HIPAA Security Rule Amendments (Proposed)
90 FR 898, January 6, 2025 (NPRM)
The most significant proposed update to the HIPAA Security Rule since 2003. This is a Notice of Proposed Rulemaking — not a final rule. The current Security Rule remains in effect and fully enforceable. If finalized, the proposal would (subject to limited exceptions) require encryption of ePHI at rest and in transit, multi-factor authentication, network segmentation, vulnerability scanning and penetration testing on defined cadence, an annual compliance audit, written technology asset inventory and network map review, and the capability to restore certain relevant electronic information systems and data within 72 hours. The proposal would also remove the required/addressable distinction and make implementation specifications required, subject to specific limited exceptions.
What it means for your practice
- The proposal would remove the required/addressable distinction and make implementation specifications required, subject to specific limited exceptions.
- The proposal would require multi-factor authentication for access to ePHI, subject to limited exceptions.
- The proposal would require network segmentation controls that isolate systems storing or processing ePHI.
- The proposal would require vulnerability scanning and penetration testing on defined cadence — most independent practices have never done either.
- The proposal would require the capability to restore certain relevant electronic information systems and data within 72 hours. This is a restoration/recovery obligation — NOT a new HHS breach notification deadline. HIPAA breach notification remains 60 calendar days after discovery for breaches of 500+ (§164.408).
- The proposal would require a written technology asset inventory and network map with defined review cadence.
What to do now
- 1Verify encryption is enabled on all systems storing or transmitting ePHI (EHR, email, backups, cloud storage) — a Patient Protect baseline today, and a likely requirement if the NPRM finalizes.
- 2Implement MFA on all accounts with ePHI access — start with EHR and email.
- 3Conduct a technology asset inventory — document every device, system, and vendor that touches patient data.
- 4Engage an IT provider or MSP to assess network segmentation options.
- 5Review your incident response plan — document your 72-hour restoration capability and confirm your HIPAA notification workflow (individuals: 60 days §164.404; HHS: 60 days for 500+ §164.408).
- 6Schedule your first vulnerability scan if you've never done one.
Patient Protect: Patient Protect already implements encryption, role-based access with MFA, and per-session ePHI access logging with tamper-evident storage as our own standard. These are Patient Protect controls, not currently-required HIPAA mandates — but if the NPRM finalizes, practices on Patient Protect will be positioned to satisfy the majority of the new explicit requirements.

