Medical Practice Compliance Guide

HHS delayed the new HIPAA security rule. Your cyber insurance renewal didn't get the memo.

The federal mandate for multi-factor authentication, encryption, and regular penetration testing has been pushed to at least 2027 — but cyber carriers are already requiring most of it to bind or renew a policy today. Here's what's actually happening at renewal, and how to prepare.

HIPAA Security Rule proposal issuedDec 27, 2024
Public comments received4,000+
Final rule now delayed toAt least July 2027
Current HIPAA rule in the meantimeStill fully enforced
What HHS Actually Proposed

Three requirements carriers already ask about.

The Office for Civil Rights' proposed HIPAA Security Rule update would make several previously optional safeguards mandatory for covered entities and business associates, with limited exceptions.

Multi-Factor Authentication

Mandatory for all access to systems holding electronic protected health information — on-site and remote, not remote access alone as under current guidance.

Encryption at Rest and in Transit

No more "addressable" flexibility. The proposal would require encrypting ePHI both while stored and while moving between systems.

Vulnerability Scanning & Penetration Testing

Vulnerability scans at least every six months, and penetration testing at least once every twelve months — proof the defenses work, not just that a policy exists.

What's Happening at Renewal Right Now

The delay didn't slow down your cyber underwriter.

1

Insurers Moved First

Cyber applications have been asking about MFA, encryption, and backups for several renewal cycles already, independent of whether HHS ever finalizes this rule.

2

Coverage Gets Conditioned

Practices that can't demonstrate these controls see sublimits, coinsurance on ransomware, exclusions, or a declined renewal — not just a higher price.

3

The Old Rule Still Applies

The current HIPAA Security Rule, not the delayed update, remains fully enforceable today and still drives OCR investigations after a breach.

Why Your Broker Is Asking About MFA Before Your Renewal

The proposed federal rule and your cyber application ask the same questions.

HHS pulled its HIPAA Security Rule update off the near-term agenda in 2026, moving it to a long-term list that signals no final rule within the next year. That's a real delay, and it's reasonable to read it as room to breathe. It isn't, at least not for your insurance.

Cyber carriers built their own underwriting questionnaires around the same control set HHS proposed — MFA, encryption, tested backups, a written incident response plan — because that control set is what actually stops the claims they pay out on. A federal delay doesn't change what a carrier asks before binding or renewing a policy, and it doesn't change what a claims adjuster asks after a ransomware event either.

The practices getting surprised right now aren't the ones behind on cybersecurity. They're the ones who assumed the regulatory delay meant the insurance conversation could wait too.

Before Your Next Cyber Renewal

What to have ready when we shop your program.

MFA across every system with ePHI

EHR, email, remote access, and any vendor portal that touches patient data — not just your network login.

Written incident response plan

A plan your staff has actually seen, not a template sitting unopened in a compliance binder.

Tested backup & restore process

Evidence you've actually restored from backup recently, not just that backups run on schedule.

Current business associate agreements

Signed BAAs with every vendor touching patient data, reviewed within the last year.

Details on the proposed HIPAA Security Rule requirements are drawn from the U.S. Department of Health and Human Services' official fact sheet on the Notice of Proposed Rulemaking, issued December 27, 2024. Delay timing is reported by Clark Hill's regulatory tracking coverage of the Fall 2026 Unified Agenda. This page is not legal or compliance advice; confirm your practice's specific obligations with your compliance counsel or IT security provider. Sources: hhs.gov and clarkhill.com.

Not sure your cyber policy covers what you think it does? Let's find out.

Fifteen minutes to walk through your current controls and your current policy, side by side — no obligation, no jargon.

Request My Discovery Call