A proposed update to HIPAA has been working its way through the federal regulatory process since late 2024, and healthcare organizations would be wise to treat it as a near-certainty. The public comment period closed on March 7, 2025, and the Office for Civil Rights has not yet issued a final rule. That means the specific language could still shift, but the direction is clear, and the core requirements are unlikely to change significantly.
According to Chris Bowman, Director of Security Services at Vertilocity, organizations that wait for the final publication before acting will be in a difficult position. “It’s going to be a very intense period of activity, and for organizations that aren’t aware of it or aren’t thinking about it or haven’t begun the process of implementation now, it may be quite painful when that rule does finally drop.”
Once published, covered entities will have 180 days to comply. Business associates get an additional 60 days beyond that. For environments with real gaps to close, that runway moves quickly.
No More Exceptions: How the Proposed Rule Raises the Floor
The most consequential shift in the proposed rule is the elimination of the “addressable” designation for implementation specifications. Under the current HIPAA Security Rule, addressable controls are effectively optional with justification: organizations can document why a particular safeguard is not reasonable or appropriate for their environment and address it another way. That flexibility is disappearing.
The proposed rule removes the distinction between required and addressable specifications entirely and makes all implementation specifications required, with only specific, limited exceptions. The full scope of the proposed rule is extensive, so what follows are some of the most operationally significant shifts, particularly for smaller practices such as dental groups, optical practices, specialty clinics, that have operated with leaner IT environments and relied on the addressable framework to defer certain controls.
Encryption at rest and in transit. Both have been best practices for years, but under the proposed rule, they become mandatory, with limited exceptions. Vertilocity implements encryption standards across clinic environments as part of its managed security program, ensuring ePHI is protected whether it is stored or in motion. Learn more about our cybersecurity services.
Multi-factor authentication. “You’d think that seems obvious,” Bowman notes, “but it was not mandatory previously, and now it is.” MFA configuration and enforcement across users, applications, and administrators is a core component of Vertilocity’s security stack for healthcare clients.
Network segmentation. Servers, workstations, internet-facing systems, and other network components must be separated from networks containing ePHI. This includes Internet of Things devices that are easy to overlook, such as conference room displays, smart appliances, and other connected equipment. Flat networks, common in smaller environments, will no longer be compliant.
Vulnerability scanning. Organizations will be required to conduct vulnerability scans at least every six months. Vertilocity provides vulnerability scanning services tailored to healthcare environments, identifying risk before it becomes exposure.
Annual penetration testing. Penetration testing must be conducted at least once every 12 months; a requirement that goes beyond scanning to actively test whether known vulnerabilities can be exploited.
Annual compliance audit. A compliance audit will be required annually to confirm adherence to Security Rule requirements.
Technology asset inventory and network maps. Organizations must maintain a current inventory of technology assets and a network map showing how ePHI moves through their systems, reviewed and updated at least once every 12 months. Vertilocity’s vCIO advisory service helps practice leaders maintain this kind of documentation and keeps it current as environments evolve.
How One Breach Changed the Regulatory Conversation
These changes did not emerge in a vacuum. The Change Healthcare network ransomware attack, which compromised records for an estimated 100 million patients, is widely seen as the catalyst for this regulatory overhaul. The breach spread through pharmacy systems, health insurance infrastructure, and connected organizations, resulting in one of the most significant healthcare data events in U.S. history.
The reported root cause: a single user account without multi-factor authentication enabled.
That failure, and the scale of the damage it enabled, accelerated the federal government’s reassessment of HIPAA’s requirements. The proposed rule brings HIPAA into closer alignment with other security frameworks, including NIST Cybersecurity Framework (CSF) and the Cybersecurity Maturity Model Certification, which have long required more rigorous controls. HIPAA is catching up to standards that much of the broader technology and regulated industries landscape has already adopted.
The Requirements That Will Hit Hardest
Tighter Timelines for Contingency and Incident Response
The proposed rule strengthens requirements around contingency planning and incident response in ways that will require real infrastructure investment. Organizations will be required to establish written procedures to restore the loss of critical electronic information systems and data within 72 hours, and to implement written security incident response plans with documented procedures for testing and revising them.
Business associates, including managed IT and security partners like Vertilocity, will be required to notify covered entities upon activation of their contingency plans within 24 hours. This tightens coordination requirements across the entire vendor ecosystem.
Every business associate agreement will need to be reviewed and updated. Organizations will also be required to obtain written verification at least every 12 months confirming that their business associates have implemented the required technical safeguards. That verification must include a written analysis of the business associate’s electronic information systems performed by a subject matter expert, along with a written certification signed by a person authorized to act on the business associate’s behalf. A signed BAA alone will no longer be sufficient.
Vertilocity works with healthcare clients to review and update business associate agreements and provides the written attestations the proposed rule requires. Disaster recovery planning and testing are also standard components of Vertilocity’s managed services program, ensuring that the 72-hour restoration requirement is not just a policy on paper but a tested, repeatable capability.
Centralized Logging: A Significant Infrastructure Investment
The proposed rule’s requirements around risk analysis and security monitoring will push most healthcare organizations toward implementing a Security Information and Event Management platform, commonly known as a SIEM, along with continuous log review.
Bowman explains why this becomes a practical necessity at scale: “In a small environment, you can configure alerting rules and review administrative logs for each system, and it’s feasible. But as an environment scales up, that rapidly becomes impossible. So you really need to centralize them and review holistically.”
For organizations that have never invested in centralized logging infrastructure, this is not a small line item. The proposed rule also sets a minimum retention period of 12 months for audit logs tied to ePHI access, modification, or export events. Many organizations are currently well below that threshold. Log data is voluminous, retention adds to storage costs, and meaningful analysis requires both the right platform and consistent oversight. Organizations should begin evaluating SIEM solutions now, before costs increase in response to a compliance deadline and vendor bandwidth tightens. Vertilocity provides 24/7 monitoring and SIEM solutions tailored to healthcare environments, centralizing security event data and applying the continuous, intelligent review the proposed rule is pushing toward.
Why Starting Now Matters More Than You Think
The comment period on the proposed rule closed in March 2025. The final rule has not been issued, and the current HIPAA Security Rule remains in effect in the meantime. But the regulatory direction is set, and the requirements being proposed are broadly consistent with security frameworks that have been standard in other industries for years.
When the final rule is published, covered entities will have 180 days to comply. Business associates will have an additional 60 days. That sounds like adequate time until you map it against the actual work: deploying MFA across systems, encrypting data at rest, contracting penetration testing, updating business associate agreements, validating disaster recovery capabilities, and implementing or upgrading logging infrastructure.
Organizations that wait for the final publication before beginning their assessments will also face a supply-and-demand problem. Managed IT and security firms will be fielding requests from every healthcare client simultaneously. Vendors will have limited bandwidth, and pricing may reflect that pressure. The organizations that begin now will have access to thoughtful, well-paced implementation. Those who wait may find themselves managing a rushed, reactive process under a hard deadline, and paying more for the privilege.
The stakes of non-compliance extend beyond the implementation crunch. Failing to implement mandatory controls after the effective date constitutes willful neglect under HIPAA, carrying penalties of $14,232 to $2,134,831 per violation. Beyond the fines, the downstream consequences compound: cyber insurers may deny claims if required controls were not in place at the time of a breach, and business associates may decline to work with organizations that cannot demonstrate compliance. The regulatory deadline is fixed, but the risk of inaction starts now.
Why the Old Approach to Security No Longer Works
The regulatory pressure is happening alongside a meaningful escalation in the threat landscape. Cybersecurity attacks have become more sophisticated, more targeted, and easier to execute. AI-assisted tooling has lowered the barrier for threat actors significantly, enabling scripted attacks that once required deep technical expertise.
Bowman is direct about what this means for organizations still operating with legacy security approaches: “Attacks have gotten much more sophisticated. We can’t continue doing things the way that we did before.”
The proposed HIPAA updates reflect this reality. The controls being mandated are not new ideas. They are security fundamentals that other regulated industries have required for years. Healthcare organizations are being asked to meet a standard the rest of the field has already adopted.
What to Do Before the Updates are Finalized
The organizations best positioned when the rule is finalized will be those that have already done the foundational work. That means:
- Assessing your current state. Are encryption, MFA, and network segmentation already in place? If not, where are the gaps?
- Evaluating your logging infrastructure. Do you have centralized log management and continuous monitoring? If not, begin researching SIEM solutions and associated costs now.
- Reviewing legacy systems. Older systems that lack native encryption support may require upgrades or replacement.
- Auditing business associate agreements. Any agreement with a technology vendor should be reviewed against the new notification and attestation requirements before the rule is published.
- Starting the conversation early. Implementation partners with deep healthcare IT experience are going to be in high demand. Getting into their planning queue now is a practical advantage.
Vertilocity works with healthcare organizations to assess compliance readiness, implement the technical controls required under HIPAA, and provide the ongoing monitoring and vCIO guidance needed to stay ahead of regulatory change. Talk to us about your HIPAA readiness.
The proposed rule is not designed to create burden for its own sake. It reflects where security standards have already landed across regulated industries, and it responds to documented failures with documented consequences. Healthcare organizations that approach this proactively will find the transition manageable. Those that treat it as a future problem may find, when the rule finally drops, that the window they had is already closed.
