For the past two months, the healthcare security community has been evaluating the proposed HIPAA Security Rule changes. While many discussions have focused on summarizing the updates, the real challenge lies in implementation. These modifications, if finalized, would modernize key security requirements, but they also introduce complex operational hurdles that covered entities and business associates will need to navigate.
This analysis goes beyond just listing the changes—it examines the practical impact these requirements will have in real-world healthcare environments.
Summary of Key Proposed Changes
General Requirements
- Ensure confidentiality, integrity, and availability of electronic PHI (ePHI).
- Protect against reasonably anticipated threats to ePHI.
- Implement administrative, physical, and technical safeguards.
Administrative Safeguards
- Technology Asset Inventory: Maintain an up-to-date inventory of all systems handling ePHI.
- Risk Analysis & Management: Conduct a written risk assessment and update annually or as needed.
- Patch Management: Apply critical patches within 15 days and high-risk patches within 30 days.
- Access Management: Restrict access to ePHI based on job function and terminate access within one hour of employee departure.
- Security Awareness Training: Provide annual security training and frequent updates on emerging threats.
- Audit and Activity Monitoring: Maintain and review system logs for creation, access, modification, transmission, copying, and deletion of ePHI.
- Incident Response & Contingency Plans: Develop documented plans for security incidents and system failures, test them annually.
Physical Safeguards
- Facility Access Controls: Restrict and monitor access to physical locations storing ePHI.
- Workstation Security: Implement security measures to prevent unauthorized access to PHI on workstations.
- Device & Media Controls: Secure disposal and reuse procedures for hardware and media storing ePHI.
Technical Safeguards
- User Access Controls: Require unique user IDs, automatic session timeouts, and separate admin & user accounts.
- Encryption: Encrypt ePHI at rest and in transit where feasible, with written migration plans for non-compliant systems.
- Multifactor Authentication (MFA): Mandatory MFA for all systems unless a migration plan is in place.
- Network Security & Segmentation: Implement security controls to restrict PHI access across networked systems.
- Audit Logging & Retention: Maintain logs of all ePHI interactions and review for security incidents.
- Vulnerability Management: Conduct biannual vulnerability scans and annual penetration tests.
Business Associate (BA) Compliance
- Contractual Compliance Period: BAs operating under outdated agreements may continue for up to 240 days without modification.
- Annual Compliance Verification: BAs must provide annual written verification of security compliance.
- Delegation & Liability: Covered entities remain liable for BAs’ compliance, even if security responsibilities are delegated.

The Devil is in the Details
Several of these proposed changes introduce operational and logistical challenges for covered entities and business associates. Below are some of the more problematic provisions:
- Accelerated Patch Management Timelines: While addressing security vulnerabilities quickly is necessary, vendor dependencies and system testing constraints may make compliance difficult.
- Annual Policy Reviews and Testing: Clarification is needed on how to test governance policies, as some security strategies are difficult to validate through traditional testing methods.
- One-Hour Access Revocation Requirement: Manual workflows for employee terminations can create compliance risks, making investment in IAM solutions a necessity.
- Mandatory Separation of Administrative and User Accounts: Best practice but can introduce licensing costs and usability challenges for organizations using software that charges per account.
- Expanded Audit Logging Requirements: Logging every ePHI interaction creates storage and monitoring burdens, requiring investment in SIEM solutions and 24/7 monitoring.
- Migration Plans for Non-MFA-Compatible Systems: Many healthcare systems lack MFA support, making compliance complex due to vendor limitations and regulatory constraints.
- Annual Vulnerability Scanner Effectiveness Reviews: Requires clearer regulatory guidance on appropriate validation methodologies.
- Conditional Business Associate (BA) Compliance Extensions: BAs under outdated agreements will require close contract monitoring to ensure compliance with new requirements.
Final Thoughts
The proposed HIPAA Security Rule changes reinforce long-standing best practices, but they also introduce execution challenges that go beyond compliance checkboxes. While many discussions have centered on what the rule says, the real question is: how will healthcare organizations realistically implement these mandates without disrupting operations?
As the public comment period remains open until March 6, now is the time for healthcare leaders to evaluate the feasibility of these requirements and provide feedback on areas that may need clarification. Organizations that start preparing now—by assessing IAM capabilities, refining patch management workflows, and strengthening audit logging processes—will be in a better position to adapt, no matter the final outcome.
