When Is the HIPAA Security Rule Changing? | Darkhorse Tech

When Is the HIPAA Security Rule Changing? The Real 2026–2027 Timeline for Dental Practices | Darkhorse Tech
HIPAA & Compliance

When is the HIPAA Security Rule changing? Here's the real timeline

HHS proposed the biggest rewrite of HIPAA's technical safeguards in over two decades — then pushed the finalization date back from May 2026 to July 2027. Here's what's actually driving the delay, and what dental practices should do before it takes effect.

8 MIN READ HIPAA & COMPLIANCE DENTAL IT
TL;DR

The HIPAA Security Rule update is not finalized yet, and it won't be until at least July 2027 — HHS's original May 2026 target has already slipped. That delay isn't a reason to ignore what's coming: the proposed rule would make encryption, multi-factor authentication, network segmentation, and annual risk audits mandatory for every dental practice, and auditors and cyber insurers already treat most of it as the expected baseline. This fall is the window to close the gaps before the deadline forces the issue.

If you've heard that HIPAA's Security Rule is being rewritten and are wondering exactly when it takes effect, the honest answer is: later than HHS originally said, and later than most dental practices probably expect. Federal regulators proposed the update in January 2025, aimed to finalize it by May 2026, and have since pushed that target to July 2027.

That timeline matters more than it might seem. A pushed-back deadline can read as a reason to wait — but the requirements it's building toward (encryption, multi-factor authentication, regular security testing) are already what auditors and cyber insurers expect from a dental practice today. Here's the actual timeline, why it keeps moving, and what to do with the extra time it's given you.

01When is the HIPAA Security Rule changing?

Direct answer It hasn't changed yet. HHS proposed the update in January 2025 and originally targeted May 2026 for finalization. That date has since been pushed back — the current expected date is July 2027.
Current expected finalization July 2027 Pushed back from an original target of May 2026

According to HIPAA Journal's ongoing tracking of the rulemaking process, that's a meaningful delay, and it's worth sitting with for a second. Dental practices aren't racing toward an imminent deadline. Compliance analysts widely expect the proposed safeguards to become the practical baseline that auditors and cyber insurers expect well before they're legally required, which means the gap between "proposed" and "final" is exactly the window a practice should be using to prepare, not a reason to set the whole thing aside until 2027.

02What is the HIPAA Security Rule 2026 update, and why is HHS rewriting it now?

Direct answer It's a proposed federal rule from HHS that would rewrite HIPAA's technical safeguard requirements for the first time since 2013 — eliminating the current split between “required” and merely “addressable” security measures.

According to HHS's own fact sheet on the proposal, the rule responds to a sharp rise in healthcare data breaches and ransomware attacks, many of which exploited gaps that HIPAA's older “addressable” language allowed practices to treat as optional. For a dental practice, that distinction used to matter: something like multi-factor authentication was a measure you could weigh against cost and skip if you documented a reason. Under the proposed rule, it wouldn't be optional anymore.

03Why does the timeline keep slipping?

Direct answer Rules of this size go through a public comment period before HHS can finalize them, and this rewrite touches encryption, authentication, network architecture, and incident response all at once — which takes longer to work through than a narrow, single-issue update. HHS has already pushed the target date back once, from May 2026 to July 2027.

It's worth separating two different things here: the rule being proposed and the rule being final. A Notice of Proposed Rulemaking, which is the stage this update is still in, is a draft that the public and industry groups can formally comment on before it becomes binding. The scope of this particular rewrite — effectively replacing two decades of "addressable" security language with hard requirements — is large enough that a slipping timeline isn't unusual. What matters for a dental practice is less the reason for the delay and more what to do with the time it creates.

04What actually changes once the rule takes effect?

Direct answer The proposed rule would require dental practices to encrypt patient data at rest and in transit, implement multi-factor authentication, segment their networks, and run vulnerability scans every six months with annual penetration testing. It would also require a current, written inventory of every device and system that touches patient data.

The table below shows how that compares to what's actually required under the current rule:

SafeguardStatus today (2013 Rule)Status under the proposed rule
Encryption of patient data, at rest and in transitAddressable (optional with documented justification)Required, with limited exceptions
Multi-factor authenticationNot explicitly requiredRequired, with limited exceptions
Network segmentationNot explicitly requiredRequired
Vulnerability scanningNot explicitly requiredRequired at least every 6 months
Penetration testingNot explicitly requiredRequired annually
Technology asset inventory and network mapNot explicitly requiredRequired, updated at least annually
Anti-malware and system hardeningAddressableRequired
Backup and recovery controlsAddressableRequired as a separate technical control

If your practice stores patient records somewhere other than a standard on-premise server — including certain out-of-state or offshore data centers — encryption and storage requirements can get more specific still. Darkhorse Tech has broken down the added rules some states like Florida and Wisconsin already impose on healthcare data storage, which are worth checking alongside the federal proposal.

05What operational deadlines will apply once the rule is final?

Direct answer Beyond technical safeguards, the proposed rule would tighten how dental practices document and prove their compliance: restoring critical systems within 72 hours of an incident, notifying staff of access changes within 24 hours, and re-verifying every business associate's security practices annually, in writing.

OCR enforcement already treats gaps like these seriously, even without the new rule in place. Patient Protect's review of recent HIPAA enforcement actions found that Raleigh Orthopaedic Clinic paid $750,000 to resolve OCR findings after sharing patient data with vendors that never signed a business associate agreement — no breach was even required to trigger that penalty. The same review found small practices accounted for 55% of OCR's financial penalties in 2022, which cuts against the assumption that regulators only go after large health systems.

Darkhorse Tech has written before about what happens when a dental organization treats compliance loosely: Aspen Dental's $18.4 million settlement over patient data tracking is a useful reminder that enforcement risk doesn't wait for a new rule to take effect. It exists under the current one too.

06Do dental practices need to comply before the rule officially takes effect?

Direct answer Not legally — but waiting until July 2027 is riskier than it sounds. Cyber insurers and HIPAA auditors already treat most of the proposed safeguards as the expected baseline, and OCR continues to fine practices under the current rule for the exact gaps the new rule targets.

More than 30% of dental practices have experienced a HIPAA-related data breach in the past three years, and nearly half of those breaches stemmed from cybersecurity threats rather than simple paperwork errors, according to compiled dentistry compliance statistics from Resonate App. Healthcare ransomware attacks also surged roughly 58% in 2025 compared to the year before, according to Compudent Systems' analysis of the threat landscape heading into 2026. None of that risk is waiting for a final rule and neither, realistically, should your practice's security posture.

07What should a dental practice do while the rule is still pending?

The most useful thing a dental practice can do right now is treat the proposed rule's requirements as a checklist for the IT and compliance budget you're already building, rather than waiting for a final rule and a hard deadline. A few line items are worth adding now:

  1. 1
    Update your risk analysisIf it's more than a year old, or if you've changed practice management software, added imaging equipment, or had staff turnover.
  2. 2
    Turn on multi-factor authentication everywhere it's availableYour practice management system, email, and remote access tools included.
  3. 3
    Confirm every vendor with access to patient data has a signed, current business associate agreement
  4. 4
    Review how patient communications happenText messages from personal phones and unencrypted email are two of the most commonly cited violations in OCR enforcement actions, and both usually have a low-cost fix.
  5. 5
    Budget for a HIPAA-compliant phone system if you haven't alreadyA cloud VoIP platform built specifically for dental offices, like Mango Voice's dental phone system, keeps patient calls and voicemails secured rather than routed through consumer-grade hardware or personal cell phones.

None of this requires ripping out your existing systems overnight. It requires treating the current delay as planning time rather than a green light to wait.

Not sure where your practice stands?

If you want a sense of what dental-specific IT and compliance support looks like for a practice your size, compare plans or get in touch and we'll walk through where your practice stands today.

Conclusion

The short answer to "when is the HIPAA Security Rule changing" is: not yet, and not until at least July 2027. The longer answer is that the direction is already clear — encryption, multi-factor authentication, network segmentation, and regular security testing are moving from optional to required for every dental practice, not just large groups.

Three things are worth taking from this: the delay gives you real planning time, it doesn't reduce your actual risk exposure, and the highest-risk gaps — outdated risk assessments, missing business associate agreements, unsecured communications — are the same ones OCR is already fining practices over today, under the current rule.

Darkhorse Tech works with dental practices on exactly this kind of preparation every day. If you want help figuring out where your practice stands before the rule takes effect, reach out and we'll help you build a plan around it.

Frequently asked questions

When is the HIPAA Security Rule changing?
It hasn't changed yet. HHS proposed the update in January 2025 and originally targeted May 2026 for finalization, but according to HIPAA Journal's tracking of the rulemaking process, that date has since been pushed back to July 2027.
Why does the HIPAA Security Rule's timeline keep getting delayed?
Major federal rules like this one go through a public comment period before they can be finalized, and a rewrite this large — touching encryption, authentication, network security, and incident response all at once — takes longer to work through than a narrow update. HHS has already pushed the target date back once, from May 2026 to July 2027.
Do dental practices need to comply before the HIPAA Security Rule officially takes effect?
Not legally, but waiting is risky. Cyber insurers and HIPAA auditors already treat controls like multi-factor authentication and encryption as baseline expectations, and OCR continues to fine practices under the current rule for the same gaps the new rule targets.
Will small dental practices be exempt from the new HIPAA Security Rule requirements?
No exemption for small dental practices has been proposed. Patient Protect's review of recent OCR enforcement data found that small practices already accounted for 55% of OCR's financial penalties in 2022, which suggests regulators don't treat practice size as a reason to look the other way.
What should a dental practice do while the rule is still pending?
Update the practice's risk analysis, turn on multi-factor authentication everywhere it's available, confirm every vendor has a signed business associate agreement, review how patient communications happen, and budget for HIPAA-compliant infrastructure — including a secure phone system like Mango Voice's dental phone system — rather than waiting for a compliance deadline to force the issue.

Darkhorse Tech is here for you.

Your dental technology should support your practice, not slow it down. Darkhorse Tech helps dental offices stay secure, connected, and productive with IT support built specifically for dentistry.

Schedule a Consultation Today

Back to Education

Looking to get dental IT support for the first time?

You’re in the right place.

Don’t hesitate to drop us a line, we look forward to connecting with you soon.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Want To Chat?

You can schedule an intro meeting online! Find a time on our calendar that works for you.

schedule today!