Healthcare Regulation Brief

Healthcare Regulation Brief

The 240-Day Problem

Why the HIPAA Security Rule delay is runway, not a reprieve.

When word went around that the HIPAA Security Rule overhaul had slipped again, a lot of healthcare security leaders got the same message from the same people: good news, we have time.

It is not good news, and you do not have as much time as the headline suggests. Here is the arithmetic that explains why.

Where the rule actually stands

HHS released the Notice of Proposed Rulemaking in late December 2024. It published in the Federal Register on January 6, 2025. The comment period closed on March 7, 2025 with more than 4,700 comments submitted.

The opposition has been organized and serious. More than 100 hospital systems and provider associations, including major academic medical centers and national physician organizations, formally asked HHS to withdraw the proposal. The core objection is cost and prescriptiveness. HHS’s own regulatory impact analysis put first year industry cost at roughly $9 billion, with something in the range of $6 billion annually for the following four years. For small and rural providers already running on thin margins, that is not an abstraction.

OCR’s regulatory agenda originally targeted spring 2026 for final action. That window came and went with nothing published. OMB’s Unified Agenda now lists final action for July 2027 under RIN 0945-AA22.

Three things follow from that, and they need to be held at the same time:

  • The rule is not law. Nothing in the NPRM is enforceable. Anyone selling you compliance with the 2026 HIPAA Security Rule is selling you compliance with a document that does not exist.
  • The current Security Rule is still fully in force, and OCR is still enforcing it. Inadequate risk analysis remains the most frequently cited deficiency in OCR investigations. The most common finding in healthcare enforcement is failure at the most foundational requirement, which should tell you something about baseline maturity across the sector.
  • The final text is genuinely uncertain. HHS could finalize as proposed, narrow it substantially, or withdraw it. Predicting which is not a security strategy.

The compliance window is the part nobody reads

Buried in the proposal is a timeline that determines everything about how you should be planning.

If the rule finalizes as written, it takes effect 60 days after publication in the Federal Register. Most provisions then require compliance 180 days after the effective date. Business associate agreement updates get a narrow extension, running through renewal after the compliance date or one year after the effective date, whichever applies.

Round it off. Roughly 240 days from the moment a final rule publishes to the moment most of it is enforceable against you.

That number is the whole problem. It is short enough that the rule’s finalization date and your preparation timeline are almost unrelated. If you start on publication day, you are already late.

What has to happen in 240 days

Set aside the citations and look at the work itself.

An asset inventory and a network map that reflect reality. Not the CMDB that has been drifting since the last acquisition. An actual inventory of everything that creates, receives, maintains, or transmits ePHI, and a map of how those systems connect. In a mid-sized health system with clinical devices, imaging, a hosted EHR, a dozen SaaS vendors, and whatever the last merger brought along, this is a three to four month project on a good day. Every other requirement depends on it.

Encryption of ePHI at rest and in transit, with no addressable escape hatch. The proposal eliminates the addressable category entirely. The documented justification you wrote in 2019 explaining why encrypting that legacy system was not reasonable and appropriate stops being an option. Finding every place ePHI sits unencrypted takes the inventory you have not built yet.

Multi-factor authentication on systems accessing ePHI. Technically straightforward. Organizationally slow, because clinical workflow objections are real and pushing MFA onto shared workstations in a clinical setting is a change management project, not a configuration change.

Network segmentation. The longest pole in the tent. Segmenting a flat clinical network without disrupting care delivery is a multi-quarter effort in almost every environment we test. It also cannot start meaningfully until the map exists.

Vulnerability scanning at least every six months, and penetration testing at least every twelve. The proposal names penetration testing explicitly, which HIPAA never has before, and requires it be performed by a qualified person. It also proposes remediation timelines tied to severity, which is a harder change than the testing requirement for organizations running quarterly or semiannual patch cycles.

An annual compliance audit against every standard and implementation specification. Distinct from your risk analysis, and additive to it.

Written verification from business associates, annually, backed by analysis and certification. Plus a requirement that business associates notify covered entities within 24 hours of activating a contingency plan.

Now sequence those. The inventory gates the encryption work and the segmentation work. The segmentation work substantially changes what a penetration test finds, so testing before it is done produces findings you already know about. The pen test produces remediation work that takes its own cycle. Then you need to demonstrate the whole thing in an audit.

Run that dependency chain honestly and it does not fit in 240 days. It fits in about eighteen months.

The uncomfortable implication

The delay to 2027 does not give you more time. It gives you the amount of time the work actually requires, for the first time.

An organization that starts the inventory now and sequences from there will absorb a final rule as documentation. An organization that waits for a Federal Register notice will be buying emergency remediation, emergency testing capacity, and emergency consulting at the exact moment every other covered entity in the country is doing the same thing. Qualified penetration testing capacity does not expand on demand. Neither do the network engineers who know how to segment a clinical VLAN without dropping a telemetry feed.

There is also the possibility that the rule is withdrawn entirely, and it is worth addressing directly rather than pretending it is remote.

If it is withdrawn, what have you lost? You will have built an accurate asset inventory, encrypted ePHI end to end, deployed MFA, segmented your network, established a scanning cadence, and run an independent penetration test.

That is not compliance overhead. That is the control set that determines whether a phished credential becomes a help desk ticket or a two-week clinical outage. Healthcare remains among the most expensive sectors in which to suffer a breach, and the cost is not primarily the regulatory penalty. It is downtime, diversion, notification, and litigation.

Ransomware operators do not read the Unified Agenda.

A defensible order of operations

If you are building the plan this quarter, this is the sequence we would argue for.

  • Months 1 through 4. Asset inventory and network map. Nothing else moves until this does. Include medical devices, which are frequently missing from IT inventories entirely and which sit under a separate FDA regime that does not exempt them from your network.
  • Months 3 through 8. Encryption gap closure and MFA rollout, running in parallel with the tail of the inventory work. Both are constrained by clinical workflow negotiation more than by technology.
  • Months 5 through 12. Network segmentation, informed by the map. Expect this to take longer than planned.
  • Months 10 through 14. Penetration test, scoped against the segmented environment. Then remediation, then retest of the material findings. Testing before segmentation gives you a report about a network you are about to change.
  • Ongoing from month 4. Vulnerability scanning cadence, business associate verification workflow, and the annual compliance audit process. These are operational disciplines, not projects, and standing them up early means the first cycle is a rehearsal rather than an exam.

One structural note. Whoever performs the penetration test should not be the party selling you the remediation. A vendor grading its own work has an obvious incentive problem, and covered entities have started asking business associates about that separation during diligence. Expect it to become standard.

The short version

The HIPAA Security Rule overhaul is proposed, contested, and currently pointed at July 2027. It may change substantially. It may not survive.

The compliance clock it carries is roughly 240 days, and the work it describes takes about eighteen months to do properly. That gap is the entire reason the delay matters, and it is the opposite of the reason most boards think it matters.

Compliance dates move. Attackers do not.

Brackish Security runs penetration tests against healthcare environments and the systems that hold ePHI. We test the way attackers work, and we do not sell the remediation we scope.

Talk to us about scoping: brackish.io/contact

This article summarizes publicly available regulatory information as of August 2026 and is not legal advice. The HIPAA Security Rule NPRM is a proposed rule and is not currently enforceable. Timeline estimates for remediation work are Brackish Security’s own, based on engagements in comparable environments, and will vary with scope and organizational readiness. Confirm current regulatory status with counsel before making compliance decisions.