Blog - risk3sixty

HIPAA Compliance Is Changing: 8 Security Rule Updates Coming in 2026

Written by Jeremy Sharp | Jun 26, 2025, 4:00:00 AM

Check out our HIPAA Risk Analysis Guide for practical steps on how to assess, document, and strengthen your security program.

For those in the healthcare compliance space, HIPAA compliance is practically synonymous with patient care. The Health Insurance Portability and Accountability Act (HIPAA) — and, more specifically, its Security Rule — has dictated requirements for healthcare providers and their partners since it became law in 1996.  

While there have been several updates over the past two decades, the most significant change to date is now on the horizon. Earlier in 2025, the Department of Health & Human Services (HHS) — the federal agency responsible for enforcing HIPAA compliance — released their proposal for some far-reaching changes to the rule.  

While these changes haven’t yet been finalized, anyone regularly dealing with HIPAA should familiarize themselves with the potential changes that may soon affect them.  

In this post, I’ll break down some of the most significant changes I see, link you out to the source documentation for you to read deeper on your own, and provide you with the timeline for implementation and enforcement. Let’s dive in! 

8 Key HIPAA Compliance Changes Affecting Business Associates

1. Annual Compliance Audits.

The most consequential change here is the requirement for a formal audit every 12 months, the results of which all BAs are required to share (each year after the audit concludes) with each of their clients who are CEs. This will put a significantly brighter spotlight on HIPAA compliance than ever before.

The enhanced specificity of BAAs (see point 2, below) will mean that even minor gaps in a BA’s security posture would likely result in a breach of contract that would then have to be shared with every single client—greatly increasing the seriousness of compliance without increasing the burden on HHS to police thousands of entities across the country.

2. Business Associate Agreement (BAA) Enhancements.

While BAAs are not new, the proposed changes enhance the detail that’s required to be in the agreements. CEs can no longer use blanket terms such as “all parties must comply with HIPAA,” the agreements need to have specific security requirements listed within them, including MFA, encryption, incident reporting timelines (24-hours), annual audits, and use of NIST-aligned security practices.

3. Expanded Risk Assessment Requirements.

All organizations will need to conduct more detailed and documented risk assessments, and know what to do with those findings to ensure they’re driving meaningful security improvements.One option would be to align with the NIST Cybersecurity Framework for simpler security compliance.

One of the most specific changes will be that the risk assessment will need to formally review an asset inventory and network map (see point 4, below), and should specifically identify all threats to the confidentiality, integrity, and availability of ePHI.

4. Must Develop a Network Map for ePHI Movement.

For any systems handling ePHI, regulated entities must detail exactly how the ePHI will transit through their network and where it would be stored—and should understand what technology assets would ever be touched by the ePHI.

Even if systems are designed not to store or process ePHI, entities must understand how, if any ePHI were to enter the system, it would do so. These details would all need to be documented and then reviewed annually during the risk assessment.

5. Stronger Security Incident & Breach Reporting Obligations.

The proposed change clarifies the definition of “security incidents” and in so doing naturally expands the reporting requirements around incidents. All covered entities are required to maintain defined incident response plans that are tested annually, and, via updated Business Associate Agreements (BAAs), all Business Associates (BAs) are required to report incidents to a Covered Entity (CE) within 24 hours of activating their incident response plan.

  • The proposed rule change doesn’t really expand the definition of incidents, but it seeks to clarify the existing language to make it clear that the same current reporting requirements also apply to smaller-scale incidents that don’t necessarily involve a breach of sensitive information. According to 45 CFR §164.304, an incident is currently defined as:

“The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.”

  • The Notice of Proposed Rulemaking states they wish to add “two numbered paragraphs to delineate the two separate categories of security incidents,” so I expect them to simply split out the last clause regarding “interference with system operations.”
  • This change, combined with the tighter, 24-hour reporting requirements for incidents, means there will likely be a LOT more notifications of security incidents. The Department is explicitly doing this in response to the SolarWinds hack. HHS wants more organizations to be aware of ongoing incidents while they’re happening to hopefully limit the downstream effects of the incident.
  • These changes are enforced by requiring changes to BAAs, so be prepared to have clients who are CEs reach out to negotiate updates to their BAAS.

6. Mandatory Multi-Factor Authentication (MFA).

In almost every single scenario where someone is accessing ePHI, MFA will be required. Any exceptions will need to be formally documented and tied to a specific, risk-based justification—and the exceptions are expected to be isolated occurrences, not blanket approvals.

7. Increased Encryption Requirements.

Encryption is no longer an “addressable” requirement; it’s effectively mandatory. Further, encryption must meet “recognized security practices,” such as NIST (SP 800-111 for encryption of data at rest, and SP 800-52 for data in transit) or FIPS 140-3 validated algorithms.

8. Stricter Workforce Training Requirements.

As humans are typically the weakest link in any organization’s security perimeter, HHS is recommending an overhaul of workforce security awareness training programs. The Department is clarifying that training must be “ongoing,” tailored to each employee’s job role, and, crucially, tested for effectiveness (through quizzes, phishing simulations, random inspections, etc.).

Further, updated training must be rolled out after a security incident, when a new system that handles ePHI is brought online, and even whenever a security policy is updated. The requirement also extends to ANY person in the organization who might handle ePHI—from interns to vendors to full-time employees. All CEs will be expected to retain records of who was trained, when the training was administered, and on the content of each training.

The annual one-size-fits-all mandatory training most organizations have historically relied upon is no longer enough—all CEs will need to increase the frequency, detail, level of rigor, and documentation they retain for all training.

This list is by no means exhaustive. There are plenty of great resources available across the web, but if you want to go straight to the source, you can read all 400-ish pages of the proposed change in the Federal Register

HIPAA Compliance Implementation Timeline for 2026

  • Proposed Rule Published: January 6, 2025 
  • Public Comment Period Closed: March 7, 2025 
  • Publication Date of Formal Changes: Unknown; but expected in late 2025 or early 2026 
  • Effective Date of Final Rule: 60 days after publication in the Federal Register 
  • Compliance Deadline: 180 days from the effective date to fully implement the new requirements

These timelines mean all CEs will have eight months from when the changes are formally published to bring themselves in alignment with the new standards. In totality, we’re likely not looking at mandatory compliance until, at the very earliest, Q2 2026.  

So in summary, large changes are coming soon. Nobody should panic with a runway as long as this, but all entities handling ePHI should absolutely begin planning to ensure an orderly and effective rollout of all new policies and procedures.  

Need help getting ahead of the proposed HIPAA compliance changes? Risk3sixty can help you assess your current state, prioritize what’s next, and build a roadmap to compliance—before the clock runs out. Contact us to get started.