ANALYSIS

A proposed HIPAA overhaul would make health-data security safeguards mandatory

Reported health-data breaches rose 100% from 2018 to 2023 and the people affected by them 950%. A federal proposal would drop the rule's 'addressable' loophole and require encryption, multi-factor login and more.

Increase in reported breaches and cyberattacks, 2018–2023Reported breaches: 100%; Hacking: 260%; Ransomware: 264%; Individuals affected: 950%0%500%1000%Reported breaches100%Hacking260%Ransomware264%Individuals affected950%
Increase in reported breaches and cyberattacks, 2018–2023
GroupValue (%)
Reported breaches100
Hacking260
Ransomware264
Individuals affected950
Increase in reported breaches and cyberattacks, 2018–2023 Increases the department reports over 2018–2023, from breaches of unsecured PHI affecting 500 or more individuals. Source: U.S. Department of Health and Human Services / Federal Register

The federal rule that governs how health-care organisations protect electronic patient records would be substantially rewritten under a proposal the Department of Health and Human Services published on 6 January 2025 [s1]. The core change is unglamorous but consequential: the proposal would remove the long-standing distinction between "addressable" and "required" security safeguards, so that measures a hospital could previously decline to implement — if it documented why — would instead become mandatory, with only narrow exceptions [s1]. That single edit is what would convert a widely ignored best-practice list into an enforceable floor.

The proposal is a notice of proposed rulemaking (NPRM), not a final rule, issued under HIPAA and the HITECH Act; its public comment period ran to 7 March 2025 [s1]. As of writing it is a proposal, and whether it is finalised — and in what form — is unresolved, which is the appropriate way to read any pending regulation.

The problem the rule is responding to

HHS frames the rewrite as a response to a decade of worsening numbers. Between 2018 and 2023, the department reports, the number of breaches of unsecured protected health information affecting 500 or more individuals grew 100 percent, and the number of individuals affected by those breaches grew 950 percent [s1]. Over the same window it attributes a 260 percent increase to hacking and a 264 percent increase to ransomware specifically [s1]. Its enforcement arm, the Office for Civil Rights, adds that its investigations keep finding the same failures — the rule cites a finding that a large covered entity had not deployed multi-factor authentication across its enterprise before a significant breach [s1].

Independent research points the same way. A study in JAMA Health Forum counted 374 ransomware attacks on US health-care delivery organisations from January 2016 to December 2021, exposing the personal health information of nearly 42 million patients, with the annual number more than doubling from 43 to 91 [s2]. Crucially, these are not purely data problems: the study found that 166 of the attacks (44.4%) disrupted care delivery, including electronic system downtime in 156 (41.7%), cancellations of scheduled care in 38 (10.2%), and ambulance diversion in 16 (4.3%) [s2]. A breach in this sector is often also an interruption of treatment.

What the proposal would require

The NPRM's specific mandates read like a baseline that many outside health care already treat as table stakes. Regulated entities would have to maintain a written inventory of their technology assets and a network map showing how electronic protected health information moves through their systems — the department's argument being that an organisation cannot protect what it has not catalogued [s1]. Encryption of that information, both at rest and in transit, would become a general requirement rather than an "addressable" option [s1]. Multi-factor authentication would be required [s1]. So would network segmentation, the practice of partitioning a network so an intruder who breaches one part cannot move freely through the rest [s1]. And entities would have to run vulnerability scans and penetration tests and then act on what those find within a defined period [s1].

The department estimates the first-year cost of the proposed rule at approximately $9 billion [s1]. It sets that against the cost of the status quo, citing an average of almost $10.1 million per health-care data breach — which it notes is higher than in any other sector [s1]. Whether the $9 billion is money well spent is precisely the kind of judgement the comment process exists to test, and hospital and provider groups can be expected to contest both the price and the pace.

What is genuinely new here

The regulatory substance is less about inventing new security techniques — encryption and MFA are decades old — than about closing the discretion that let organisations opt out. The existing Security Rule was written to be flexible and technology-neutral, and in practice that flexibility became the loophole: an "addressable" specification could be, and often was, addressed by a memo explaining why it would not be implemented [s1]. Making the specifications required, backed by asset inventories and testing that generate evidence of compliance, is an attempt to make the rule auditable rather than aspirational.

What to watch

The open questions are the ordinary ones for a major proposed rule: whether it is finalised, whether the mandates survive the comment period intact or are softened, and how the compliance timeline and cost land on smaller and rural providers, which the ransomware data suggest are among the most exposed [s1][s2]. For how the enforcement landscape around health data has been shifting in parallel, see our coverage of the FTC's Health Breach Notification Rule action against GoodRx and BetterHelp, the FDA's medical-device cybersecurity alerts, and the gap in privacy protection for consumer wearable health data.

Sources

Sources

  1. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Notice of Proposed Rulemaking) — U.S. Department of Health and Human Services / Federal Register , January 6, 2025
  2. Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations — JAMA Health Forum , December 29, 2022
Related coverage