By the EHR Association Privacy & Security Workgroup
With the recent publication of the US Department of Health and Human Services’ (HHS) 2026 unified regulatory agenda, the HHS Office for Civil Rights (OCR) hit the snooze button on HIPAA Security Rule updates. Final rulemaking for the January 2025 HIPAA Security Notice of Proposed Rule Making (NPRM) was targeted for a May 2026 release in the previous unified agenda, but notably excluded from the current agenda. Instead, it was transitioned to a long-term action with a target date of July 2027.
While this delay buys time to get the rule right, it isn’t cost-free, as the cyberattack trend that justified the NPRM in the first place hasn’t paused.
Read the full post »
