Resources · Enterprise infrastructure & compliance
The Security Rule update is still a proposal. Here is what is actually enforceable on your network today, which proposed controls are worth building anyway, and how to tell those two things apart when a vendor is in the room.
Search for HIPAA network requirements right now and most of what comes back describes a 2026 compliance deadline as settled fact, usually alongside a product that will meet it for you.
It is not settled. On December 27, 2024, the Office for Civil Rights issued a Notice of Proposed Rulemaking to modify the Security Rule. It went to the Federal Register on January 6, 2025 and the comment period closed that March. As of today OCR has not issued a final rule, and the Unified Agenda now targets July 2027 for final action — moved back from an earlier spring 2026 target. More than a hundred hospital and provider groups have asked HHS to withdraw the proposal outright.
HHS states the position plainly in its own fact sheet: while the Department is undertaking this rulemaking, the current Security Rule remains in effect.
That does not make the proposal irrelevant. It makes the distinction between enforceable and proposed the single most useful thing a hospital IT director can hold onto in a vendor conversation this year.
The current Security Rule is what OCR investigates against, and it is deliberately less prescriptive than the proposal. It splits implementation specifications into required and addressable— and “addressable” does not mean optional. It means you either implement it, or you document why it is not reasonable and appropriate in your environment and what you did instead.
That documentation requirement is where most organizations are actually exposed. Not because the control is missing, but because the reasoning was never written down.
Risk analysis remains the most frequently cited deficiency in OCR investigations. It is a required specification, not an addressable one, and the failure mode is rarely that nobody did one — it is that the one on file describes an environment that has since changed, or covers the EHR and stops there.
Three things follow from that, and none of them require waiting for a final rule:
The NPRM's structural change matters more than any individual control: it would remove the required/addressable distinction and make all implementation specifications required, with limited exceptions.
For a network team, the proposed additions with direct infrastructure impact are:
Read that list as an engineering roadmap rather than a compliance countdown and it changes character entirely. Most of it is what a well-run hospital network should already be able to evidence.
The proposal may be finalized, weakened, delayed again, or withdrawn. That uncertainty is a reason to sequence carefully, not a reason to wait.
Three of the proposed controls pay for themselves whatever OCR does, because they are prerequisites for everything else rather than compliance artifacts:
This is the one to start with, and not because it is proposed. You cannot segment a network you have not mapped, you cannot scope an encryption programme without knowing where ePHI flows, and you cannot write a defensible risk analysis against an estate nobody has inventoried. Every other item on the list depends on this one existing.
It is also the item most likely to reveal that the real problem is not compliance at all. An organization that cannot produce a current map usually discovers its first engagement is discovery work — a smaller and cheaper project than the compliance programme it was about to buy.
Clinical networks accumulate flat adjacency over time. Biomedical devices, guest wireless, building management, and clinical workstations end up closer together than anyone would design deliberately, because each addition was reasonable in isolation.
Segmentation limits blast radius during an incident. That value is independent of any rule, and the work is slow enough that starting it when a rule finalizes is starting two years late.
The proposed 72-hour restoration requirement is only meaningful if someone has tried it. A documented recovery procedure that has never been exercised is a document, not a capability — and the gap between the two is discovered at the worst possible moment.
The other proposed items — MFA, encryption, scanning cadence, annual audit — are worth doing, but they are more readily bought or scheduled once the first three exist. Sequence accordingly.
HIPAA is not the only obligation attached to a clinical campus, and the other one has been enforceable since 2020 rather than proposed for 2027.
E911 obligations attach to any multi-line telephone system, and a hospital is a difficult case for the same reasons a hotel is: a caller in a patient room or a distant wing frequently cannot describe their own location, room numbers mean nothing to a Public Safety Answering Point without a location database mapping them to a civic address with floor and unit, and campuses reconfigure constantly. E911 obligations attach to any multi-line telephone system regardless of industry.
This matters here because it is a live obligation competing for the same budget and the same team as a proposed one. Compliance decays through moves, adds and changes, and clinical campuses generate more of those than almost any environment — units reconfigure, wings close for renovation, extensions migrate during platform upgrades and the location records attached to them do not follow.
An organization deferring E911 remediation to fund readiness for a rule that may finalize in 2027 has the sequencing backwards.
Four questions tend to separate an organization that needs a compliance programme from one that needs discovery, and from one that needs neither.
Can you produce a current network map showing where ePHI flows? Not an architecture diagram from a previous project. A current one. If the answer is no, that is the first engagement, and it is smaller than the one you were about to scope.
When was your risk analysis last updated, and does it cover the network or only the applications? Application-scoped analyses are common and are the version OCR most often finds insufficient.
For each addressable specification you have not implemented, does the written reasoning exist? This is enforceable today. It is also the cheapest gap on this list to close.
Have you tested a restore, end to end, within the last twelve months? Not verified that backups completed. Restored.
An organization that answers all four cleanly does not need to do anything differently until OCR moves. An organization that cannot answer the first has found its starting point, and has found it cheaply.
If the open question is what your infrastructure actually needs — as opposed to what a vendor says a proposed rule will require — that is an assessment rather than a project.
Enterprise Infrastructure & Compliance covers governance and risk-readiness advisory for exactly this decision. If the question is narrower and architectural — whether a segmentation design or a migration approach holds up before you commit budget — that is Network & Telecom Architecture, and it is worth testing before committing budget.
Both are advisory-only. We do not implement what we recommend, which means there is no version of either engagement where recommending more work pays us more.
Regulatory detail is drawn from the HHS Office for Civil Rights HIPAA Security Rule NPRM fact sheet. The NPRM was issued December 27, 2024 and published in the Federal Register on January 6, 2025; as of September 2026 no final rule has been issued and the current Security Rule remains in effect. Status verified September 3, 2026 — this article will be updated if OCR acts.
Related
The decisions worth testing before committing budget, and the ones that do not need it.
E911 & MLTSCompliance is not a project outcome. It degrades through moves, adds and changes — this explains the governance cycle that prevents it.
ConsultancyGovernance and risk-readiness advisory, with no implementation attached to the recommendation.
Thirty minutes on your estate, the current rule, and what is worth sequencing first.