William Cochran · January 7, 2025
The HIPAA Security Rule Just Got Its Biggest Update in a Decade
HIPAA Security Rule 2025 update explained. Mandatory MFA, encryption requirements, 72-hour incident response, and what healthcare practices need to do now.
Status update, 28 August 2026. This was written when the proposed rule was published in January 2025. It remains a proposal — it has not been finalized, the comment period closed in March 2025, and the target for final action has moved more than once since. Treat the requirements below as the direction of travel rather than settled law, and check the Federal Register (RIN 0945-AA22) for current status before acting on a deadline.
The Department of Health and Human Services published the most sweeping update to the HIPAA Security Rule since 2013. The proposed changes were published in the Federal Register on 6 January 2025. They are a proposal, not a final rule. If your organization handles protected health information, this affects you directly.
What Changed
No more “addressable” vs. “required.” Under the current rule, some safeguards are “required” and others are “addressable” — meaning you could document why you chose not to implement them. Under the new rule, all safeguards are required. Period. The ambiguity is gone.
MFA is mandatory. Multi-factor authentication for all access to systems containing ePHI. No exceptions.
Encryption at rest and in transit is mandatory. Full-disk encryption on all devices, encrypted email, encrypted backups. Again, no exceptions.
72-hour restoration. The proposal would require certain critical systems and data to be restored within 72 hours — not merely that a response begins. That is a materially harder obligation than it first sounds, and it is a recovery-time commitment as much as a security one. It assumes a documented, tested incident response plan with defined roles, and backups you have actually practised restoring.
Annual penetration testing. Organizations must conduct penetration testing at least annually — not just vulnerability scanning, but actual penetration testing.
Asset inventory and network mapping. You must maintain a current inventory of all systems that handle ePHI and a map of how ePHI moves through your environment.
The Cost
HHS estimates the first-year compliance cost at $9 billion across the industry. That is a significant number, and it will fall disproportionately on smaller practices that have been relying on the “addressable” loophole to defer investments.
What to Do Now
The rule is not final yet, but the direction is clear. Do not wait for finalization to start preparing:
- Enable MFA on everything — this is coming regardless
- Encrypt all devices and communications
- Conduct a risk assessment if you have not done one recently
- Document your incident response plan
- Create an asset inventory
Where does your practice stand today? Our compliance service maps your current posture against these requirements and documents the gaps.
Our team has been implementing these controls in healthcare environments for two decades — not because anyone predicted this rule, but because they are the right thing to do. If you are starting from scratch, our compliance service is built around exactly these controls.