The proposed federal rule and your cyber application ask the same questions.
HHS pulled its HIPAA Security Rule update off the near-term agenda in 2026, moving it to a long-term list that signals no final rule within the next year. That's a real delay, and it's reasonable to read it as room to breathe. It isn't, at least not for your insurance.
Cyber carriers built their own underwriting questionnaires around the same control set HHS proposed — MFA, encryption, tested backups, a written incident response plan — because that control set is what actually stops the claims they pay out on. A federal delay doesn't change what a carrier asks before binding or renewing a policy, and it doesn't change what a claims adjuster asks after a ransomware event either.
The practices getting surprised right now aren't the ones behind on cybersecurity. They're the ones who assumed the regulatory delay meant the insurance conversation could wait too.