On December 27, 2024, HHS announced a proposed HIPAA Security Rule update that would turn many flexible safeguards into firm requirements. It is still a proposal, and the final version could look different. However, most of what it asks for is basic security hygiene, so practices that start now will be ahead no matter how the rule lands.
Where the proposal stands today
The Office for Civil Rights published the notice of proposed rulemaking in the Federal Register on January 6, 2025. Public comments are due by March 7, 2025. After that, HHS must review the comments before it can issue a final rule.
That means nobody knows the final wording or the compliance deadline yet. A new administration also took office on January 20, which adds uncertainty to the timing. Until a final rule takes effect, the current Security Rule still applies.
So treat this as a planning window, not a panic. The practical question is which changes you would want anyway.
What the HIPAA Security Rule update would change
The biggest structural change is simple to state. HHS proposes to remove the distinction between “required” and “addressable” implementation specifications. Almost everything would become required, with limited exceptions.
According to the HHS fact sheet on the proposed rule, the proposal would also:
- MFA: multifactor authentication would become mandatory, with limited exceptions.
- Encryption: ePHI would need encryption at rest and in transit, with limited exceptions.
- Asset inventory and network map: practices would document every technology asset and how ePHI moves, reviewed at least every 12 months.
- Testing: vulnerability scans at least every six months and a penetration test at least once a year.
- Recovery: written procedures to restore certain systems and data within 72 hours.
- Audits: a compliance audit at least once every 12 months.
- Business associates: annual verification of their technical safeguards, with written certification.
Why “addressable” mattered so much
In my experience, “addressable” was the word that let small practices put off hard projects. Encryption on every laptop felt expensive, so someone documented a reason to skip it. Then the reason stayed in a binder for years.
The proposal would close that door. As a result, practices should expect less room for judgment calls and more demand for proof. Written policies, dated reports, and current diagrams would carry real weight.
What practices can do now
You do not need a final rule to act. The steps below match the proposal, and each one also lowers your real risk today.
Build the asset inventory and network map
First, list every device, application, and cloud service that touches patient data. Include the EHR, the billing system, imaging tools, patient portals, and personal phones used for work. Then sketch how data moves between them, even if the first map is rough.
This step usually takes longer than people expect. However, it also drives every other decision, because you cannot protect systems you do not know about.
Turn on MFA and encryption everywhere you can
Next, enforce MFA on email, remote access, the EHR, and every admin account. After that, confirm that laptops and mobile devices use full-disk encryption. Most of this is configuration work in tools you already own.
Test restores against a clock
The 72-hour restoration target is a useful test. Pick your most critical system and time a full restore. If it takes longer than three days, you have found a gap worth fixing now.
Write down what you already do
Many practices do more than their paperwork shows. The front desk locks screens, the office manager removes access when people leave, and backups run every night. However, none of it counts well in an audit if nobody wrote it down.
So capture current practices in short, dated procedures. Keep them plain and specific. A one-page procedure that staff actually follow beats a thick template nobody reads.
Scanning and penetration testing, explained
These two terms get mixed up often, so it helps to separate them. A vulnerability scan is an automated check that looks for missing patches and weak settings across your systems. It is broad, repeatable, and fairly quick.
A penetration test goes further. A qualified tester actively tries to break in, the way an attacker would, and reports what worked. It is deeper, slower, and usually done by an outside firm.
The proposal would require both on a set schedule. If you have never done either, start with a scan. Then use the results to fix the easy problems before paying for a penetration test.
Do not forget business associates
Business associates include your IT provider, billing service, cloud hosting vendor, and transcription service. Under the proposal, they would need to verify their safeguards and provide written certification each year.
So start asking now. Request a summary of each vendor’s security controls and find out who signs their compliance statements. Also review your business associate agreements, because many were signed years ago and never updated.
Budget for the work honestly
Some items on this list cost little. MFA and encryption often come with licenses you already pay for. Other items, such as annual penetration testing and a formal compliance audit, need outside help and a real budget line.
Plan this year’s budget with those costs in mind. That way, a final rule does not force a rushed purchase later. It also gives you time to compare options instead of buying the first thing a vendor pitches.
Finally, consider filing a comment before March 7 if a requirement would be hard for a small practice. HHS asked for feedback, and practical input from smaller providers helps shape the result.
How WEBIT approaches this
We start with the inventory and network map, because every other control depends on them. Then we align MFA, encryption, backups, and scanning to the proposed requirements and document each one so the proof is ready. Our cybersecurity team handles the technical work while practice leaders stay focused on patients.
We also plan the larger items, such as testing and audits, as part of a longer IT roadmap. We watch the rulemaking closely and adjust plans if the final text changes. This HIPAA Security Rule update is a moving target, so we build for the controls that matter in any version.
Key takeaways
- The HIPAA Security Rule update is still a proposal, and comments are due March 7, 2025.
- HHS proposes making nearly all safeguards required, including MFA and encryption.
- An asset inventory and network map are the best first step.
- Business associates would need to certify their safeguards every year.
- Most proposed controls reduce real risk today, so starting early pays off.
Related from WEBIT: dental IT support in Naperville, medical IT support in Naperville, and cyber insurance readiness checklist.
Want help mapping where your practice stands against the proposal? Talk to an owner.





