Sep 23, 2026
News
The HIPAA Security Rule Overhaul Got Delayed to 2027 — Here's Why South Florida Practices Shouldn't Wait


If you heard that the big HIPAA Security Rule update got pushed back and breathed a sigh of relief, that relief is misplaced. The delay doesn't lower the bar — it just means the bar HHS already set for you years ago is still the one you're being held to today, while a stricter one quietly gets finalized in the background.
Here's what's actually going on, and what it means if you run a small medical practice in South Florida.
What actually happened
In January 2025, the Department of Health and Human Services proposed the first major overhaul of the HIPAA Security Rule in more than a decade. It would require things like mandatory multi-factor authentication for anyone accessing electronic patient health information, encryption of that data at rest and in transit, an annual technology asset inventory and network map, vulnerability scans at least every six months, penetration testing at least once a year, and documented internal audits on the same annual cadence.
The rule drew more than 4,000 public comments, and a coalition of over 100 hospital and provider groups asked HHS to withdraw it outright, largely over implementation cost and feasibility for smaller organizations. HHS missed its original May 2026 target, and the latest federal regulatory agenda now points to roughly July 2027 for a final rule — with an actual compliance deadline likely landing around March 2028 once the standard effective-date and implementation windows are added on. None of that is locked in; these are planning estimates, and they've already slipped once.
Why the delay doesn't actually help you
Here's the part that's easy to miss: the current HIPAA Security Rule — the one written in 2003 — never went away and is fully enforceable right now. The Office for Civil Rights hasn't paused investigations or enforcement actions while the new rule works its way through the process. A breach today gets evaluated against today's rule, and "we were waiting to see what the new rule required" isn't a defense.
There's a second, more practical reason the delay doesn't buy you much room: several of the proposed rule's headline requirements — real multi-factor authentication, encryption, documented risk analyses, regular vulnerability scanning — are already what cyber insurers ask about on applications, and already what most breach investigations flag as the gap that let an attacker in. We wrote a few weeks ago about how more than 40% of cyber insurance claims get denied because what a practice attested to on its application didn't match what was actually deployed. The proposed rule is essentially HHS catching up to what insurers and attackers already treat as baseline. Waiting for the regulation to force your hand means you're already behind where your risk profile needs you to be.
There's also a smaller, already-passed deadline worth flagging: updated Notice of Privacy Practices requirements took effect February 16, 2026. If your practice hasn't reviewed and updated its NPP since then, that's a gap that exists independent of anything still pending.
What this means if you're a South Florida practice
For practices across Palm Beach, Broward, and Miami-Dade counties — and increasingly for the practices we're working with as we extend our HIPAA-focused support into Martin and St. Lucie counties, including Stuart and Port St. Lucie — the practical reality is the same regardless of where you're located or which version of the rule is technically in force: OCR enforcement, state breach notification laws, and insurer underwriting all already expect the controls the new rule would make mandatory. A practice that waits for the 2027 deadline to act is choosing to carry avoidable risk for roughly two more years, on the assumption that nothing goes wrong in the meantime.
The practices in the best position aren't the ones tracking the federal rulemaking calendar closely. They're the ones who treated "what would a real HIPAA Security Rule update require" as a checklist to work through now, on their own timeline, instead of a deadline to scramble for later.
Practical takeaways
Don't treat the 2027 delay as permission to deprioritize security spending — the existing 2003 Security Rule is fully enforceable today, and OCR enforcement hasn't slowed down.
Confirm MFA is enabled on every account that touches patient data, not just email and EHR logins — admin accounts and third-party portals get missed most often.
Verify your encryption coverage for data at rest and in transit; don't assume it's already handled without checking.
Schedule a genuine, documented risk analysis if you haven't done one in the past year — this is the single most common gap OCR cites in enforcement actions.
Ask whether your last vulnerability scan and penetration test happened within the past six and twelve months, respectively.
Confirm your Notice of Privacy Practices was updated to reflect the February 2026 requirements.
Test your backup and disaster recovery process — not just that backups exist, but that you could actually restore from them.
None of this requires waiting for a final rule. It requires treating the version of HIPAA compliance that already protects your practice — and your patients — as the standard, not the floor.

