What is changing in HIPAA, and when

The Security Rule overhaul that has not landed, the reproductive health rule a court erased, the Part 2 changes that did take effect, and the penalty numbers that moved. What is law today, what is only proposed, and what it means for an ABA clinic.

Last verified: 2026-07-12

Everyone in health care privacy is waiting on the same thing, and most of what is written about it is written in the wrong tense. So here is the state of play, dated, with the rule in force separated from the rule that has been proposed, and nothing described as law that is not law.

This page carries a visible last-verified date and is reviewed monthly, because it is the page most likely to go stale, and a stale page about pending regulation is worse than no page at all.

The Security Rule overhaul: proposed, delayed, not law

On January 6, 2025, HHS published a notice of proposed rulemaking to substantially rewrite the HIPAA Security Rule, the first major overhaul in over two decades (90 FR 800). The comment period closed in March 2025.

What it would do, if finalized. Eliminate the addressable category entirely, making every implementation specification required. Mandate encryption of ePHI at rest and in transit, with narrow exceptions. Mandate multi-factor authentication. Require a written technology asset inventory and a network map showing how ePHI moves through your systems. Impose specific cadences for testing, vulnerability scanning, and review. Require annual compliance audits.

Where it actually stands. No final rule has been issued. HHS had a working target in spring 2026; that passed without a rule. The federal regulatory agenda now shows final action pushed to July 2027, a date that has already moved once. An industry coalition has formally asked HHS to withdraw the proposal outright.

So the honest reading. The proposal is not law. It has never been law. And a clinic that reorganized itself around a rule that may never arrive has made a planning error in the opposite direction from the clinic ignoring it entirely.

The useful move is neither. Look at what the proposal is actually made of: encryption, MFA, an asset inventory, real risk analysis cadence. Every one of those is something an honest risk analysis under the current rule already concludes is reasonable and appropriate for a clinic whose ePHI rides into living rooms on tablets. The proposal would make mandatory what the existing rule’s addressable path already leads a truthful clinic to do.

“The proposal is not law. It has never been law. And a clinic that reorganized itself around a rule that may never arrive has made a planning error in the opposite direction”

Which is why the practical answer is the same either way: do the addressable work honestly today (45 CFR 164.306). If the rule lands, you are adjusting rather than rebuilding. If it never lands, you were compliant anyway. Nobody who does the honest version gets hurt by either outcome.

The reproductive health rule: erased, but still printed

This one matters because almost every HIPAA resource on the internet, including some published by reputable firms, still describes it as binding law.

In April 2024, HHS finalized amendments creating special protections for reproductive health care information (89 FR 32976): a prohibition on certain uses and disclosures, a required attestation before others, a new definition in 160.103, and new Notice of Privacy Practices content.

In June 2025, a federal court vacated nearly all of it, nationwide (Purl v. HHS, No. 2:24-cv-00228-Z, N.D. Tex., June 18, 2025). HHS did not appeal, and the appeal window closed in August 2025.

What that means in practice. There is no reproductive health attestation requirement. The 164.509 attestation section, the 164.502(a)(5)(iii) prohibition, the 160.103 reproductive health care definition, the related abuse-reporting carve-out, and the reproductive-health NPP items are all unenforceable. OCR cannot enforce them.

And the trap. The text is still printed in the Code of Federal Regulations. A clinic reading the CFR today will find provisions that look mandatory and are not. A vendor generating an NPP from the CFR text will generate one built partly on vacated paragraphs. If your Notice of Privacy Practices or your policy set was written or updated between mid-2024 and mid-2025, it is worth checking what it says.

One piece of the 2024 package survived. The Notice of Privacy Practices changes relating to substance use disorder records under 42 CFR Part 2 were not vacated, and their compliance date was February 2026. If your clinic holds Part 2 records, that one is real and it is already in force.

Part 2 enforcement is arriving

42 CFR Part 2 is the separate, stricter federal confidentiality rule for substance use disorder treatment records. It is not HIPAA, but the 2024 alignment brought it much closer, and violations now carry HIPAA-scale penalties.

OCR has signaled it is preparing to enforce the updated Part 2 rules. For most ABA clinics this is not a live issue; if you do not hold SUD treatment records, it does not reach you. But if you are part of a larger behavioral health organization that does, this is a real change and it deserves its own look.

The penalty numbers moved

HHS published its inflation adjustment on January 28, 2026 (91 FR 3666). Tier minimums are now 145, 1,461, 14,602, and 73,011 dollars; the per-violation maximum for the first three tiers is 73,011; the codified calendar-year cap is 2,190,294.

The 2019 enforcement discretion (84 FR 18151), which applies much lower annual caps to tiers one through three, has still not been rescinded or incorporated into the regulation. So the codified numbers remain the exposure and the discretion remains the practice. The full picture, with the layers separated.

These figures move every January. If you are reading this in a new year, check the date above.

Enforcement is where the real change is happening

While the rulemaking has stalled, enforcement has not, and this is the change that actually affects you.

OCR launched a dedicated Risk Analysis Initiative in late 2024, targeting one failure: entities that never conducted a compliant risk analysis. It has produced a steady run of settlements, and OCR’s April 23, 2026 announcement of four simultaneous ransomware settlements (1,165,000 dollars, more than 427,000 individuals affected) found the same deficiency in all four: no accurate and thorough risk analysis before the breach.

And OCR has said the initiative is expanding from risk analysis into risk management. The question is moving from “did you identify your risks” to “what did you actually do about them.” A clinic with a current analysis and an untouched list of findings is precisely the profile the expanded initiative describes.

Notice what that means. The rule did not change. The enforcement posture sharpened, and it sharpened around the requirement that was already first in the Security Rule (45 CFR 164.308(a)(1)(ii)(A) and (B)). You do not need a new rule to be exposed by an old one.

What an ABA clinic should actually do about all of this

Nothing dramatic, and one thing specific.

Do not restructure your program around a proposed rule. Do not ignore it either. Do the addressable work honestly under the rule that exists: encryption on the devices that travel, MFA where credentials reach ePHI, an inventory of where your data actually lives, a risk analysis that describes your clinic, and a remediation list with dates on it.

That is the whole answer, and it is the same answer whether the proposal lands in 2027, arrives in a narrower form, or dies. It is also, not coincidentally, what OCR is enforcing today.

How this page is maintained

Reviewed monthly until the Security Rule proposal resolves. Every regulatory event triggers a sweep of the other pages it touches, not just this one. The date at the top of this page is the last time a human verified every claim on it against a primary source. If that date is old, treat this page with the same suspicion we would.

The short version

  • The Security Rule overhaul proposed in January 2025 is still a proposal. No final rule has issued, and the federal agenda now shows final action pushed to July 2027.
  • The 2024 reproductive health privacy provisions were vacated nationwide in June 2025 and HHS did not appeal. The text remains printed in the CFR and has no legal force.
  • The 42 CFR Part 2 alignment did take effect: NPPs addressing substance use disorder records were required from February 2026.
  • HIPAA penalty amounts were adjusted January 28, 2026; the 2019 enforcement discretion on annual caps still stands.
  • OCR's Risk Analysis Initiative is expanding into risk management: from did you look, to what did you do about what you found.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Built for the rule that exists.

WiseUpHIPAA computes against the law in force today, and the honest work it asks for is most of what the proposal would require anyway. When the rules move, the platform moves; your evidence does not have to be rebuilt.