Do you want to pay a healthcare bill online? Make a payment now

A significant update to the HIPAA Security Rule was proposed on December 27, 2024 by the U.S. Department of Health and Human Services (HHS). The proposed rule signals a stricter, more prescriptive era of cybersecurity expectations for electronic protected health information (ePHI) from HHS. What remains hard to pin down is timing: how long it will take for a proposal to become a final rule, what the final requirements will look like after stakeholder input, and how long organizations will have to comply once a final rule is issued. 

The policy momentum behind the overhaul is clear. Axios reporting on the proposal has linked the overhaul to high-impact healthcare cyber incidents, most notably the 2024 Change Healthcare attack. There is also a growing view among regulators and some security experts that a meaningful share of breaches are preventable when baseline controls are consistently implemented. 

The intent of the rule, separate from the timing of enforcement, is important for healthcare organizations to consider and act on. Healthcare is a constant cyber target and organizations must defend against ransomware, extortion, third-party breaches and prolonged outages. The question is not whether the HIPAA overhaul will accelerate cybersecurity work, but whether organizations will do the work to prevent the next incident. 

That decision is being made against a difficult financial backdrop for many providers, especially as cost pressures continue to increase and reimbursement rates decline. In this environment, security investments tied to a proposed rule, especially one with uncertain timing, can fall behind competing operational priorities. The risk is that postponement does not remove the obligation, but rather increases the odds the organization is forced to act under duress, either due to updated enforcement timeline or a cyber event. 

What the proposal signals, in plain terms 

The direction HIPAA rule update is clear: healthcare will need to move away from flexible security interpretations to defined minimums that can be audited and enforced more consistently. In practice, that will mean that controls once treated as a best practice will increasingly be treated as baseline safeguards, including multi-factor authentication (MFA), encryption, threat scanning, and written security plans with defined recovery procedures. 

Requirements may shift in the final text, but healthcare leaders can safely assume that the bar for measurable security practices are rising. 

Ultimately, this is an attempt to close the gap between what modern threats exploit and what many organizations can prove they have implemented across a complex environment of legacy systems, specialized devices, multiple cloud footprints and sprawling vendor dependencies. 

A key operational implication is enforcement. The proposal expands enforceable violations and increasing potential civil penalty exposure on a per-violation basis. For large, distributed enterprises, that turns “security maturity gaps” into a governance and controls problem with direct regulatory consequences. 

Why the timeframe remains ambiguous—and why that matters 

Rulemaking is a process with variable duration: proposals, comment periods, revision cycles and final rules with phased compliance windows. For healthcare, timing is further complicated by the differences in organization types and sizes.  

Large integrated delivery networks, academic medical centers and payers do not have the same constraints as rural hospitals and small physician groups. That often results in intense debate over feasibility, cost and sequencing. The resulting debate can slow timelines and reshape requirements. 

The practical implication is that planning around a single, unknown effective date is unreasonable. If the final rule is delayed, a date-driven plan can lose momentum. If the final rule arrives sooner than expected, the organization scrambles, pays more for rushed implementation and increases operational risk. 

A better approach is to plan around capabilities that are valuable under any regulatory outcome: the ability to prevent common intrusion paths, limit blast radius, detect abnormal activity quickly and restore critical services reliably. 

The operational cost of waiting is higher than the compliance cost of starting 

Delaying cybersecurity implementations may be a harsh reality for healthcare leaders who face competing priorities, constrained staffing and budget pressure. However, the associated costs of cyber-attacks compound in ways that cannot be captured in a single line item. 

In the unfortunate event of a major cyber incident, the impact can reach beyond the expected cyber realm and include:  

  • Care delivery disruption: downtime changes clinical workflows, delays services, increases error risk, and forces workarounds that degrade safety and productivity. 
  • Operational throughput loss: scheduling backlogs, call center surges, manual documentation, and diverted leadership attention can persist for weeks. 
  • Revenue cycle disruption: eligibility checks, coding, claims workflows, billing, and  collections slow or halt, creating cash flow stress and reconciliation complexity. 
  • Regulatory and legal exposure: incident response becomes multi-front—technical containment, notifications, contractual obligations, audits,  and potential enforcement. 
  • Reputational damage: trust erosion can affect patient engagement, workforce morale, and partner relationships. 

Often for other healthcare organizations, the real risk is not only the event itself but the duration and complexity of recovery. Larger environments often take longer to fully restore because they have more dependencies, more bespoke integrations and more variation in security maturity across business units and acquired entities. 

What to do now: “regret-minimizing” priorities for enterprise healthcare 

Healthcare organizations do not need to wait for the final rule to begin. The goal is not to implement all of the expected safeguards at once, but to work around the highest-risk failure modes first. 

1. Make identity the front door—and reinforce it 

Credential theft and misuse remain a dominant intrusion path. Prioritize multi-factor authentication coverage in this order: privileged accounts, remote access, administrator actions, and high-value clinical and financial systems. Complement MFA with tighter privileged access management, better session logging, and stronger account lifecycle controls (rapid deprovisioning, role-based access, and separation of duties).

This is not just a security upgrade. It reduces the probability that a single, phished credential becomes enterprise-wide compromise.

2. Treat asset visibility as a prerequisite, not a technical nice-to-have 

Healthcare organizations struggle to secure what they cannot inventory. Build a living asset view across endpoints, servers, cloud workloads, applications and networked medical/IoT devices where applicable. Link the inventory to ownership and criticality so remediation is operationally possible. Visibility is the foundation for vulnerability management, segmentation, incident response and third-party risk. 

No longer is scanning environments once or even yearly is enough, rather the rule of thumb is to show what exists today, what is exposed and who is accountable to resolve issues. 

3. Run vulnerability management as a business process 

Scanning tools are widely deployed, while disciplined remediation is not. Healthcare organizations should prioritize based on exploitability, exposure and system criticality, and not generic severity scores alone. Establish patching SLAs tied to risk tiers, and investing in compensating controls for systems that cannot be patched quickly, including: segmentation, application allowlisting, strict access controls and enhanced monitoring. 

Leaders should ask themselves: When a high-risk vulnerability is announced, can we identify affected systems quickly? Can we prove closure within a defined window? 

4. Encrypt with intent, and govern exceptions tightly 

Encryption is increasingly treated as baseline for ePHI, but coverage gaps persist across data flows, legacy platforms and backups. Enterprises should accelerate encryption in transit and at rest, while acknowledging that exceptions sometimes exist due to technical or clinical constraints. The key is governance: documented exceptions, compensating controls and time-bound remediation plans, not permanent waivers by default. 

5. Build recovery muscle: backups are not resilience unless restoration is routine 

Ransomware is an outage problem as much as a data problem. Resilience requires more than backup existence: immutable/offline backups where appropriate, clear recovery objectives for critical services, and routine restore testing that simulates real conditions including degraded staff availability and vendor coordination. Measure time-to-restore for critical workflows, not just systems. 

A useful maturity marker is whether the organization can restore a prioritized set of clinical and revenue-cycle functions within a planned window, under pressure, with documented decision rights. 

Just as importantly, recovery should not rely on the availability of a single individual. Critical knowledge, responsibilities, and decision-making authority should be documented and shared across the organization. 

6. Treat third-party exposure as first-party risk 

Business associates and vendors frequently sit inside critical workflows and data paths. Enterprises should move beyond questionnaire-based compliance toward evidence-based assurance, especially for high-impact vendors. Contracts should define minimum controls, notification timelines, and cooperation obligations during incidents. Internally, vendor access should be segmented, monitored, and least-privilege by design. 

Leaders should assume that a portion of their risk resides in ecosystems that they do not fully control and manage accordingly. As a result, organizations are likely to place greater emphasis on vendor assurance, potentially leading to enhanced security expectations, contractual requirements, and ongoing evidence of control effectiveness from third-party providers. 

What boards and executive teams should measure 

Enterprise healthcare needs cybersecurity metrics that reflect real outcomes, not activity. A concise executive dashboard can include: MFA coverage for privileged access, percentage of assets inventoried with accountable owners, patch SLAs met for high-risk exposures, backup restore test success rates, mean time to detect and contain and the number of critical vendors with verified security evidence. 

These measures align with the likely direction of regulation, but more importantly, they align with the practical goal: reducing the likelihood and impact of incidents that disrupt care and operations. 

The bottom line 

The proposed HIPAA Security Rule overhaul introduces timing ambiguity, not strategic ambiguity. The industry is moving toward clearer, more enforceable cybersecurity minimums. Enterprise healthcare organizations should plan for uncertainty by accelerating the fundamentals that are durable under any final rule: strong identity controls, asset visibility, disciplined vulnerability remediation, encryption with governed exceptions, tested recovery and tighter third-party risk management. 

In cybersecurity, waiting for certainty is often indistinguishable from waiting for an incident. The organizations that fare best will be the ones that treat ambiguity as a reason to execute—not as a reason to defer. 

Get InstaMed In Your Inbox!

Join our mailing list to stay up-to-date with the latest industry trends, insights, innovation and technology!