Get Demo
↑

HIPAA Security Rule 2025–2026 Update: What Changed and What Did Not

Jan 2025 Security Rule NPRM proposed MFA, encryption, and asset inventory.

Published: September 2026 Compliance · HIPAA 8–12 min read

HHS published a major HIPAA Security Rule NPRM on January 6, 2025 (RIN 0945-AA22, 90 FR 898). Headlines often treat the proposal as if it already rewrote ePHI safeguards. It has not. As of September 2026 there is no final rule; the existing Security Rule (45 CFR Part 164, Subpart C) remains in effect.

Related: HIPAA hub · Encryption · MFA · CSA for HIPAA.

Security Rule NPRM — not final: Jan 6, 2025 NPRM (RIN 0945-AA22, 90 FR 898) proposed MFA, encryption at rest/in transit as required, asset inventory, and related enhancements. No final rule as of September 2026; the Unified Agenda projects final action around July 2027 (planning estimate only). The current Security Rule remains in effect; proposed changes are not mandatory until a final rule. Encryption at rest/transit is addressable under §164.312 today; MFA is not a current standalone required standard.

Required vs Addressable (Security Rule) — 45 CFR 164.306(d): Required implementation specifications must be implemented. Addressable specs: implement if reasonable and appropriate; if not, document why and implement an equivalent alternative measure if reasonable and appropriate. Addressable ≠ optional.

Current Status (2025–2026)

What Not to Claim

Do not tell boards or customers that “new mandatory MFA and encryption are already law.” Until a final rule is published and effective, encryption remains addressable under §164.312, and MFA is not a standalone required Security Rule standard (though it is often reasonable and appropriate under access control / authentication).

Prudent Readiness Without Premature Claims

  1. Complete / refresh the §164.308(a)(1) risk analysis covering all ePHI systems.
  2. Document Required vs Addressable decisions with equivalent alternatives where applicable.
  3. Inventory assets that create, receive, maintain, or transmit ePHI (aligns with NPRM direction and good security practice).
  4. Adopt MFA and strong encryption where risk analysis supports them — and track them as programme priorities for any future final rule.
  5. Map evidence in CyberSilo CSA and continuous monitoring via ThreatHawk.

How CyberSilo Helps

Prepare for NPRM Direction Without Misstating Current Law

Map today’s Security Rule controls and track readiness for proposed MFA/encryption changes in one evidence plane.

Frequently Asked Questions

Did the HIPAA Security Rule change in 2025 or 2026?

HHS issued an NPRM in January 2025 proposing major changes. No final Security Rule update was in effect as of September 2026; the current Security Rule still governs.

Are MFA and encryption mandatory under HIPAA today?

Encryption at rest and in transit is addressable under §164.312. MFA is not a current standalone required standard. The NPRM proposed making several of these required — that is not final.

What should we do while waiting for a final rule?

Maintain Required specifications, document Addressable decisions, run risk analysis, and implement MFA/encryption where reasonable and appropriate.

HIPAA hub · §164.312 · Encryption · MFA · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!