HHS is signaling a more assertive posture on healthcare data governance, including active enforcement of information-blocking rules under the 21st Century Cures Act. In Senate HELP Committee testimony, HHS leadership emphasized improving nationwide health data exchange via TEFCA, noting broad connectivity across tens of thousands of locations and support for hundreds of millions of records, while lawmakers raised concerns that providers, health IT developers, and exchanges continue to impede data flow.
Separately, HHS’ Office for Civil Rights has proposed the first major update to the HIPAA Security Rule in over two decades via a January 2025 Notice of Proposed Rulemaking, driven by escalating cyber threats and healthcare breaches. The proposal would move HIPAA from a flexible, risk-based approach toward more prescriptive requirements, including eliminating the “required” vs. “addressable” distinction for implementation specifications, updating/renumbering citations that will force control-mapping changes, mandating defined review and testing frequencies (often at least annually), and requiring detailed asset inventories, network maps, and data-flow documentation showing where ePHI/PHI is created, stored, processed, and transmitted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By March 2026, OCR had not confirmed whether the proposed HIPAA Security Rule update would be finalized on schedule, delayed, narrowed, or issued at all. Reporting noted it could be finalized as early as May 2026, but the timeline remained uncertain.
Following publication of the proposed rule, healthcare providers and industry groups criticized the proposal over cost, implementation burden, and timing. OCR said it received more than 4,700 comments on the Notice of Proposed Rulemaking.
By June 2025, the proposed HIPAA Security Rule modernization was listed in the federal regulatory agenda under RIN 0945-AA22, indicating HHS/OCR was tracking the rulemaking and targeting further action in December 2025. This provided an interim signal on expected timing between the December 2024 proposal and the later March 2026 uncertainty.
On 2025-01-06, the proposed HIPAA Security Rule update was published in the Federal Register along with HHS's regulatory impact analysis. HHS estimated roughly $9.314 billion in combined first-year compliance costs and said the rule would break even if it reduced breach incidence or per-record breach costs by about 7% to 16%.
On 2024-12-27, the HHS Office for Civil Rights issued a Notice of Proposed Rulemaking to strengthen and modernize the HIPAA Security Rule. The proposal would be the first major overhaul of the rule in more than 20 years and would make requirements more prescriptive.
In January 2024, HHS introduced the voluntary Health Care and Public Health Cybersecurity Performance Goals as part of its broader healthcare cybersecurity strategy. These goals were later cited as context for the proposed HIPAA Security Rule modernization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehipaajournal.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcereginfo.gov
Open sourcefederalregister.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.