Standard

Addressable is becoming required. The controls the overhaul mandates — encryption, MFA, segmentation, asset visibility, tested recovery — are the same controls that stop steal-and-extort ransomware and credential-based intrusion. The rule isn’t asking healthcare organizations to do something disconnected from the threat. It’s asking them to finally do the thing the threat has demanded for years.

The organizations that start now will finish inside the window with a security program that’s genuinely stronger. The ones that wait for the final rule will spend their entire compliance runway discovering that six months wasn’t enough time to encrypt a legacy environment, deploy MFA across a clinical workforce, and re-paper two hundred business associate agreements simultaneously.

If your organization needs to build a defensible asset inventory and network map, run the risk analysis the new rule requires, scope and close the addressable gaps you’ve been deferring, or stand up a business associate verification process that survives scrutiny, that is the work we do. Verify your security posture at watchur6.com/secure, or establish a secure line at watchur6.com/contact.

Trust but verify your own posture. Run the risk analysis. Close the addressable gaps. Verify your business associates. Execute the standard.

This Sitrep reflects the HIPAA Security Rule NPRM as published in the Federal Register on January 6, 2025, and summarized in the OCR fact sheet. The rule remains proposed and the final version may differ. The current Security Rule stays in effect until a final rule takes effect. We will update this dossier as the rulemaking progresses.

SECURE YOUR PERIMETER.

DON'T WAIT FOR THE BREACH TO READ THE SITREP.

Join The Watch for immediate access to Declassified Sitreps and Strategic Intel before the threat reaches your door.