HIPAA Updates for 2025–2026: A July 2026 Status Brief

What is effective, what was vacated, what remains proposed, and what a medical practice should put in its regulatory change register now.

Updated

Status date: July 12, 2026. The headline “new HIPAA rule” can describe an effective final rule, a proposal that may change, court-affected provisions, agency guidance, or an enforcement action under an existing rule. Treating those categories as interchangeable produces bad policy. This brief separates them and provides a register a practice can verify with its privacy, security, and legal resources.

This is operational education, not legal advice. Applicability depends on the organization's activities, data, contracts, and jurisdiction. HHS maintains the HIPAA for Professionals portal as the primary starting point. Assign someone to recheck the official source and status before approving a policy or contract change.

Executive status: what is and is not in force

The current HIPAA Security Rule remains in effect. HHS states this directly on its Security Rule NPRM page. The December 2024 proposal would make extensive changes, including more prescriptive requirements involving inventories, network maps, multifactor authentication, encryption, testing, and business-associate verification. Those items are proposals, not effective HIPAA requirements merely because they appear in an HHS fact sheet.

The 2024 Part 2 Final Rule is effective. HHS says the rule became effective April 16, 2024 and compliance was required by February 16, 2026. It concerns confidentiality of substance use disorder patient records governed by 42 CFR part 2 and aligns portions of Part 2 more closely with HIPAA. A practice must determine whether it is a Part 2 program, receives Part 2 records, or has related notice obligations; the label “healthcare provider” alone does not answer that question. See HHS's current Part 2 overview.

Most of the 2024 reproductive-health Privacy Rule was vacated. HHS reports that a federal district court's June 18, 2025 order vacated most of that final rule and only left undisturbed portions of the Notice of Privacy Practices changes. HHS says compliance with the remaining NPP modifications was required February 16, 2026. Use the agency's court-status notice and fact sheet, not an older summary that predates the decision.

Regulatory change register for a practice

Item and source versionStatusApplicability question and rationaleDecision ownerDue dateLast verifiedEvidenceNext status trigger
HHS OCR Security Rule; current-rule page reviewed by HHS March 19, 2026 Final rule; currently effective Which systems and workflows create, receive, maintain, or transmit ePHI, and which duties attach to this entity's covered-entity or business-associate role? The answer defines the risk-analysis and safeguard scope. Designated security official with privacy, operations, and counsel input Practice-set after scope or material change; no new 2026 compliance date created by this brief July 12, 2026 Current scope, risk analysis, risk-treatment decisions, policies, safeguards, and evaluation records Material environmental or operational change, incident, new authoritative guidance, or final rule
HHS OCR Security Rule NPRM; issued December 27, 2024 Notice of Proposed Rulemaking; not effective law If finalized, which proposed changes would affect current systems, contracts, and workflows? Readiness planning can expose gaps, but proposal language is not labeled as a current mandate. Security and privacy leaders with operations, counsel, and affected vendors No compliance due date while proposed; practice-set monitoring date July 12, 2026 Proposal-impact worksheet clearly marked proposed; official-source monitoring assignment Federal Register final rule, withdrawal, supplemental proposal, or material HHS update
HHS 2024 Part 2 Final Rule overview; final rule effective April 16, 2024 Final; compliance was required February 16, 2026 Is the organization a Part 2 program, does it receive Part 2 records, or does another role create a specific duty? Document the facts because healthcare-provider status alone does not decide applicability. Privacy officer and counsel; Part 2 program leadership when applicable February 16, 2026 where applicable; confirm immediately if status or evidence is unresolved July 12, 2026 Written applicability rationale, consent and disclosure workflow, notice, breach process, and training evidence New Part 2 service or data flow, HHS rule or guidance update, incident, or court action
HHS 2024 reproductive-health Privacy Rule status page; updated for June 18, 2025 court order Most provisions vacated; specified NPP modifications remain Which undisturbed NPP provisions apply to this practice after the court order? A documented legal review prevents reliance on a pre-order summary. Privacy officer with counsel February 16, 2026 for remaining applicable NPP modifications; confirm now if unresolved July 12, 2026 Court-affected scope analysis, approved NPP, posting and distribution records Further court order, appeal, HHS rulemaking, or revised official status notice
HHS revised model NPPs; February 2026 models Agency templates and guidance; not private certification Does the practice's notice accurately describe its own services, rights workflow, locations, web presence, and applicable Part 2 content? A model still requires practice-specific review. Privacy officer with communications and counsel February 16, 2026 for applicable new NPP content; otherwise upon material privacy-practice change July 12, 2026 Approved effective notice, website and facility posting, distribution method, and acknowledgment process Material privacy-practice change, new service or location, HHS model revision, or Part 2 status change
HHS OCR resolution agreements and civil money penalties; current enforcement library Enforcement outcomes under applicable existing rules; not new rules of general applicability Does a published finding expose a comparable, evidenced weakness in this practice's facts? Similarity should be documented rather than assumed from an industry headline. Privacy or security official with leadership and counsel Practice-set from risk and corrective-action priority July 12, 2026 Fact comparison, current control evidence, decision rationale, corrective-action owner and closure proof Relevant OCR outcome, complaint, investigation, incident, audit finding, or control failure

What practices should verify now

1. Notice of Privacy Practices

HHS published revised model Notices of Privacy Practices in February 2026. HHS says covered providers and plans subject to the requirement must include Part 2-related information as of February 16, 2026, and must prominently post the current notice on a website that describes customer services or benefits. A template still requires organization-specific review, an effective date, appropriate distribution, and alignment with actual privacy practices.

2. Current Security Rule evidence

Do not wait for the proposed rule to perform the work required today. The current rule protects the confidentiality, integrity, and availability of electronic protected health information through administrative, physical, and technical safeguards. HHS's risk-analysis guidance calls for an accurate and thorough assessment of potential risks and vulnerabilities and rejects a one-size-fits-all blueprint. Keep the system scope, data flows, threats, vulnerabilities, decisions, remediation owners, and review triggers visible.

3. Breach and incident workflow

A security incident is not automatically a reportable breach, and the IT provider should not make that legal determination alone. Preserve facts, contain the event, notify the designated privacy and security roles, follow contract timelines, and perform the required assessment. HHS's Breach Notification Rule guidance explains the presumption, risk-assessment factors, and notification framework. The current HHS reporting portal also distinguishes covered-entity, business-associate, Part 2, and qualified-service-organization roles.

Separate the parties before assigning tasks

Covered entity decisions: The practice determines its status and scope, designates required roles, approves policies, defines permissible workflows, conducts or obtains its risk analysis, handles patient-rights processes, and decides how an incident is evaluated and reported with appropriate professional advice.

Business associate or MSP work: An MSP may be a business associate when its services involve creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity. Its duties come from applicable HIPAA provisions and the business associate agreement. HHS explains that business associates are directly liable for specified HIPAA requirements. The contract should state permitted uses, safeguards, incident reporting, subcontractor flow-down, access to records, and termination handling rather than promising generic “HIPAA certification.”

Software-vendor work: A vendor should document the functions it operates, security features it provides, data it can access, logs and exports available to the practice, incident communications, and end-of-contract data handling. Vendor claims do not determine the practice's status, satisfy its risk analysis, or prove that the configured workflow is compliant. Some vendors may be business associates; others may have different obligations. Classify from the facts and contract.

Keep four workstreams visible

  • Privacy: permitted uses and disclosures, minimum necessary where applicable, patient rights, notices, complaints, and data-sharing decisions.
  • Security: risk analysis, access, authentication, devices, logging, configuration, vulnerability management, incident response, and technical recovery.
  • Quality: correct patient matching, complete records, accurate interfaces, usable corrections, and reliable provenance. HIPAA security work does not by itself prove clinical data quality.
  • Availability: prioritized clinical workflows, downtime procedures, tested backups, vendor dependencies, and restoration decisions. Availability is a Security Rule objective, but the clinic must define what continuity means operationally.

A 30-day update process

  1. Appoint one register owner and record the status, source URL, applicability question, decision owner, due date, and evidence for every item above.
  2. Verify the current NPP against the HHS model and the practice's actual services, locations, website, and Part 2 relationships.
  3. Read the existing risk analysis and list systems, locations, vendors, and data flows added since it was completed. Assign unresolved gaps rather than merely changing the document date.
  4. Review business associate agreements and service exhibits for incident timing, access changes, logs, recovery, subcontractors, and exit handling. Do not import proposed-rule language as a current mandate.
  5. Report status to leadership as effective, proposed, guidance, enforcement signal, under legal review, or not applicable with rationale. Set a trigger to revisit each open item.

Use the HIPAA and PCI roadmap when payment-card and health-data scopes overlap, the healthcare MSP selection guide for provider due diligence, and the NIST CSF healthcare guide to organize cybersecurity outcomes without confusing a voluntary framework with law.

Official sources

Suggested next step

Put the six register rows in the next privacy and security meeting. Require a source-backed status and evidence link for each one before funding new tools. Contact Cloud Core MSP if the resulting technical work needs a scoped implementation plan.

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.