HIPAA 2025 Proposed Rule Changes: What to Expect
Regulatory Overview
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has proposed several rule changes to HIPAA regulations for 2025, aimed at strengthening privacy protections, updating technology requirements, and addressing contemporary healthcare challenges including telemedicine, electronic health information exchange, and cybersecurity threats. These proposed changes reflect OCR's evolving enforcement priorities and the healthcare industry's transition to digital-first operations.
Proposed Change Categories
The 2025 proposed changes focus on several key areas:
- Enhanced privacy protections for sensitive health information
- Updated cybersecurity and encryption standards
- Telemedicine and remote care regulations
- Information blocking and interoperability requirements
- Data breach notification timelines and procedures
- Business Associate management and oversight
Key Proposed Changes
1. Enhanced Encryption Requirements
The proposal would strengthen encryption standards for data at rest and in transit:
- Data at Rest: Requirement for AES-256 or equivalent encryption for stored PHI
- Data in Transit: Mandatory TLS 1.2 or higher for all electronic transmission of PHI
- Key Management: Enhanced requirements for encryption key storage, rotation, and destruction
- Legacy Systems: Transition period for organizations using older encryption standards
2. Breach Notification Timeline Acceleration
Proposed changes would accelerate breach notification requirements:
- Current Requirement: Notify individuals within 60 days of discovery
- Proposed Change: Reduce to 30 days of discovery for most breaches
- Emergency Notifications: Requirement for immediate (24-48 hour) notification of critical breaches affecting sensitive data
- OCR Notification: Same-day or next-day notification to OCR for breaches affecting 100+ individuals
3. Telemedicine Privacy Standards
New regulations would address telemedicine-specific privacy and security requirements:
- Platform Certification: Requirement that telemedicine platforms meet minimum security standards
- Patient Consent: Enhanced informed consent requirements for telemedicine sessions
- Recording Prohibition: Prohibition on recording telemedicine sessions without explicit written consent
- Third-Party Access: Restrictions on data sharing with non-healthcare third parties using telemedicine data
- Location Privacy: Requirements to protect patient location information during telemedicine sessions
4. Information Blocking Enhancements
Updates to align with ONC interoperability requirements:
- API Standards: Requirement for FHIR API availability for patient-directed data exchange
- Response Time: Mandate for API response within specific timeframes (e.g., 30 seconds)
- Documentation: Requirement to document API capabilities and limitations
- Third-Party App Support: Requirements for supporting patient-authorized third-party applications
5. Business Associate Oversight
Proposed enhancements to covered entity oversight of Business Associates:
- Annual Risk Assessment: Requirement for annual security risk assessments of all Business Associates
- Breach Liability: Covered entities held more directly liable for Business Associate breaches
- Audit Rights: Expanded audit and inspection rights for Business Associates
- Termination Rights: Clearer standards for terminating Business Associate relationships for non-compliance
6. Cybersecurity Incident Response
New requirements for cybersecurity incident detection and response:
- Monitoring Requirement: Mandate for continuous monitoring and logging of system access
- Incident Detection: Requirement for automated threat detection systems
- Response Plan: Enhanced incident response plan requirements with specific timelines
- Ransomware Standards: Specific requirements for preventing and responding to ransomware attacks
- Forensic Analysis: Requirement for forensic analysis of significant breaches
Implementation Considerations
Timeline for Organizations
- 2025-2026 (Current Period): Proposed rules under review; public comment period may still be active
- 2026-2027 (Anticipated): Final rules may be published; typically 1-2 year implementation period begins
- 2027-2028 (Expected): Full compliance required for final rules; transition period ends
Immediate Action Items
- Monitor HHS OCR website for updates on final rule status
- Conduct gap analysis comparing current practices to proposed requirements
- Assess encryption capabilities and timeline for upgrades to AES-256
- Review current breach notification procedures for alignment with accelerated timelines
- Evaluate telemedicine platforms for proposed privacy and security standards
- Assess Business Associate audit and monitoring capabilities
- Review incident response procedures for alignment with proposed requirements
Preparation Strategies
- Budget for system upgrades and security infrastructure improvements
- Evaluate vendor compliance with proposed requirements (EHR, billing, clearinghouses)
- Begin planning for encryption standard transitions
- Establish automated monitoring and incident detection systems
- Develop enhanced Business Associate audit procedures
- Update privacy policies and patient agreements to address telemedicine requirements
- Prepare staff training materials on new requirements as they are finalized
Risk Mitigation
- Develop transition plans that exceed minimum proposed requirements
- Invest in modern security infrastructure ahead of regulatory requirements
- Establish cybersecurity insurance coverage for potential breach scenarios
- Engage compliance counsel to monitor regulatory changes
- Participate in industry groups tracking regulatory developments
- Document all compliance efforts to demonstrate good faith implementation
Frequently Asked Questions
When will these proposed changes become final rules?
The proposed changes are currently under review by OCR and may still be in the public comment period. Typically, the federal rulemaking process takes 1-2 years from proposal to final rule. Once a rule is finalized (published in the Federal Register), covered entities typically receive 1-2 years for implementation before the rule becomes enforceable. However, some requirements may have different effective dates. Organizations should monitor the HHS OCR website and Federal Register for updates on the status of these proposed rules. Legal counsel can help track these developments.
What should we do now while these rules are still proposed?
Organizations should take proactive steps to prepare for potential final rules: (1) Assess current compliance against proposed requirements, (2) Identify gaps in current practices and security infrastructure, (3) Begin budgeting for necessary system upgrades and enhancements, (4) Evaluate vendor capabilities for compliance with proposed standards, (5) Develop preliminary implementation plans, and (6) Establish monitoring processes to track regulatory developments. Even if proposals change, these actions will strengthen overall HIPAA compliance and security posture. Additionally, many proposed requirements reflect industry best practices that organizations should implement regardless of regulatory status.
Will there be an implementation grace period after rules are finalized?
Historically, yes. When HIPAA rules are finalized, OCR typically provides an implementation period (usually 12-24 months) before enforcement begins. However, the specific timeline varies by requirement complexity. Some technical requirements may have longer timelines than administrative requirements. The final rule will specify implementation deadlines and any phase-in requirements. Organizations should note that demonstrating good faith compliance efforts during implementation periods helps mitigate penalties if violations are discovered. Starting implementation early (before the official requirement date) strengthens this position and demonstrates organizational commitment to compliance.
How might encryption requirement changes affect our current systems?
If the proposed encryption requirements (AES-256 for data at rest, TLS 1.2+ for transit) are finalized, organizations currently using older encryption standards will need to upgrade. This affects: (1) Database encryption for stored PHI, (2) All network communications transmitting PHI, (3) Encrypted backups and archived data, and (4) Encryption for data on mobile devices and removable media. The transition may require: (1) System upgrades or replacements, (2) Re-encryption of existing data, (3) Vendor compatibility assessments, and (4) Testing to ensure encrypted systems perform adequately. Most modern systems already support these standards, but legacy systems may require investment to upgrade or replace. Organizations should begin assessing their encryption capabilities now.
Stay Ahead of Regulatory Changes
Medcurity monitors HIPAA regulatory developments and helps organizations prepare for proposed rule changes with compliance roadmaps and security assessments.
Get Your Compliance Roadmap