
- 01Encryption of ePHI at rest and in transit moves from 'addressable' to 'required' — every legacy ePHI system without end-to-end encryption becomes a remediation project on the day the rule lands.
- 02MFA on all access to ePHI, mandatory asset inventories, network maps, annual penetration tests, biannual vulnerability scans, and risk-based patch SLAs all become testable requirements.
- 03Business associates pick up subcontractor verification with annual written attestations. SaaS vendors handling ePHI should plan for a wave of enhanced security questionnaires the moment the rule is finalized.
- 04Asset and data-flow inventory is the lowest-risk, highest-leverage thing to start now — every other proposed control depends on knowing where ePHI lives and what touches it.
The HHS Office for Civil Rights's Notice of Proposed Rulemaking for the HIPAA Security Rule signals the most consequential changes since the rule was finalized in 2003. While the final rule may shift, several changes are widely expected to land.
Likely material changes
- 01Encryption of ePHI at rest and in transit becomes 'required,' not 'addressable'
- 02Multi-factor authentication for access to ePHI
- 03Mandatory technology asset inventory and network mapping
- 04Annual penetration testing and biannual vulnerability scans for in-scope systems
- 05Documented patch management with risk-based timelines
- 06Mandatory written incident response plan with annual exercises
The implication for business associates
The proposed rule sharpens business-associate obligations. BAs must verify the security practices of their subcontractors annually, with written attestations. SaaS vendors handling ePHI should expect a wave of enhanced security questionnaires the moment the rule lands.
Start with the inventory
Every other proposed control depends on knowing where ePHI is and what touches it. An accurate, automatically refreshed asset and data-flow inventory is the lowest-risk, highest-leverage thing to start now, regardless of how the final rule is worded.


