Get Compliance Tools

HIPAA 2025 Proposed Rule Changes: What to Expect

Last updated: March 2026 | Regulatory Deep Dive

Regulatory Overview

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has proposed several rule changes to HIPAA regulations for 2025, aimed at strengthening privacy protections, updating technology requirements, and addressing contemporary healthcare challenges including telemedicine, electronic health information exchange, and cybersecurity threats. These proposed changes reflect OCR's evolving enforcement priorities and the healthcare industry's transition to digital-first operations.

Proposed Change Categories

The 2025 proposed changes focus on several key areas:

Important Note: These are proposed changes and not yet final rules. The rulemaking process includes public comment periods, stakeholder feedback, and OCR review before final adoption. Implementation timelines and specific requirements may change before finalization.

Key Proposed Changes

1. Enhanced Encryption Requirements

The proposal would strengthen encryption standards for data at rest and in transit:

2. Breach Notification Timeline Acceleration

Proposed changes would accelerate breach notification requirements:

3. Telemedicine Privacy Standards

New regulations would address telemedicine-specific privacy and security requirements:

4. Information Blocking Enhancements

Updates to align with ONC interoperability requirements:

5. Business Associate Oversight

Proposed enhancements to covered entity oversight of Business Associates:

6. Cybersecurity Incident Response

New requirements for cybersecurity incident detection and response:

Stakeholder Feedback: The healthcare industry has raised concerns about implementation costs and timelines for these proposed changes, particularly for smaller organizations and those with legacy systems. OCR is expected to provide transition periods and technical assistance.

Implementation Considerations

Timeline for Organizations

  1. 2025-2026 (Current Period): Proposed rules under review; public comment period may still be active
  2. 2026-2027 (Anticipated): Final rules may be published; typically 1-2 year implementation period begins
  3. 2027-2028 (Expected): Full compliance required for final rules; transition period ends

Immediate Action Items

Preparation Strategies

Risk Mitigation

Frequently Asked Questions

When will these proposed changes become final rules?

The proposed changes are currently under review by OCR and may still be in the public comment period. Typically, the federal rulemaking process takes 1-2 years from proposal to final rule. Once a rule is finalized (published in the Federal Register), covered entities typically receive 1-2 years for implementation before the rule becomes enforceable. However, some requirements may have different effective dates. Organizations should monitor the HHS OCR website and Federal Register for updates on the status of these proposed rules. Legal counsel can help track these developments.

What should we do now while these rules are still proposed?

Organizations should take proactive steps to prepare for potential final rules: (1) Assess current compliance against proposed requirements, (2) Identify gaps in current practices and security infrastructure, (3) Begin budgeting for necessary system upgrades and enhancements, (4) Evaluate vendor capabilities for compliance with proposed standards, (5) Develop preliminary implementation plans, and (6) Establish monitoring processes to track regulatory developments. Even if proposals change, these actions will strengthen overall HIPAA compliance and security posture. Additionally, many proposed requirements reflect industry best practices that organizations should implement regardless of regulatory status.

Will there be an implementation grace period after rules are finalized?

Historically, yes. When HIPAA rules are finalized, OCR typically provides an implementation period (usually 12-24 months) before enforcement begins. However, the specific timeline varies by requirement complexity. Some technical requirements may have longer timelines than administrative requirements. The final rule will specify implementation deadlines and any phase-in requirements. Organizations should note that demonstrating good faith compliance efforts during implementation periods helps mitigate penalties if violations are discovered. Starting implementation early (before the official requirement date) strengthens this position and demonstrates organizational commitment to compliance.

How might encryption requirement changes affect our current systems?

If the proposed encryption requirements (AES-256 for data at rest, TLS 1.2+ for transit) are finalized, organizations currently using older encryption standards will need to upgrade. This affects: (1) Database encryption for stored PHI, (2) All network communications transmitting PHI, (3) Encrypted backups and archived data, and (4) Encryption for data on mobile devices and removable media. The transition may require: (1) System upgrades or replacements, (2) Re-encryption of existing data, (3) Vendor compatibility assessments, and (4) Testing to ensure encrypted systems perform adequately. Most modern systems already support these standards, but legacy systems may require investment to upgrade or replace. Organizations should begin assessing their encryption capabilities now.

Stay Ahead of Regulatory Changes

Medcurity monitors HIPAA regulatory developments and helps organizations prepare for proposed rule changes with compliance roadmaps and security assessments.

Get Your Compliance Roadmap