Photo of Emma Trivax

Emma represents a wide range of health care providers, including physicians, management service organizations, dental service organizations, hospitals, clinical laboratories, skilled nursing facilities, ambulatory surgical centers, DMEPOS suppliers, and behavioral health providers.

Key Points

  • OCR’s proposed 2025 HIPAA Security Rule update has a projected finalization date of July 2027, moved from the original May 2026 target and classified as a “long-term action” in the OMB Unified Agenda.
  • The 2024 Change Healthcare ransomware attack — the largest protected health care data breach in U.S. history — has renewed pressure on OCR to modernize the HIPAA Security Rule’s cybersecurity requirements.
  • A coalition of more than 100 health care organizations, led by CHIME, sent a December 2025 letter to HHS Secretary Robert F. Kennedy Jr. urging full withdrawal of the proposed Security Rule update, citing its deregulatory inconsistency and compliance burden.
  • Prior HIPAA rulemaking history — including the 2013 Omnibus Rule and the court-vacated 2024 Reproductive Health Care Privacy Rule — suggests finalization in revised or consolidated form is more likely than adoption of the proposed rule as written.