Has the New HIPAA Security Rule Taken Effect?
No. This is worth stating plainly, because a great deal of published content says otherwise.
The proposed overhaul was published in the Federal Register in January 2025. The public comment period closed in March 2025.
A final rule has not been issued. Regulatory agendas have shifted the target date more than once.
So where does that leave your practice?
- The existing Security Rule remains fully in force
- Enforcement is active and ongoing right now
- The proposed changes are not yet binding requirements
- Preparing early is sensible, but the obligation today is the current rule
Anyone telling you the new rule is already law is working from outdated information.
What Is a HIPAA Security Risk Analysis?
It is a documented assessment of every risk to your electronic protected health information.
The obligation sits at 45 CFR 164.308 within the Administrative Safeguards. It requires an accurate and thorough evaluation of potential risks and vulnerabilities.
Three qualities matter to regulators. Accuracy, thoroughness, and evidence that it actually happened.
A checklist someone filled in once does not meet this standard.
Why Is This Getting So Much Regulatory Attention?
Because it is the easiest violation to prove.
When investigators arrive after a breach or a complaint, the first request is almost always the same. Show us your risk analysis.
A dedicated enforcement initiative has been running on this specific requirement for several years. Recent years have produced some of the highest annual enforcement totals on record.
The scope is also widening. Regulators have signalled that simply having a risk analysis is no longer the end of the question. They now ask whether the organisation acted on what it found.
What that shift means
- A completed analysis sitting in a drawer is not compliance
- Findings must connect to a documented remediation plan
- Remediation must have owners and timelines
- Progress must be reviewable
What Does OCR Find Wrong Most Often?
Three findings appear again and again in enforcement actions.
| Finding | What it looks like |
|---|---|
| Never conducted | The practice simply never did one |
| Incomplete | Some systems covered, others missed entirely |
| Never updated | Done once years ago, then filed away |
That third one catches otherwise diligent practices. An analysis completed several years ago does not satisfy today’s requirement.
Small practice size offers no exemption. The requirement applies regardless of headcount.
What Must a Compliant Risk Analysis Include?
Regulators expect specificity, not general assurances.
Asset and Data Mapping
- Every system that creates, receives, stores or transmits ePHI
- Cloud applications and hosted platforms
- Connected medical devices
- Mobile devices and remote access points
- Third-party processors and vendors
Threat and Vulnerability Identification
- Reasonably anticipated threats to each asset
- Technical vulnerabilities in current configurations
- Human and procedural weaknesses
- Physical access exposures
Risk Evaluation
- Likelihood of each threat occurring
- Potential impact if it does
- Current safeguards already in place
- Residual risk after those safeguards
Documented Output
- A risk register listing findings
- A remediation plan with assigned owners
- Executive review and sign-off
- Retained documentation with a defined review cadence
A properly scoped HIPAA security risk analysis covers all four layers rather than sampling one
How Often Should It Be Updated?
There is no single fixed interval written into the rule. There is a clear expectation.
Most compliance guidance points to an annual review as the baseline. Certain events should trigger an off-cycle review regardless of timing.
Trigger a fresh review when
- You adopt a new EHR or practice management system
- You add cloud storage or a new hosted platform
- You open a new location or add remote workers
- You onboard a vendor that touches ePHI
- You experience a security incident, however minor
- Your patient volume or service mix changes substantially
Regular daily, weekly and monthly reports help practices notice operational changes that should trigger a review.
Is Your Billing Company a Business Associate?
Yes, and this matters more than most practices realise.
Any vendor that handles ePHI on your behalf is a business associate. That vendor carries its own direct compliance obligations. It also carries yours by extension.
Vendor oversight is a recurring theme in enforcement actions. Missing or outdated business associate agreements appear repeatedly.
Where ePHI moves between your practice and vendors
Clinical documentation is a clear example. Raw patient narrative flows through the workflow in medical transcription.
Financial transactions are another. Patient and payment identifiers move through EFT, ERA and EBI setup.
What to verify with every vendor
- A current, signed business associate agreement exists
- The agreement contains required breach notification provisions
- The vendor conducts its own risk analysis
- Access is limited to what the vendor genuinely needs
- Access is revoked promptly when relationships end
Ask your vendors for evidence. A vendor that cannot produce it is a documented risk on your register.
Which Practices Carry the Highest ePHI Exposure?
Risk is not evenly distributed. Two factors raise it sharply.
The first is data volume. High-throughput environments touch enormous quantities of patient records daily, which is why ePHI safeguards matter especially in diagnostic laboratories services.
The second is data sensitivity. Records involving minors carry heightened privacy expectations and guardian access complexity in pediatric medical billing services.
Neither factor changes the legal requirement. Both change how carefully your analysis needs to be scoped.
What Would Change If the Proposed Rule Is Finalised?
Nothing is binding yet. But the direction is clear enough to plan around.
| Current rule | Proposed direction |
|---|---|
| Some specifications are addressable | Nearly all become required |
| Encryption flexible in places | Encryption expected broadly |
| MFA treated as best practice | MFA expected as a control |
| Risk analysis periodic | More rigorous, more frequent |
| Access termination reasonable | Far tighter timeframes |
If finalised, organisations would get a defined transition window before compliance is required. Practices that prepare early would face configuration work rather than a scramble.
This article is general information, not legal advice. Confirm your obligations with qualified counsel.
A Practical Starting Checklist
If you do nothing else this quarter, do these.
- Locate your most recent risk analysis and check its date
- List every system touching ePHI, including cloud and mobile
- Confirm the analysis actually covers all of them
- Check that findings connect to a written remediation plan
- Verify remediation items have owners and dates
- Collect current business associate agreements from every vendor
- Confirm access is revoked promptly for departed staff
- Document executive review and retain the evidence
Build Compliance That Holds Up Under Review
The requirement has not changed since 2003. What has changed is how closely regulators examine it. A risk analysis that exists but was never acted upon no longer satisfies anyone.
Our team supports practices across New York and all fifty states with compliance-aware billing operations. We maintain the safeguards and documentation on our side of the relationship.
Reach out and contact our billing team to discuss your current compliance posture.
Fast Billing Solutions 68 South Service Road, Suite 100, Melville, NY (631) 500-1007
Compliance is not a document you produce once and file away, it is a process you can evidence at any moment. Fast Billing Solutions works with practices that take that difference seriously.
Frequently Asked Questions
No. The overhaul remains a proposed rule. The existing Security Rule is what applies and what is being enforced.
Annually as a baseline, with off-cycle reviews after significant system, staffing or vendor changes.
Yes. Any vendor handling ePHI on your behalf is a business associate and requires a signed agreement.
Yes. The requirement applies regardless of practice size. Size offers no exemption.
It is the most commonly cited deficiency in investigations. Penalties are tiered and assessed per violation, and an unmet requirement can be counted for each day it remains unaddressed.
More answers are available on our frequently asked questions page.