AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

The HIPAA Security Rule Rewrite: The Dates to Budget Around and the Controls That Stop Being Optional

HIPAA Security Rule update timeline: the proposal is not final and HHS projects July 2027, so here are the controls to budget for and the dates to plan around.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsNovember 30, 2026 · 6 min read

Budget season, and the vendor says wait

The administrator of a three-site eye clinic sits down with the owner-physician on the last Monday in November to build next year's budget. The IT vendor has sent a note recommending that the practice defer security spending, because the HIPAA rewrite is only a proposal and might change.

The owner is inclined to agree. Then the administrator reads out two items from her own list.

The first is a laptop. A technician left in March, returned a badge and a set of keys, and the laptop went into a drawer at the Southside office, or possibly did not. Nobody can say whether it held exported patient images, because the asset spreadsheet was last updated in 2021 and has 46 rows for what is now 60-something devices.

The second is a restore. In August the practice management server was rebuilt after a failed update, and the vendor's engineer had it back by Thursday. Everyone remembers it as a success. Nobody wrote down that it took 51 hours, or that scheduling ran on paper for two days, or that the imaging archive came back last.

The owner asks the fair question: if the rule is not final, what exactly are we buying?

Two things, and neither of them is a product. An accurate list of where patient data lives, and a tested answer to how fast it comes back.

The rewrite, in plain words

The HIPAA Security Rule has not been meaningfully updated since 2013. In January 2025, HHS published a Notice of Proposed Rulemaking to change that. It is a proposal, it is not final, and HHS projects finalization in July 2027.

Notice of Proposed Rulemaking: the published draft of a rule, open for comment. It tells you what the regulator intends, not what you owe today.

Addressable and required: the current rule's two categories. Addressable never meant optional; it meant you may implement an equivalent measure and document why. The proposal moves several long-standing addressable items into the required column.

The proposed controls, in plain terms: multi-factor authentication on systems that hold electronic protected health information, encryption of that information at rest and in transit, a written inventory of the technology assets and how data moves between them, restoration of critical systems and data within 72 hours, and an audit of compliance at least once a year.

Look at that list as a clinician would. None of it is novel. Every item is something a practice already claims to do informally, and the proposal turns each claim into something that must be written, tested and dated. The gap it exposes is not a technology gap. It is a documentation and testing gap, and that is the part money cannot buy quickly.

The numbers that matter

The January 2025 HIPAA Security Rule proposal is not final and HHS projects finalization in July 2027, per the HHS Office for Civil Rights proposal published in the Federal Register in January 2025. Its proposed controls, multi-factor authentication, encryption, asset inventory, 72-hour restoration and annual audits, are good practice now.

Healthcare recorded 1,438 confirmed breaches in the Verizon 2026 Data Breach Investigations Report. The proposal reads like a list of what was missing in those investigations.

Ransomware appeared in 48% of breaches in the Verizon 2026 DBIR. That statistic is the reason the 72-hour restoration item exists, and it is the one control that also protects your Tuesday clinic schedule whatever the final rule says.

What to do this week

  1. Rebuild the asset list from what is on the network today rather than from the 2021 spreadsheet. Every workstation, laptop, tablet, imaging device, server and cloud system, with an owner, a location and a yes or no on whether patient data touches it. Then find the technician's laptop. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Add the data flows to the same document: which system sends patient information to which, including the billing company, the imaging archive, the referral portal and the recall service. Two pages of arrows answers half of any risk analysis question you will ever be asked. (CIS 1 Inventory and Control of Enterprise Assets)
  3. Restore your practice management database and one imaging study from backup, into a test space, and record the date and the elapsed time. If the number is above 72 hours, you now have a specific problem to solve instead of a general worry. (CIS 11 Data Recovery)
  4. Keep one backup copy in a place your daily administrator account cannot delete, and confirm it in writing with whoever runs your backups. Ransomware that reaches the backup turns a bad week into a closure. (CIS 11 Data Recovery)
  5. Confirm encryption is on, device by device, from the asset list you just built, and keep the screenshots in a folder with the date. A stolen encrypted laptop is a lost asset. An unencrypted one is a notification. (CIS 3 Data Protection)
  6. Put four dates in next year's calendar now: a quarterly review of the asset list, a restore test each quarter, one annual audit of your safeguards, and the month you will revisit all of it when the final rule lands. Owning the calendar is what converts a proposal into a plan. (CIS 6 Access Control Management)

Where AccuSights fits

We treat the proposal as a preview and the current rule as the obligation, because both are true at once. Our assessment produces the risk analysis the HIPAA Security Rule already requires, an accurate asset and data-flow map, and a plan ranked by what actually reduces risk in your practice. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the systems that hold patient records, and our healthcare package keeps the analysis current instead of annual. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.

Questions people ask

Is the HIPAA Security Rule update final? No. The Notice of Proposed Rulemaking published in January 2025 is still a proposal, and HHS projects finalization in July 2027. That means nothing in the proposal is enforceable today, and it also means the direction of travel has been published in writing for more than a year. Practices that treat the proposed controls as good practice now are buying themselves a longer runway at a lower cost than practices that wait for a final rule and a compliance date at the same time.

What does a 72-hour restoration requirement actually mean for a practice? It means being able to bring critical electronic systems and data back within 72 hours of a loss, which is a measurable claim rather than an aspiration. The only way to know your number is to restore something and time it. Most practices that have never tested discover that the restore itself is fine and the delay sits elsewhere: the software vendor's rebuild queue, a licence key nobody can find, or a backup that was running against the wrong folder since a server change.

How long do we have to notify patients after a breach? Under the current Breach Notification Rule, individuals are notified without unreasonable delay and no later than 60 days from discovery, and a breach affecting 500 or more people also goes to HHS and to the media serving the area. None of that is changing in the proposal, and the practical problem is the same as ever: the 60 days include the time you spend working out whose records were involved, so your logging and your asset list decide how much of the clock you actually get.

A rule that arrives in July 2027 is not a deadline. It is a diagnosis you were given early, with time to treat it.

Controls this post maps to

CIS 1 Inventory and Control of Enterprise AssetsCIS 11 Data RecoveryCIS 3 Data Protection

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.