Key Points
- OCR’s proposed 2025 HIPAA Security Rule update has a projected finalization date of July 2027, moved from the original May 2026 target and classified as a “long-term action” in the OMB Unified Agenda.
- The 2024 Change Healthcare ransomware attack — the largest protected health care data breach in U.S. history — has renewed pressure on OCR to modernize the HIPAA Security Rule’s cybersecurity requirements.
- A coalition of more than 100 health care organizations, led by CHIME, sent a December 2025 letter to HHS Secretary Robert F. Kennedy Jr. urging full withdrawal of the proposed Security Rule update, citing its deregulatory inconsistency and compliance burden.
- Prior HIPAA rulemaking history — including the 2013 Omnibus Rule and the court-vacated 2024 Reproductive Health Care Privacy Rule — suggests finalization in revised or consolidated form is more likely than adoption of the proposed rule as written.
