September 22, 2026
Key takeaways
  • Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
  • AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
  • Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
  • Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.

Last Updated on September 23, 2026

Delaying the HIPAA Security Rule update until July 2027 gives healthcare firms more time to prepare for stricter cybersecurity requirements. Current HIPAA guidelines remain in full effect, and active cyber threats continue to increase in sophistication and effectiveness.

What are the right strategic moves to make the most of the delay while safeguarding sensitive data? This article shares top recommendations.

Key takeaways

  • The HIPAA Security Rule is a part of the HIPAA legislation that sets US national standards for protecting electronic healthcare data. An update to the Security Rule was proposed in 2025 to expand the mandated control set. It also proposes removing the “addressable” versus “required” language in the law, which will reduce implementation flexibility and make the rule more prescriptive.
  • Delaying the update does not pause the current enforcement scenario. It also does not take the pressure off healthcare organizations to strengthen their security postures in the face of relentless attacks.
  • Healthcare businesses should view the delay as giving them a longer planning window to roll out essential controls that are already required to obtain cyber insurance and deemed essential to protect sensitive data by leading cybersecurity standards.
  • Covered businesses should start preparing now for new HIPAA requirements and technical controls that will be coming soon.

What is the HIPAA Security Rule and why was it delayed?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a US national law designed to regulate the security and privacy of medical data and other sensitive healthcare patient data, often referred to as protected health information or PHI. Its original purpose was to help workers keep their health insurance when they changed jobs or lost a job. 

 

The HIPAA Security Rule is a component of the act that sets US national standards to protect electronic PHI (ePHI). It mandates administrative, physical, and technical controls to ensure the confidentiality, integrity, and availability of ePHI.

In response to widespread healthcare data breaches exposing millions of ePHI records, a Notice of Proposed Rulemaking (NPRM) issued in Q1 2025 seeks to strengthen HIPAA’s technical controls by introducing new requirements. These include multifactor authentication (MFA), mandatory encryption, network segmentation, and yearly penetration testing. It also proposes removing “addressable” versus “required” language that gave covered organizations leeway on control implementation.

 

The US Department of Health and Human Services (HHS) delayed the target date for finalizing proposed updates to the HIPAA Security Rule from May 2026 to July 2027. This date is a planning estimate, not an official deadline.

Reasons cited include pushback from healthcare organizations on the financial and operational burdens the new technical mandates would impose. HHS received over 4,000 public comments regarding the proposed rule. Moving the action item to the long-term regulatory agenda allows time to refine the proposed requirements before issuing a final rule.

What does delaying the HIPAA Security Rule update NOT mean?

For covered entities and business associates, delaying the HIPAA Security Rule does not mean a pause in the current enforcement regime. The current version of the HIPAA Security Rule remains fully in effect and enforceable by the Office for Civil Rights (OCR).

The delay also does not give healthcare entities latitude to wait on cybersecurity investments. Healthcare remains one of the most popular targets for cybercriminals due to the high value of ePHI and overall lax security.

 

Finally, the delay does not mean that stricter requirements are not coming soon. While some of the proposed updates may be revised or removed before the final rule is published, HHS would still need to introduce changes to counter escalating threats.

What is the recommended strategic view of the delay scenario?

Covered entities and business associates should view the delay as constituting a longer planning window to budget for and implement essential controls like encryption, network segmentation, and MFA.

 

While the current proposed rule may change before it becomes final, expectations will undoubtedly be higher going forward. Treating the proposed controls as “voluntary” or “nice to have” and failing to account for them now could jeopardize compliance and leave businesses scrambling to implement them later.

Moreover, many of the proposed new controls are already mandated by cyber insurance underwriters and required within best-practice cybersecurity standards and frameworks like ISO 27001, HITRUST CSF, and the NIST Cybersecurity Framework.  

What should healthcare firms do now to prepare for upcoming HIPAA changes?

While the HIPAA Security Rule update is still in the proposed phase, covered entities should start preparing now for significant new requirements and technical safeguards that will be coming soon—and which are vital to prevent data breaches.

Important steps include:

  • Perform a gap assessment against the proposed new requirements.
  • Develop and maintain a comprehensive asset inventory, network map, and ePHI flow diagrams.
  • Apply advanced encryption to all ePHI at rest and in transit (servers, endpoints, mobile devices, backups).
  • Enforce MFA across every system that touches ePHI.
  • Segment networks to isolate ePHI, restrict attackers’ lateral movement in your environment, and reduce data breach impacts. 
  • Begin conducting vulnerability scans at least twice per year and penetration testing at least once per year. 
  • Create actionable plans to remediate high-risk vulnerabilities.
  • Begin conducting comprehensive risk assessments at least annually and whenever significant IT infrastructure changes take place.
  • Identify all business associates and other third parties that handle ePHI and evaluate their cybersecurity postures.
  • Update Business Associate Agreements (BAAs) to reflect new incident notification timelines.

What’s next?

The upcoming HIPAA Security Rule changes are still “proposed.” But they are sure to shift HIPAA compliance from a policy/documentation focus to quantifiable control performance. Operationalizing the new controls and not just relying on written policies will be critical to success.

Planning and preparing now for more robust cybersecurity can help businesses control costs, reduce disruption risks, and enhance competitive posture before enforcement begins. Waiting until the new requirements are compulsory to get started will likely make the effort cost more and take longer—while increasing cyber risk exposure.

 

CBIZ has extensive experience helping HIPAA covered entities efficiently achieve and maintain compliance while demonstrating robust cybersecurity.

Connect with a member of our cybersecurity team to discuss how HIPAA Security Rule changes could impact your business and how best to address them.

Back to Blog