In one of its last regulatory actions, the Biden Administration released a Notice of Proposed Rulemaking that will have a significant impact on all HIPAA-regulated entities – health care providers, health plans/health insurance companies, and healthcare clearinghouses. This proposed rule will even extend to entities such as health plan sponsors, e.g., employers. The stated intent of the new regulations is to modify the Security Standards for the Protection of Electronic Protected Health Information, aka, the HIPAA Security Rule.
Table of contents
- What is the Rationale for this Proposed Rule?
- Important New HIPAA Security Rule Definitions
- General Changes to the HIPAA Security Rule
- Changes to the HIPAA Administrative Safeguards Standards
- Changes to HIPAA Technical Safeguards
- Changes to HIPAA Physical Safeguards Standards
- Changes to Business Associates Agreements
- Other Potential Changes
- Some Final Thoughts
The incoming Trump Administration has frozen all new regulatory initiatives, announcing the revival of the 10-for-1 approach to regulations: retire 10 existing regulations for every new regulation approved and implemented. So it remains to be seen just how or when this rule is implemented.
What is the Rationale for this Proposed Rule?
The Proposed Rule cites the audit experience of the Office for Civil Rights (OCR) of the Health and Human Services Department (HHS) in discussing the rationale for the Proposed Rule. This audit process found that “most regulated entities failed to implement the Security Rule requirements for risk analysis and risk management, requirements that are fundamental to protecting the confidentiality integrity and availability of electronic protected health information (ePHI).”
Investigations of breaches almost always find multiple potential violations of the Security Rule that contribute to the unauthorized disclosure of ePHI.
The HIPAA “Wall of Shame“, the list of healthcare entities reporting breaches affecting 500 or more persons, shows 57 reports of unauthorized disclosures or hacking incidents in just the first 24 days of 2025! It is very clear that what many covered entities are doing with respect to cybersecurity is just not enough, and the Security Rule requirements need updating.
And of course, there are also the financial implications of data breaches. According to IBM, the cost of a global data breach rose to $4.88 million in 2024. The cost of data breaches in health care in the same year was $9.77 million!
In the meantime, it is worthwhile reviewing the most important or most revolutionary provisions of the Proposed Rule. The current Administration’s posture notwithstanding, covered entities and business associates will continue to suffer hacking incidents and unauthorized disclosures. It is never too early to take steps to improve the cybersecurity of ePHI, even with steps that exceed the current existing Security Rule’s obligations.
Important New HIPAA Security Rule Definitions
“Electronic storage media” is being replaced by electronic storage material to ensure ePHI found in copiers, smartphones, VOIP technologies, and technologies that electronically record or transcribe telehealth sessions are included.
“Access” is expanded to include deleting and transmitting as well as creating, receiving and maintaining ePHI.
The definition of deploy is added to ensure that regulated entities are required to implement policies and procedures and technology they discuss in their policies and procedures. Technology described in policies and procedures must be “in place, configured for use and actually in use and operational…”
Malicious software was defined as software designed to damage or disrupt a system, and the only example was a virus. The definition is expanded to include software or firmware intended to perform an unauthorized action that will have an adverse impact on an electronic information system or on the confidentiality, integrity, or availability of ePHI. The list of examples will be non-exhaustive and include elements such as trojans and spyware.
Multi-factor authentication (MFA) would mean identifying users with at least two or three factors:
Technical safeguards currently refers to technology and policies and procedures that protect ePHI and control access to it. OCR is adding “technical controls” to the definition. It further defines technical controls as “technical mechanisms contained in the hardware, software or firmware components of an electronic information system that are primarily implemented and executed by it to protect it and the data within it.
“Technology asset” is added to mean the components of electronic information systems, including but not limited to hardware, software, electronic media, information, and data.
There are several other definitions addressed, including terms like risk and threat, plus other definitions where the terms are updated for new technology (like workstations) or to clarify an existing definition (like vulnerability). In part, these updates are designed to address shortcomings pointed out by judges when covered entities sued Health and Human Services over an enforcement action or penalty.
General Changes to the HIPAA Security Rule
The current Security Rule provisions described some of the administrative, physical, and technical standards as required, and some as “addressable”. Covered entities were not required to comply with the standard and implementation specifications of addressable standards. Instead, they could describe how the entity would achieve compliance using an alternate method. In this new Proposed Rule, the OCR is making all standards and implementation specifications required.
Regulated entities can still apply what they consider reasonable and appropriate security measures to implement specifications of the Security Rule, but they must also take into account how their measures affect the resiliency of their relevant electronic information systems.
Changes to the HIPAA Administrative Safeguards Standards
The Proposed Rule will make several changes to the Administrative Safeguards.
- Regulated entities would be required to test certain security measures to ensure they are still working as designed and that workforce members know how to implement them. This could include things like penetration testing.
- The current Administrative Safeguard called “Security Management Process” has four implementation specifications. These cover security risk analysis, risk management, sanction policy, and information system activity Review. These four implementation specifications would be elevated to become Administrative Safeguards and would contain additional implementation specifications.
- The Security Management process would be revamped to become a Technology Asset Inventory standard. Covered entities would be required to maintain an accurate and thorough written technology asset inventory and network map of their electronic information systems. This map would be required to illustrate the movement of ePHI throughout its electronic information systems. The map would document how ePHI enters and exits information systems, and how ePHI is accessed from outside of the systems.
- The technology asset inventory and network map would be required to be updated at least every 12 months, or when there is a change in the regulated entity’s environment or operations that may affect ePHI.
- A Risk analysis must be conducted at least every 12 months, and besides assessing the human, natural, and environmental threats, it must also assess risks posed by legacy devices. The lack of an initial or updated risk analysis is one of the most frequent deficiencies cited by the OCR in its investigations and enforcement actions.
- A new standard would require regulated entities to establish policies and procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying the timely installation of patches, updates, and upgrades to their electronic information systems that contain ePHI.
- Other Administrative Safeguards up for changes include: workforce security, security awareness training, security incident procedures, and business associates contracts.
Changes to HIPAA Technical Safeguards
Changes to the Technical Safeguards standards include:
- Regulated entities would be required to deploy technical controls in relevant electronic information systems to allow access only to those users and technology assets that have been granted access rights. Regulated entities must not only have policies and procedures, but they must also implement those policies.
- The Implementation specifications for Access Controls will be increased by five new implementation specifications.
- The Implementation specifications covering encryption will become a Standard with its own implementation specifications.
- The Implementation specifications for automatic logoff will be modified to require deployment of a mechanism to terminate an electronic session after a period of inactivity.
- A new implementation specification would require a regulated entity to deploy technical controls that disable or suspend the access of a user or technology asset to relevant electronic information systems after a certain number of unsuccessful authentication attempts.
- The implementation specification covering encryption and decryption would be elevated to a standard with implementation specifications. Regulated entities would be required to configure and implement technical controls to encrypt and decrypt all ePHI in a manner that is consistent with prevailing cryptographic standards. Entities would also be required to encrypt all ePHI at rest and in transit (with limited exceptions). Annual testing of the technical controls for encryption and decryption would also be required.
- Other implementation specifications would address requiring the deployment of technology against malicious software, removal of extraneous software, configuring operating systems to reduce the risks identified in its risk analysis, and testing the effectiveness of its technical controls at least every 12 months.
- There are four new implementation specifications related to audit trails and system log controls. Other proposed updates cover Authentication (including deploying MFA or compensating controls), transmission security, vulnerability management, and information systems backup and recovery.
Changes to HIPAA Physical Safeguards Standards
Changes to the Physical Safeguards standards include:
- Policies and procedures covering contingency operations, facility security plans, access control, and validation procedures must be in writing. (Hard to believe the OCR has to specify this, but there it is.)
- Workstation use and security policies must take into account new types of workstations, including those that are mobile.
- Device and Media Controls would be re-titled “Technology Asset Controls”, to make it consistent with changes in the Administrative Safeguards.
Changes to Business Associates Agreements
Regulated entities would be required to include a provision in business associate agreements to receive notice of activation by the business associate (BA) of the BA’s contingency plan for an unauthorized disclosure of ePHI no later than 24 hours after activation.
Other Potential Changes
Other changes to the Security Rule would require health plan sponsors to protect the security and privacy of ePHI they receive from health plans and health insurance companies to the same standards required by the HIPAA Security Rule.
The OCR is also requesting input on new and emerging technologies such as quantum computing, artificial intelligence, and virtual and augmented reality (VR and AR), and how the Security Rule would apply in each case.
Some Final Thoughts
This proposed rule is extensive. Some would say, in view of the huge numbers of unauthorized disclosures of electronic health information by health care entities large and small, this update is overdue. Only time will tell if a final rule will be issued anytime in the next four years. However healthcare providers and other regulated entities would do well to review the details of the proposed rule and consider how many of these requirements they can and should deploy without new regulations.
At The Fox Group, we have acted as HIPAA Privacy Officers for many of our clients. We constantly remind them: take a look at what other healthcare providers have gone through after a large breach. Think about implementing stronger cybersecurity protections now, before you have to do it under duress and while you are bearing the financial and organizational burden of dealing with a large breach!
