Key Update: 2025 HIPAA Security Rule Overhaul — HHS published a Notice of Proposed Rulemaking (NPRM) in January 2025 proposing the most significant update to the HIPAA Security Rule (45 CFR Part 164, Subpart C) since its original adoption. The proposed rule would require encryption of all ePHI at rest and in transit, mandatory multifactor authentication, and annual compliance audits. Public comment closed March 2025; a final rule has not yet been issued as of mid-2026.
Who this page is for: Privacy Officers, Compliance Leads, IT Security staff at covered entities, Office Managers new to HIPAA, and Business Associate compliance teams.
HIPAA enforcement is not slowing down. OCR settled or imposed penalties in more cases in 2025 than any prior year, and the proposed Security Rule overhaul signals even stricter requirements ahead. If you handle protected health information, staying current is not optional.
This page covers the most important HIPAA developments, enforcement actions, breach trends, and regulatory changes that affect covered entities and business associates. The compliance blog covers each topic in depth with practical guidance for small and mid-size healthcare organizations.
This page covers the following compliance areas: updated penalty amounts, Security Rule changes, breach trends, ransomware threats to healthcare, and risk assessment requirements.
Protected Health Information (PHI) — Any individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate. PHI includes medical records, billing information, and any data in a medical record that can identify a patient.
Covered Entities — Health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically in connection with a HIPAA-covered transaction. These organizations must comply with HIPAA's Privacy, Security, and Breach Notification Rules.
Business Associates — Organizations or individuals that perform functions or activities on behalf of a covered entity that involve access to PHI. Business associates must sign a Business Associate Agreement (BAA) and comply with applicable HIPAA Security Rule requirements under 45 CFR Part 164, Subpart C.
Office for Civil Rights (OCR) — The division within the U.S. Department of Health and Human Services (HHS) responsible for enforcing HIPAA. OCR investigates complaints, conducts compliance reviews, and issues civil monetary penalties for violations.
Breach Notification Rule — Requires covered entities to notify affected individuals, HHS, and in some cases the media, following a breach of unsecured PHI. Breaches affecting 500 or more individuals must be reported to OCR within 60 days and are posted publicly on the HHS Breach Portal.
OCR enforcement activity reached a record pace in 2025. Civil monetary penalties and settlement agreements increasingly target small and mid-size covered entities, not just large health systems. Common enforcement triggers include failure to conduct a Security Risk Assessment (required under 45 CFR 164.308(a)(1)(ii)(A)), insufficient access controls, and lack of encryption for electronic PHI (ePHI). Updated penalty tiers and fine amounts took effect in 2025 under the adjusted Civil Monetary Penalties published in the Federal Register. For current penalty amounts, see HIPAA Fines and Penalty Amounts.
The HIPAA Security Rule (45 CFR Part 164, Subpart C) sets administrative, physical, and technical safeguard standards for ePHI. The January 2025 NPRM proposes to eliminate the distinction between "required" and "addressable" implementation specifications, making all safeguards mandatory. Key proposed changes include: mandatory encryption of all ePHI at rest and in transit, required multifactor authentication for systems containing ePHI, written technology asset inventories updated every 12 months, and annual compliance audits. The Privacy Rule (45 CFR Part 164, Subpart E), which governs use and disclosure of PHI, remains unchanged in this proposal but is subject to separate rulemaking. For a full breakdown, see New HIPAA Security Rule Changes.
Healthcare data breaches affecting 500 or more individuals continue to increase year over year. In 2024, HHS received over 700 large-breach reports, the highest annual total on record. The most common breach types reported to OCR are hacking/IT incidents (including ransomware), unauthorized access/disclosure, and theft of unencrypted devices. Business associates were involved in a growing share of reported breaches, reflecting expanded enforcement of BA obligations under the HITECH Act. For current data and analysis, see Healthcare Data Breach Trends.
Ransomware remains the most significant cybersecurity threat to healthcare organizations. OCR has stated that a ransomware attack resulting in encryption of ePHI is presumed to be a reportable breach under the Breach Notification Rule unless the covered entity or business associate can demonstrate a low probability of compromise. The Security Rule requires covered entities to implement contingency plans (45 CFR 164.308(a)(7)), including data backup, disaster recovery, and emergency mode operations. For ransomware-specific guidance, see Ransomware Protection for Healthcare.
The Security Risk Assessment (SRA) is required under 45 CFR 164.308(a)(1)(ii)(A) and is the single most frequently cited deficiency in OCR enforcement actions. A compliant SRA must identify all systems that create, receive, maintain, or transmit ePHI; evaluate threats and vulnerabilities to the confidentiality, integrity, and availability of that ePHI; assess current security measures; and determine the level of risk. The assessment must be documented and updated whenever there are significant changes to the organization's environment. For guidance on completing a risk assessment, see Risk Assessment Requirements.
The One Guy Consulting Compliance Blog is the place to be to learn about regulatory matters that directly affect you if you work in the healthcare space.
One Guy Consulting is a consultancy firm that specializes in making the process of becoming HIPAA compliant approachable.
Since 2015 our CEO and Founder, Chuck Weiselberg, has implemented thousands of organizations' HIPAA compliance plans. In this period of over 10 years no client of One Guy Consulting has even failed an audit or been fined for non-compliance.
WOW! How Is That Even Possible?
Excellent question! For our stellar record we have to thank our unqiue approach and process which draws it's content directly from the law without deviating into fluff, getting lost in the legal jargon of it all, or harping on points that are less relevant than others.
The results speak for themselves when it comes to our clients' success in becoming compliant and staying compliant.
Book a demo here to learn more about how we can help you become HIPAA compliant and remain HIPAA compliant