In the federal government's own regulatory agenda, the HIPAA Security Rule overhaul sits under a heading called Long-Term Actions, with a projected final action date of 07/00/2027. The zeros are not a typo. That is how the agenda writes a month with no day attached: sometime in July 2027, day unknown.
You would not guess that from the content being published about it. The rule has its own readiness market now, with countdowns, deadline framing, and checklists for a 2026 that is already two thirds gone.
Both things are true at once, and the gap between them is worth understanding before you spend against it.
What was actually published
On January 6, 2025, HHS published a document titled "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information." Its type, in the Federal Register's own record, is Proposed Rule. Its action line reads "Notice of proposed rulemaking; notice of Tribal consultation." It carries regulation identifier 0945-AA22, and its comment period closed on March 7, 2025 (Federal Register record for 2024-30983).
A notice of proposed rulemaking is a government agency saying what it is thinking about doing and asking what you think. It is a real signal of intent. It is not a requirement, it binds nobody, and the text that eventually lands can differ from the text that was proposed, because responding to comments is the entire purpose of the exercise.
Nothing has landed. As of today, the Security Rule in force is the one that was already in force.
Where the proposal actually sits
The Unified Agenda is the government's own published schedule of what each agency is working on. Every rule in it carries a stage and a timetable.
In the most recent edition listing this rule, RIN 0945-AA22 appears with an "Agenda Stage of Rulemaking" of Long-Term Actions, a timetable showing the NPRM at 01/06/2025 (90 FR 898), and a Final Action projected for 07/00/2027 (OMB Unified Agenda entry for RIN 0945-AA22, Fall 2025 edition, checked August 24, 2026). The rule is flagged Economically Significant and Major, and it would amend 45 CFR parts 160 and 164.
Long-Term Actions is the agenda's category for rulemakings the agency is not expecting to move in the near term. A rule in that bin has not been abandoned. It has been parked.
I checked whether a newer edition tells a different story. The RIN does not appear in the 2026 editions I could query, so Fall 2025 remains the most recent published position. If that changes, the position changes with it.
What the market is selling
Search the rule and you get a genre. "New Requirements to Prepare For." "What Hospital CISOs Must Do in 240 Days." Readiness assessments, gap analyses, and platform tiers scoped to a rule whose own schedule now points at the second half of 2027.
This is not fraud and mostly it is not even cynical. The proposed requirements are real proposals, the direction of travel is real, and a vendor writing "prepare now" believes it. The problem is subtler and it is structural: a proposed rule can generate a compliance market on the strength of the proposal alone, and every month the final action slips is another month that market gets to run against a deadline nobody has to meet.
That is the same dynamic we wrote about with SOC 2 fragmentation. Compliance spend scales with the number of vendors who can find a reason to sell you something, not with how hard your security problem actually is. A slipping federal deadline is an unusually good reason.
The strongest case for buying anyway
Worth stating fairly, because it is not weak.
Agencies do finalize rules, and this one carries an explicit projected date rather than an open-ended one. A company that begins in 2027 begins behind a company that began in 2026.
The proposal also points somewhere unambiguous. It would "remove the distinction between required and addressable implementation specifications and make all implementation specifications required, with specific, limited exceptions" (full text of the NPRM, 90 FR 898, 125 pages). That is the load-bearing change, and it is easy to miss under the list of new controls. Addressable has never meant optional, but it has meant a covered entity could document why encryption was not reasonable and appropriate in its environment and move on. The proposal closes that door.
And a healthcare buyer does not wait for HHS. If a hospital's procurement team asks for multi-factor authentication and an asset inventory, the fact that the rule is unfinalized is irrelevant to whether you close the deal.
All of that argues for doing the work. None of it argues for doing the work because of a deadline, and the difference shows up in what you buy.
What the deadline framing costs you
Buying against a deadline changes the shape of the purchase. It compresses the timeline, which raises the price. It favors bundles that promise coverage of a specific rule over controls chosen for your actual risk. It produces artifacts aimed at an auditor who is not coming yet. And it puts the renewal on a clock tied to someone else's schedule, which has now moved at least once.
Buying the same controls on their own merits changes all four. You sequence by risk instead of by rule. You can negotiate. What you build works for the customer asking today, and it keeps working if the final rule lands in a different shape than the proposal.
The controls in the proposal are not exotic, and reading them makes that plain. A written technology asset inventory and a network map covering every asset that could affect the confidentiality, integrity, or availability of health data, proposed at 45 CFR 164.308(a)(1)(i). Automated vulnerability scanning at least once every six months. Penetration testing "at least once every 12 months or in accordance with the covered entity's or business associate's risk analysis, whichever is more frequent," proposed at 45 CFR 164.312(h)(2)(iii). A first-ever definition of multi-factor authentication. Network segmentation.
That is a description of competent security at a company handling patient data. If those are missing, the reason to fix them is not a date in a regulatory agenda. It is that you are handling patient data.
And the rule that can be enforced against you today is the existing Security Rule, unchanged, which has required a risk analysis and reasonable safeguards since long before any of this.
What to do with this
If someone is selling you readiness for the new HIPAA Security Rule, three questions are fair.
Which requirements are you pricing, the proposed ones or the ones in force today?
What happens to this engagement if the final rule differs from the proposal, or if July 2027 moves again?
Would you recommend these controls to a company with no compliance requirement at all?
An honest answer to the third one tells you most of what you need. Controls worth having are worth having without a deadline. Anything that only makes sense because of a date should be priced like the option it is.
For what HIPAA requires of a small company right now, we wrote that up separately: breaking down HIPAA compliance for startups and small businesses.
