← Back to Resources
Free Article Article HIPAA

The 2026 HIPAA Security Rule Is Getting a Facelift

A plain-language breakdown of every significant change in the 2026 HIPAA Security Rule NPRM and what it means for your tech stack.

The 2026 HIPAA Security Rule Is Getting a Facelift

IRON FORT SOLUTIONS · 2026

Instant email delivery — no waiting
Written by compliance professionals
Updated for 2026 regulatory changes
No credit card required

Get Free Access

Enter your work email and we'll send the download link immediately.

Your info is never sold or shared. Unsubscribe anytime.

Article · HIPAA · Read in full

A plain-language breakdown of every significant change in the 2026 HIPAA Security Rule NPRM and what it means for your tech stack.

In 2025, HHS published a landmark proposed update to the HIPAA Security Rule — the first major revision since 2013. The 2026 NPRM isn't a minor tweak. It's a substantial rewrite that reflects two decades of evolving threats, cloud infrastructure, and healthcare technology that the original rule never anticipated.

The Big Picture: Why This Update Was Overdue

The HIPAA Security Rule has been largely unchanged since 2003. In that time, the healthcare industry has moved from on-premises servers to multi-cloud architectures, from paper fax machines to mobile apps, from isolated hospital networks to interconnected ePHI ecosystems spanning dozens of vendors. The rule's "addressable vs. required" structure — which let organizations substitute alternative measures for many technical controls — created compliance variability that OCR found difficult to enforce consistently.

Change #1: "Addressable" Controls Become Required

This is the most sweeping change. Under the original rule, many implementation specifications were "addressable" — organizations could document why they chose alternative measures. The NPRM converts most addressable specifications to required, eliminating the ambiguity. Encryption at rest and MFA are the two highest-impact examples.

Change #2: Technology Asset Inventory Becomes Required

Covered entities must now maintain a current, documented inventory of all technology assets that touch ePHI — updated at least annually. This formalizes what security-mature organizations already do, but creates new obligations for organizations relying on informal knowledge of their technology stack.

Change #3: Incident Response Gets Specific

The NPRM adds specificity to incident response requirements that were previously vague. Organizations must have written, tested incident response plans with defined roles, escalation procedures, and recovery timelines. The 72-hour breach notification window makes a tested IR plan operationally essential.

Change #4: Vulnerability Management Timelines Defined

For the first time, the HIPAA Security Rule specifies vulnerability remediation timelines. Critical vulnerabilities must be patched within 15 days; high severity within 30 days. Scans must occur at least every six months. This brings HIPAA closer to NIST's vulnerability management framework.

Summary: What You Need to Implement

RequirementWhat It MeansEffective
MFARequired for all ePHI system access2026
Encryption at RestRequired for all ePHI stored on any media2026
Asset InventoryAnnual technology asset inventory required2026
Vuln ScanningEvery 6 months minimum; 15/30 day remediation SLAs2026
Breach Notification72 hours to HHS (down from 60 days)2026
BAA Updates24-hour incident notification; subcontractor accountability2026
IR PlanningWritten, tested, role-assigned incident response plan2026

Get a free HIPAA NPRM gap assessment at goironfort.com/demo — see exactly what you need to update.

Want the formatted PDF?

You've just read the whole thing. If you'd like the designed, printable version to share with your team or attach to an audit file, we'll email it over.

Email Me the PDF →