If you've heard that HIPAA's Security Rule is being rewritten and are wondering exactly when it takes effect, the honest answer is: later than HHS originally said, and later than most dental practices probably expect. Federal regulators proposed the update in January 2025, aimed to finalize it by May 2026, and have since pushed that target to July 2027.
That timeline matters more than it might seem. A pushed-back deadline can read as a reason to wait — but the requirements it's building toward (encryption, multi-factor authentication, regular security testing) are already what auditors and cyber insurers expect from a dental practice today. Here's the actual timeline, why it keeps moving, and what to do with the extra time it's given you.
01When is the HIPAA Security Rule changing?
According to HIPAA Journal's ongoing tracking of the rulemaking process, that's a meaningful delay, and it's worth sitting with for a second. Dental practices aren't racing toward an imminent deadline. Compliance analysts widely expect the proposed safeguards to become the practical baseline that auditors and cyber insurers expect well before they're legally required, which means the gap between "proposed" and "final" is exactly the window a practice should be using to prepare, not a reason to set the whole thing aside until 2027.
02What is the HIPAA Security Rule 2026 update, and why is HHS rewriting it now?
According to HHS's own fact sheet on the proposal, the rule responds to a sharp rise in healthcare data breaches and ransomware attacks, many of which exploited gaps that HIPAA's older “addressable” language allowed practices to treat as optional. For a dental practice, that distinction used to matter: something like multi-factor authentication was a measure you could weigh against cost and skip if you documented a reason. Under the proposed rule, it wouldn't be optional anymore.
03Why does the timeline keep slipping?
It's worth separating two different things here: the rule being proposed and the rule being final. A Notice of Proposed Rulemaking, which is the stage this update is still in, is a draft that the public and industry groups can formally comment on before it becomes binding. The scope of this particular rewrite — effectively replacing two decades of "addressable" security language with hard requirements — is large enough that a slipping timeline isn't unusual. What matters for a dental practice is less the reason for the delay and more what to do with the time it creates.
04What actually changes once the rule takes effect?
The table below shows how that compares to what's actually required under the current rule:
| Safeguard | Status today (2013 Rule) | Status under the proposed rule |
|---|---|---|
| Encryption of patient data, at rest and in transit | Addressable (optional with documented justification) | Required, with limited exceptions |
| Multi-factor authentication | Not explicitly required | Required, with limited exceptions |
| Network segmentation | Not explicitly required | Required |
| Vulnerability scanning | Not explicitly required | Required at least every 6 months |
| Penetration testing | Not explicitly required | Required annually |
| Technology asset inventory and network map | Not explicitly required | Required, updated at least annually |
| Anti-malware and system hardening | Addressable | Required |
| Backup and recovery controls | Addressable | Required as a separate technical control |
If your practice stores patient records somewhere other than a standard on-premise server — including certain out-of-state or offshore data centers — encryption and storage requirements can get more specific still. Darkhorse Tech has broken down the added rules some states like Florida and Wisconsin already impose on healthcare data storage, which are worth checking alongside the federal proposal.
05What operational deadlines will apply once the rule is final?
OCR enforcement already treats gaps like these seriously, even without the new rule in place. Patient Protect's review of recent HIPAA enforcement actions found that Raleigh Orthopaedic Clinic paid $750,000 to resolve OCR findings after sharing patient data with vendors that never signed a business associate agreement — no breach was even required to trigger that penalty. The same review found small practices accounted for 55% of OCR's financial penalties in 2022, which cuts against the assumption that regulators only go after large health systems.
Darkhorse Tech has written before about what happens when a dental organization treats compliance loosely: Aspen Dental's $18.4 million settlement over patient data tracking is a useful reminder that enforcement risk doesn't wait for a new rule to take effect. It exists under the current one too.
06Do dental practices need to comply before the rule officially takes effect?
More than 30% of dental practices have experienced a HIPAA-related data breach in the past three years, and nearly half of those breaches stemmed from cybersecurity threats rather than simple paperwork errors, according to compiled dentistry compliance statistics from Resonate App. Healthcare ransomware attacks also surged roughly 58% in 2025 compared to the year before, according to Compudent Systems' analysis of the threat landscape heading into 2026. None of that risk is waiting for a final rule and neither, realistically, should your practice's security posture.
07What should a dental practice do while the rule is still pending?
The most useful thing a dental practice can do right now is treat the proposed rule's requirements as a checklist for the IT and compliance budget you're already building, rather than waiting for a final rule and a hard deadline. A few line items are worth adding now:
- 1Update your risk analysisIf it's more than a year old, or if you've changed practice management software, added imaging equipment, or had staff turnover.
- 2Turn on multi-factor authentication everywhere it's availableYour practice management system, email, and remote access tools included.
- 3Confirm every vendor with access to patient data has a signed, current business associate agreement
- 4Review how patient communications happenText messages from personal phones and unencrypted email are two of the most commonly cited violations in OCR enforcement actions, and both usually have a low-cost fix.
- 5Budget for a HIPAA-compliant phone system if you haven't alreadyA cloud VoIP platform built specifically for dental offices, like Mango Voice's dental phone system, keeps patient calls and voicemails secured rather than routed through consumer-grade hardware or personal cell phones.
None of this requires ripping out your existing systems overnight. It requires treating the current delay as planning time rather than a green light to wait.
Not sure where your practice stands?
If you want a sense of what dental-specific IT and compliance support looks like for a practice your size, compare plans or get in touch and we'll walk through where your practice stands today.
Conclusion
The short answer to "when is the HIPAA Security Rule changing" is: not yet, and not until at least July 2027. The longer answer is that the direction is already clear — encryption, multi-factor authentication, network segmentation, and regular security testing are moving from optional to required for every dental practice, not just large groups.
Three things are worth taking from this: the delay gives you real planning time, it doesn't reduce your actual risk exposure, and the highest-risk gaps — outdated risk assessments, missing business associate agreements, unsecured communications — are the same ones OCR is already fining practices over today, under the current rule.
Darkhorse Tech works with dental practices on exactly this kind of preparation every day. If you want help figuring out where your practice stands before the rule takes effect, reach out and we'll help you build a plan around it.

