A year of extra runway sounds like good news….but for most practices, it just means the deadline moved, not the risk.
If your practice has been bracing for a major HIPAA shakeup this year, you can exhale, a little. HHS quietly moved the target date for finalizing its Security Rule overhaul from May 2026 to July 2027, and the rulemaking shifted from “final rule stage” to “long-term actions” on the federal tracker (a signal that a final version is now well over a year out).
Here is what changed, what didn’t, and why the delay is not the same thing as a pass.
What’s Actually Being Delayed
The proposed overhaul, first published in January 2025, would be the first major rewrite of the HIPAA Security Rule since 2013. Its central change is straightforward but significant: it would eliminate the current rule’s “addressable” category, the loophole that lets a practice document a reasonable alternative to a safeguard like encryption or multi-factor authentication instead of implementing it. Under the new rule, those safeguards would simply be required.
That is the part getting pushed to 2027. Nearly 5,000 public comments came in during the review period, many from hospitals and provider groups warning about cost and timeline. HHS’s own estimate put first-year compliance costs at roughly $9 billion industry-wide. A coalition of hospital associations and more than 100 health systems even asked the administration to withdraw the rule entirely, arguing small and rural providers could not absorb the cost, and HHS pushed the timeline back as a result.
What Is Not Being Delayed
Two things worth knowing before you file this under “next year’s problem”:
- OCR is still moving ahead separately on HIPAA Privacy Rule changes, expected around August 2026, a different track that is not affected by this delay.
- The current HIPAA Security Rule is still fully in force, and OCR has continued actively enforcing it, meaning risk assessments, safeguards, and documentation are all still required under the rules that already exist today.
The date itself is also softer than it looks. Unified Agenda timelines are planning estimates, not binding deadlines, and this target has already slipped once. It could move again in either direction.
Not sure whether your current setup would hold up under the rules already on the books, let alone the ones coming? That is exactly the kind of gap we help small practices close before it becomes a problem.
What This Means for Your Practice
The honest read is that the extra time is useful only if you use it. The requirements in the proposed rule, universal encryption, multi-factor authentication, regular risk assessments, are the same safeguards OCR already expects a well-run practice to have. Waiting for the final rule to force the issue just means doing the same work later, under more pressure, with less runway.
The Bottom Line
A delayed deadline is not a canceled one, and the practices that use this extra year to actually close their gaps will not be scrambling when July 2027 arrives.
Where GiaSpace Fits
We help small to medium sized healthcare practices understand where they stand against both today’s HIPAA requirements and what’s coming, so a headline like this one is useful information instead of a surprise. If you are not sure where your practice’s gaps are, that is where we come in.
→ Schedule a Free Security Assessment with Rob Giannini, our CEO and AI specialist





