← All guides

The 2025 Security Rule Proposal: What Would Change

Guidance and regulation9 min read

The 2025 Security Rule Proposal: What Would Change

On January 6, 2025 HHS published a notice of proposed rulemaking to modernize the Security Rule, the first substantive rewrite since 2013. The stated reason is the gap between the rule's flexible, largely undefined standards and the threat environment that produced record breach counts. The proposal removes the distinction between required and addressable implementation specifications, making nearly everything required with narrow exceptions, and adds specific technical controls with specific timelines.

The comment period closed in March 2025 with substantial industry opposition on cost and prescriptiveness, and the final rule has not issued as of this writing. Track the Federal Register record and OMB's regulatory agenda rather than assuming a date; this site's guidance feed carries the Federal Register documents as they publish.

Whatever survives to the final rule, the proposal is the clearest statement of what OCR considers reasonable and appropriate today, and most of it aligns with the HPH Cybersecurity Performance Goals that HHS already expects entities to meet.

Key points

  • No more addressable

    All implementation specifications would be required, with limited exceptions that must be documented. The flexibility that let entities defer encryption or MFA would end.

  • Inventory and network map

    A written technology asset inventory and a network map of ePHI movement, updated at least every 12 months and after material changes, feeding a written risk analysis with specified contents.

  • Encryption and MFA

    Encryption of ePHI at rest and in transit, and multi-factor authentication for access to ePHI systems, each with narrow, documented exceptions such as certain medical devices.

  • Restoration within 72 hours

    Procedures to restore the loss of certain relevant electronic information systems and data within 72 hours, backed by a criticality analysis, and incident response plans with written procedures and testing.

  • Annual compliance audit and testing

    An annual audit of compliance with the Security Rule, vulnerability scanning at least every six months, and penetration testing at least every 12 months.

  • Business associate verification

    Business associates would have to verify to covered entities at least every 12 months that they have deployed the required technical safeguards, through a written analysis by a subject matter expert.

Common mistakes

  • Proposed versus effective

    Nothing in the NPRM is enforceable until a final rule publishes with an effective date and compliance period. Plan against it; do not cite it as current law.

  • Prescriptive controls versus the risk analysis

    The proposal adds specific controls, but the risk analysis remains the organizing requirement. Entities that implement the list without the analysis would still be out of compliance.

  • HIPAA covered entity versus everyone

    The rule binds covered entities and business associates. Health apps and data brokers outside HIPAA are governed by the FTC's Health Breach Notification Rule and state law instead.

Sources

;

See it in the live data.

Follow the Federal Register record