HIPAA Series: The Security Rule Slipped to July 2027. OCR Reorganized Around Cybersecurity Weeks Earlier

The current regulatory agenda puts the proposed HIPAA Security Rule in Long-Term Actions with a July 2027 target. It puts a deregulatory Privacy Rule proposal in Final Rule Stage with an August 2026 target. The date change is clear. The sequencing takes more explaining.

Three things say more than the new date: the rulemaking now sits on the long-term track with no identified legal deadline; the Security and Privacy proposals carry opposite EO 14192 designations; and OCR spent the spring reorganizing around health information cybersecurity while continuing to settle Security Rule cases.

What the agenda entry says

The current entry (https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22) for RIN 0945-AA22:

- NPRM: 01/06/2025, 90 FR 898

- Final Action: 07/00/2027

- Agenda Stage of Rulemaking: Long-Term Actions

- Priority: Economically Significant

- EO 14192 Designation: Regulatory

- Legal Deadline: None

The Spring 2025 entry (https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202504&RIN=0945-AA22) listed 05/00/2026 and Final Rule Stage. A 14-month slip and a change in posture.

Long-Term Actions is where agencies place rulemakings whose next regulatory step falls outside the agenda's 12-month planning window. "Legal Deadline: None" means the agenda identifies no statutory or judicial deadline for final action. July 2027 is a planning estimate, and OCR missed the last one. The stage change matters more than the date, because nothing has to happen for the date to move again.

No final rule exists. What moved is a projection.

The regulatory ledger

Compare that entry to the one for the 2021 Privacy Rule proposal: Final Rule Stage, Final Action 08/00/2026, EO 14192 Designation "Deregulatory," with claimed savings of roughly $785 million annualized at 7 percent. A proposal from January 2021 is targeted for final action this month. A proposal from January 2025 has moved to the long-term track.

The Security Rule is designated "Regulatory" and carries an HHS estimate of about $9 billion in year-one industry cost and about $6 billion annually in years two through five.

OMB's guidance implementing Executive Order 14192 directs agencies to identify at least 10 existing regulations for repeal whenever they promulgate a new one, and to offset the new action's incremental costs, subject in later fiscal years to a cost allowance OMB sets for each agency. Four limits on how far that carries here. The requirement that total incremental cost fall significantly below zero was tied to FY 2025. The allowance is set for HHS as a whole, so the ledger covers every HHS rulemaking, not a two-rule trade. The agenda does not identify the Privacy Rule as an offset for the Security Rule. And $785 million in annualized savings would not, on its own, answer a rule projected in the billions.

What survives those limits is narrower and still useful: one rule is projected to add claimed savings to HHS's regulatory ledger, the other billions in projected cost, and EO 14192 makes that difference relevant to timing. It does not establish OCR's reasoning.

Industry made a version of the argument itself. In a December 8, 2025 more than 100 provider organizations and associations, including the AMA, the Federation of American Hospitals, Cleveland Clinic, and MGMA, asked Secretary Kennedy to withdraw the proposal "immediately" and "without further consideration." Their stated ground: "The Proposed Rule runs counter to President Trump's robust deregulatory agenda." See coalition letter @ (https://www.ada.org/-/media/project/ada-organization/ada/ada-org/files/advocacy/regulatory-reform/2025/120825_coalition_letter_hipaa_security_rule.pdf),

OCR has not done so. The proposal has neither been withdrawn nor moved to Inactive. Consolidation with the Privacy Rule into a single omnibus rule, on the 2013 model, remains possible, though the separate August 2026 and July 2027 targets currently point toward independent action.

What OCR did while the rule sat still

May 18, 2026 HHS reorganized OCR into three distinct subject-matter divisions, one of them the Health Information Privacy, Data, and Cybersecurity Division. Read the release carefully before drawing conclusions (https://www.hhs.gov/press-room/hhs-announces-restructuring-of-its-office-for-civil-rights.html). HHS said breach review and complaint intake stay in a centralized Enforcement Division, and that the change is not expected to reduce OCR's workforce. This is not evidence of added enforcement resources. It is evidence that health information privacy, data, and cybersecurity now have a distinct division and senior leadership, weeks before the agenda pushed the rule out 14 months. Structural priority, not proven expansion.

Enforcement, meanwhile. On April 23, OCR announced four ransomware settlements totaling $1,165,000, covering breaches affecting more than 427,000 individuals. On June 18 it settled with an employer-sponsored group health plan for $450,000, its 20th ransomware action and 14th under the Risk Analysis Initiative. On July 29 it settled with OSF Healthcare System for $552,250 (https://www.hhs.gov/press-room/hhs-ocr-settles-ransomware-investigation-with-healthcare-system.html), its 21st ransomware action.

The OSF corrective action plan is the one to read. It requires OSF to conduct a risk analysis and to develop and implement a risk management plan addressing what the analysis finds. Director Paula Stannard's quote in that release is direct: "If a HIPAA regulated entity doesn't know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked."

Every one of those settlements involved a failed risk analysis, a requirement contained in the Security Rule since 2003.

The compliance clock, stated correctly

The 240-day figure is right. And, as much as I hate to admit it, my earlier allocation of those days was probably not.

Under the Proposed Rule (https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information), a final rule takes effect 60 days after publication. The general compliance date falls 180 days after that effective date, the standard period under 45 CFR 160.105. OCR considered a longer window and declined, writing that it did "not believe that the proposed rule would pose unique implementation challenges that would justify an extended compliance period." Total: about 240 days from publication, on the same schedule for covered entities and business associates.

My June piece put the 180 days on covered entities and gave business associates an extra 60. That was wrong. The 60 days is the gap between publication and the effective date, and it belongs to everyone.

For a July 2027 publication: effective date around September 2027, general compliance around March 2028.

The business associate agreement transition gets covered least and matters most for contract planning. Proposed 45 CFR 164.318 would let certain agreements already in place before publication, and compliant with the requirements applicable then, stay deemed compliant past the general compliance date. Deemed compliance would run to the earlier of the agreement's first renewal on or after the general compliance date, or one year after the final rule's effective date. To qualify, an agreement could not be renewed or modified between the effective date and the general compliance date. This is a contract-document transition, not an extension of the underlying Security Rule controls. Encryption and MFA obligations do not move with it. These are the proposed terms; confirm them against the final rule text when it publishes.

What to do with the extra year

Build the technology asset inventory and network map. The proposal would require both expressly, and OCR's position in the NPRM is that an accurate risk analysis already requires knowing where ePHI lives and how it moves.

Audit MFA coverage beyond the EHR. Email, remote access, cloud storage, billing, practice management, vendor access. On February 12, 2024, attackers used compromised credentials to reach a Change Healthcare Citrix remote access portal that, in UnitedHealth CEO Andrew Witty's testimony to the Senate Finance Committee (found here https://www.finance.senate.gov/imo/media/doc/0501_witty_testimony.pdf), "did not have multi-factor authentication." Ransomware followed nine days later. HHS [later reported that breach as affecting approximately 192 million individuals, the largest hacking breach of 2024.

Give every material finding an owner and a disposition. The OSF plan requires both a risk analysis and a risk management plan built from it. A finding with no owner, no treatment decision, no implementation timeline, and no documented rationale showing why the remaining risk is reasonable and appropriate can become evidence that the organization knew of an unaddressed risk.

Sort BAAs by renewal timing. Flag agreements scheduled for renewal or modification between the effective and compliance dates, because they would not qualify for the transition. Flag agreements renewing after the compliance date, because deemed compliance would end at renewal. Then find out which vendors will resist.

July 2027 is an estimate for a rulemaking with no identified legal deadline, now on the long-term track and designated Regulatory under a policy that makes new costs matter. The date may move again. The May reorganization and the summer settlements are the firmer signal: OCR slowed this rulemaking and kept enforcing the rule it already has. Price the risk accordingly.

---

Sources

- [Unified Agenda, RIN 0945-AA22, current](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22) and [Spring 2025](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202504&RIN=0945-AA22) entries

- [Unified Agenda, RIN 0945-AA00 (Privacy Rule)](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA00)

- [HIPAA Security Rule NPRM, 90 FR 898 (Jan. 6, 2025)](https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information)

- [OMB M-25-20, Guidance Implementing Section 3 of EO 14192 (Mar. 26, 2025)](https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-20-Guidance-Implementing-Section-3-of-Executive-Order-14192-Titled-Unleashing-Prosperity-Through-Deregulation.pdf)

- [Coalition letter to Secretary Kennedy (Dec. 8, 2025)](https://www.ada.org/-/media/project/ada-organization/ada/ada-org/files/advocacy/regulatory-reform/2025/120825_coalition_letter_hipaa_security_rule.pdf)

- [HHS, OCR Restructuring (May 18, 2026)](https://www.hhs.gov/press-room/hhs-announces-restructuring-of-its-office-for-civil-rights.html)

- [OCR, Four Ransomware Settlements (Apr. 23, 2026)](https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html)

- [OCR, Health Plan Ransomware Settlement (June 18, 2026)](https://www.hhs.gov/press-room/ocr-settles-ransomware-investigation-health-plan.html)

- [OCR, OSF Healthcare Settlement (July 29, 2026)](https://www.hhs.gov/press-room/hhs-ocr-settles-ransomware-investigation-with-healthcare-system.html)

- [Testimony of Andrew Witty, Senate Finance Committee (May 1, 2024)](https://www.finance.senate.gov/imo/media/doc/0501_witty_testimony.pdf)

- [HHS OCR, Annual Report to Congress on Breaches of Unsecured PHI, CY 2024](https://www.hhs.gov/sites/default/files/breach-report-to-congress-2024.pdf)

Previous
Previous

AI Act, CMMC, and HIPAA Timelines Slipped. The Duty to Act Did Not.

Next
Next

Before the First Bell: What California's Student-Data Rules Already Require of Your EdTech Contracts