I spent two days at the beginning of September at the National Institute of Standards and Technology campus in Gaithersburg, Maryland, at the conference NIST co-hosts with the Office for Civil Rights on HIPAA security. It is a government event held on a federal campus, which keeps it small, and the attendance tends to attract those closest to the work: the people in the room are the ones writing the guidance, enforcing the rules, or responsible for following them.
Over two days I heard presentations from and spoke with OCR leadership, with security practitioners, and with the people who carry compliance responsibility inside healthcare organizations. I went expecting to spend most of my attention on the proposed Security Rule overhaul, which has drawn heavier objection from the healthcare industry than any HIPAA rulemaking in years.
OCR Deputy Director Timothy Noonan has previously said the agency received roughly 4,745 comments on it. A great many raised the same point: the proposed requirements would cost too much, and the organizations least able to absorb that cost would be hit hardest. The agenda over two days covered a lot of ground, and most of it was technical.
But OCR’s own sessions kept coming back to a requirement that is not part of the proposal at all. The risk analysis has been mandatory since 2005, and turns up missing or deficient in nearly every enforcement action the agency brings. That is not news to anyone who has worked through an OCR investigation, but conversations I had between sessions only reinforced it.
So the objection to the proposed rule deserves to be taken seriously, and in part it is correct. But a significant share of it is aimed at obligations that already exist, and the debate over what compliance will cost in 2027 skips past a more immediate problem: many organizations are not meeting the requirements already in place. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.
Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Where the rulemaking stands The proposed rule was published in the Federal Register on January 6, 2025, at 90 FR 898 . The comment period closed on March 7, 2025. The rulemaking remains on the Unified Agenda as a long-term action.
OCR Director Paula Stannard clarified the expected timing in her keynote: final action anticipated in July of 2027. That date is worth understanding correctly. It is the point by which OCR currently projects taking its next formal action, not necessarily a publication date for a final rule.
What form the rule takes when it arrives is not yet knowable, but the direction is. A proposed rule is the agency telling the industry where it believes the standard needs to be. The changes are not arbitrary additions and are a reflection of what OCR keeps finding when it investigates.
Whatever the final text says, that is where this is heading, and an organization waiting for the date before it begins risks starting from further behind. OCR did not back away from the reasoning behind the changes. Director Stannard tied them to the increase in large breaches and cyberattacks and to the deficiencies the agency keeps finding in security investigations.
She also provided context as to where things stand on the proposed rule changes as comment review is still underway, adding the administration “may have a different view on some of the burdens and benefits of the proposed changes.” Director Stannard also noted she was limited in what she could say mid-rulemaking, but pointed to the cyber strategy the President released in March.
One pillar of that strategy is common-sense regulation: streamlining cyber rules and keeping them agile enough for the private sector to match evolving threats, while recognizing Americans’ right to privacy in their own data. Another pillar is securing critical infrastructure, which includes healthcare. So, how far the requirements go may still change.
That they are coming is not really in question.. What “addressable” was always supposed to mean Under the current Security Rule, each implementation specification is labeled either required or addressable. That distinction has been widely misunderstood, and the misunderstanding is the source of a good deal of the present objection.
An addressable specification has never been optional. 45 CFR 164. 306(d) sets out what a covered entity must actually do with one.
First, assess whether the specification is a reasonable and appropriate safeguard in your environment. If it is, implement it. If it is not, you must document why it is not reasonable and appropriate, and then implement an equivalent alternative measure if an equivalent alternative measure is reasonable and appropriate.
Translation: addressable means you have to achieve the protection. It gives you room to achieve it a different way if your circumstances call for that, provided you write down your reasoning and what you did instead. It does not give you room to skip it.
An organization that read “addressable” and concluded “optional” was simply not complying. OCR has said so directly. In the preamble to the proposed rule, at 90 FR 917 , the Department states that it is concerned some regulated entities proceed as if compliance with an addressable implementation specification is optional, describes that interpretation as incorrect, and concludes that compliance with the specifications currently designated as addressable is not and should not be optional.
This was a throughline across the OCR sessions in Gaithersburg, and the agency’s frustration with the misreading was evident. That is the context for the proposal to eliminate the required and addressable distinction and make implementation specifications required, with limited specified exceptions.
Originally published at hipaajournal.com


