The 2025 Security Rule Proposal: What Would Change
On January 6, 2025 HHS published a notice of proposed rulemaking to modernize the Security Rule, the first substantive rewrite since 2013. The stated reason is the gap between the rule's flexible, largely undefined standards and the threat environment that produced record breach counts. The proposal removes the distinction between required and addressable implementation specifications, making nearly everything required with narrow exceptions, and adds specific technical controls with specific timelines.
The comment period closed in March 2025 with substantial industry opposition on cost and prescriptiveness, and the final rule has not issued as of this writing. Track the Federal Register record and OMB's regulatory agenda rather than assuming a date; this site's guidance feed carries the Federal Register documents as they publish.
Whatever survives to the final rule, the proposal is the clearest statement of what OCR considers reasonable and appropriate today, and most of it aligns with the HPH Cybersecurity Performance Goals that HHS already expects entities to meet.
Key points
No more addressable
All implementation specifications would be required, with limited exceptions that must be documented. The flexibility that let entities defer encryption or MFA would end.
Inventory and network map
A written technology asset inventory and a network map of ePHI movement, updated at least every 12 months and after material changes, feeding a written risk analysis with specified contents.
Encryption and MFA
Encryption of ePHI at rest and in transit, and multi-factor authentication for access to ePHI systems, each with narrow, documented exceptions such as certain medical devices.
Restoration within 72 hours
Procedures to restore the loss of certain relevant electronic information systems and data within 72 hours, backed by a criticality analysis, and incident response plans with written procedures and testing.
Annual compliance audit and testing
An annual audit of compliance with the Security Rule, vulnerability scanning at least every six months, and penetration testing at least every 12 months.
Business associate verification
Business associates would have to verify to covered entities at least every 12 months that they have deployed the required technical safeguards, through a written analysis by a subject matter expert.
Common mistakes
Proposed versus effective
Nothing in the NPRM is enforceable until a final rule publishes with an effective date and compliance period. Plan against it; do not cite it as current law.
Prescriptive controls versus the risk analysis
The proposal adds specific controls, but the risk analysis remains the organizing requirement. Entities that implement the list without the analysis would still be out of compliance.
HIPAA covered entity versus everyone
The rule binds covered entities and business associates. Health apps and data brokers outside HIPAA are governed by the FTC's Health Breach Notification Rule and state law instead.
Sources
;
See it in the live data.
Follow the Federal Register record