A proposed HIPAA overhaul would make health-data security safeguards mandatory
Reported health-data breaches rose 100% from 2018 to 2023 and the people affected by them 950%. A federal proposal would drop the rule's 'addressable' loophole and require encryption, multi-factor login and more.
| Group | Value (%) |
|---|---|
| Reported breaches | 100 |
| Hacking | 260 |
| Ransomware | 264 |
| Individuals affected | 950 |
The federal rule that governs how health-care organisations protect electronic patient records would be substantially rewritten under a proposal the Department of Health and Human Services published on 6 January 2025 [s1]. The core change is unglamorous but consequential: the proposal would remove the long-standing distinction between "addressable" and "required" security safeguards, so that measures a hospital could previously decline to implement — if it documented why — would instead become mandatory, with only narrow exceptions [s1]. That single edit is what would convert a widely ignored best-practice list into an enforceable floor.
The proposal is a notice of proposed rulemaking (NPRM), not a final rule, issued under HIPAA and the HITECH Act; its public comment period ran to 7 March 2025 [s1]. As of writing it is a proposal, and whether it is finalised — and in what form — is unresolved, which is the appropriate way to read any pending regulation.
The problem the rule is responding to
HHS frames the rewrite as a response to a decade of worsening numbers. Between 2018 and 2023, the department reports, the number of breaches of unsecured protected health information affecting 500 or more individuals grew 100 percent, and the number of individuals affected by those breaches grew 950 percent [s1]. Over the same window it attributes a 260 percent increase to hacking and a 264 percent increase to ransomware specifically [s1]. Its enforcement arm, the Office for Civil Rights, adds that its investigations keep finding the same failures — the rule cites a finding that a large covered entity had not deployed multi-factor authentication across its enterprise before a significant breach [s1].
Independent research points the same way. A study in JAMA Health Forum counted 374 ransomware attacks on US health-care delivery organisations from January 2016 to December 2021, exposing the personal health information of nearly 42 million patients, with the annual number more than doubling from 43 to 91 [s2]. Crucially, these are not purely data problems: the study found that 166 of the attacks (44.4%) disrupted care delivery, including electronic system downtime in 156 (41.7%), cancellations of scheduled care in 38 (10.2%), and ambulance diversion in 16 (4.3%) [s2]. A breach in this sector is often also an interruption of treatment.
What the proposal would require
The NPRM's specific mandates read like a baseline that many outside health care already treat as table stakes. Regulated entities would have to maintain a written inventory of their technology assets and a network map showing how electronic protected health information moves through their systems — the department's argument being that an organisation cannot protect what it has not catalogued [s1]. Encryption of that information, both at rest and in transit, would become a general requirement rather than an "addressable" option [s1]. Multi-factor authentication would be required [s1]. So would network segmentation, the practice of partitioning a network so an intruder who breaches one part cannot move freely through the rest [s1]. And entities would have to run vulnerability scans and penetration tests and then act on what those find within a defined period [s1].
The department estimates the first-year cost of the proposed rule at approximately $9 billion [s1]. It sets that against the cost of the status quo, citing an average of almost $10.1 million per health-care data breach — which it notes is higher than in any other sector [s1]. Whether the $9 billion is money well spent is precisely the kind of judgement the comment process exists to test, and hospital and provider groups can be expected to contest both the price and the pace.
What is genuinely new here
The regulatory substance is less about inventing new security techniques — encryption and MFA are decades old — than about closing the discretion that let organisations opt out. The existing Security Rule was written to be flexible and technology-neutral, and in practice that flexibility became the loophole: an "addressable" specification could be, and often was, addressed by a memo explaining why it would not be implemented [s1]. Making the specifications required, backed by asset inventories and testing that generate evidence of compliance, is an attempt to make the rule auditable rather than aspirational.
What to watch
The open questions are the ordinary ones for a major proposed rule: whether it is finalised, whether the mandates survive the comment period intact or are softened, and how the compliance timeline and cost land on smaller and rural providers, which the ransomware data suggest are among the most exposed [s1][s2]. For how the enforcement landscape around health data has been shifting in parallel, see our coverage of the FTC's Health Breach Notification Rule action against GoodRx and BetterHelp, the FDA's medical-device cybersecurity alerts, and the gap in privacy protection for consumer wearable health data.
Sources
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (NPRM) — U.S. Department of Health and Human Services / Federal Register, 2025-01-06
- Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations — JAMA Health Forum, 2022-12-29
Sources
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Notice of Proposed Rulemaking) — U.S. Department of Health and Human Services / Federal Register , January 6, 2025
- Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations — JAMA Health Forum , December 29, 2022
New US rules make certified health records reveal how their AI was built
A federal rule now requires certified electronic health records to publish a standard set of facts about each predictive algorithm they ship, including how it was validated and whether it was tested for fairness.
Patient portals help a little — and now test results reach patients before the doctor
Reviews find portals may improve awareness and the patient–doctor relationship, with unclear effect on efficiency. Under new US rules, patients now see 40% of results before their clinician does.
How the FTC started fining health apps for feeding your data to advertisers
A dormant breach-notification rule became an enforcement tool in 2023, when the FTC fined GoodRx and BetterHelp for sharing users' health data with ad platforms. A 2024 rule change locked apps into its reach.
The EU AI Act makes most medical AI 'high-risk.' The hard part starts in 2027
Under Article 6, AI that is or sits inside a device already needing an independent safety check counts as high-risk. A 70-study review finds the trouble is overlap with existing device law.