Proposed updates to Security Rule reshape cybersecurity planning

After nearly two decades without a major refresh, the proposed updates to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule are prompting healthcare organizations to rethink how they protect data, respond to incidents and support patient care. For Matthew Webb, Assistant Vice President, Cyber Risk Management at HCA Healthcare, the changes are overdue.

The proposed rule changes signal the most significant changes since the HIPAA Security Rule was first published in 2003—shifting expectations from flexible guidance to enforceable technical controls.

Matthew Webb

“We’re at a point where the environment has changed. As threats & technology continue to evolve, healthcare organizations need to understand how to better protect ePHI.”

Matthew Webb

Why the update matters now

Healthcare systems are managing more digital complexity than ever before. Artificial intelligence has made phishing and impersonation more convincing, while cyberattacks continue to test the limits of staffing, technology and recovery planning.

Stories in the news underscore the risk. Webb points to a recent vendor cyberattack as an example of how disruptive these incidents can be—not just from a security standpoint but also across operations, supply chain and patient care. Recovery can take time, and the full scope of impact is often not immediately clear.

Stronger requirements around identity and access, data safeguards and reporting are intended to help organizations better defend the systems that enable patient care.

Four emerging priorities

  1. Incident response timing. Organizations must be prepared to identify, investigate and report incidents quickly—potentially within 24 hours—while still confirming the facts.
  2. Phishing-resistant multifactor authentication (MFA). Weak identity controls remain a common entry point for attackers. The proposed rule makes clear that stronger authentication, including MFA, is essential across systems accessing electronic Protected Health Information (ePHI).
  3. Inventory. You can protect only what you know about, and that starts with mapping where ePHI resides, which systems are most critical, and how data moves across EMRs and supporting platforms. Requirements will expand to include detailed asset inventories and network mapping—even for emerging technologies like AI.
  4. Encryption. Protecting information by converting it into a coded format that only authorized people or systems can read is evolving from a recommended safeguard into a fundamental requirement. ePHI must be guarded both at rest and in transit—even with the challenges of legacy systems.

Purposeful change

Modernizing systems is not just about upgrading tools—it’s about improving visibility and control. And security has to support care, not compete with it.

Webb highlights identity and access management as key areas of focus. Single sign-on, stronger authentication and streamlined access models can minimize patient burden while improving security. The goal is not to slow clinical teams down but to ensure the right people can access the right data at the right time.Paste the article paragraph you want to wrap around the box here.

Striking this balance is critical in healthcare. The challenge is that, in emergency settings, information availability often is the main focus.

CORE ELEMENTS OF A HIPAA READINESS STRATEGY

  • Map where ePHI lives & how it moves across systems.
  • Expand phishing-resistant MFA for privileged & remote access.
  • Review encryption capabilities across critical platforms.
  • Test incident response & reporting workflows.
  • Align clinical, IT, finance & operational leaders around remediation priorities.

HIPAA readiness at a glance

The proposed rule changes point to a few clear priorities for healthcare organizations:

  • Data inventory
  • Stronger MFA
  • Encryption
  • Faster response

7 STEPS TO PREPARE NOW

  • Refresh the security risk assessment.
  • Identify the systems & workflows that carry the most critical ePHI.
  • Expand phishing-resistant MFA where it will have the most impact.
  • Test incident response, escalation & reporting procedures.
  • Review encryption support throughout legacy & modern platforms.
  • Bring clinical, financial & operations teams into the planning process.
  • Monitor updates from the U.S. Department of Health & Human Services & outside compliance partners.

From guidance to enforcement

Two of the most significant changes are compliance and the move from intent or addressable safeguards to mandatory requirements. Organizations will need to demonstrate or prove that controls are actively implemented and effective, including:

  • Annual security audits and risk assessments
  • Documented asset inventories and network maps
  • Tested disaster recovery plans
  • Greater accountability among business associates (suppliers/contractors)

Challenges at any size

Providers of all sizes face the same threats and regulatory expectations. For larger systems, the challenge is scale. For smaller hospitals and community providers, it’s resources—staffing and budgets. Either way, the starting point is understanding where risk exists.

Webb suggests focusing on the biggest gaps, building a defensible plan and involving leadership early. Clinical, financial and operational teams all need to understand what is changing, what’s at risk and what can realistically be done next.

Balance compliance & care

The hardest part of healthcare cybersecurity is balancing safety and speed. Controls that seem straightforward in theory can be disruptive at the bedside.

The bigger message is that compliance and patient care are not competing priorities. They must work together.

Prepare now. At the time this article was written, the final HIPAA Security Rule changes had been expected in May 2026, with compliance likely to be required within the following year. However, as of early July, no updated timeline on a decision was available. Visit the HIPAA section of the HHS.gov website for important updates. Use the coming months to review your security risk assessment, identity controls and response plan.

Share This Article:

Share Email
, , , ,