HIPAA & Compliance
8 min read0 views

HIPAA 2026 NPRM: What Changes and When You Need to Comply

The proposed 2026 HIPAA Security Rule eliminates the distinction between Required and Addressable safeguards. Most healthcare websites will fail. Here is the timeline.

RocketOpp

AI & Automation Insights

Published

Saturday, July 12, 2025

HIPAA 2026 NPRM: What Changes and When You Need to Comply

The Big Change

The HIPAA Security Rule hasn't been substantially updated since 2013. The 2026 Notice of Proposed Rulemaking (NPRM) changes everything.

The headline: "Addressable" safeguards become Required.

Under the current rule, organizations can document why an "addressable" safeguard isn't necessary and implement an alternative. Under the NPRM, that option disappears. Every safeguard becomes mandatory.

What This Means in Practice

| Requirement | Current Rule | 2026 NPRM | |---|---|---| | Multi-Factor Authentication | Addressable | Required | | Encryption at Rest | Addressable | Required | | Vulnerability Scans | Not Specified | Every 6 Months | | Penetration Tests | Not Specified | Every 12 Months | | Risk Analysis | Required | Annual + Technology Map | | Compliance Audit | Not Specified | Annual |

The Timeline

  • ~May 2026: Final rule publication expected
  • ~August 2026: Last realistic start date for remediation
  • ~January 2027: Compliance deadline (~180 days post-publication)
  • The Penalty Structure

    HIPAA penalties are severe and cumulative:

    | Tier | Per Violation | Annual Cap | |---|---|---| | Did Not Know | $141 – $71,162 | $2.13M | | Reasonable Cause | $1,424 – $71,162 | $2.13M | | Willful Neglect (Corrected) | $14,232 – $71,162 | $2.13M | | Willful Neglect (Not Corrected) | $71,162 – $2.13M | $2.13M |

    Criminal penalties can include up to 10 years imprisonment.

    What To Do Now

  • Scan your website — 0nCore's HIPAA Scanner runs 63 automated checks against both current law and the 2026 NPRM
  • Fix the easy wins — security headers, HSTS, version disclosure (most are free, under 30 minutes)
  • Plan for MFA — this is the biggest change; start implementing now
  • Document everything — BAAs with every vendor, risk analysis, incident response plan
  • Budget for audits — annual compliance audits will be required
  • The 63-Point Scanner

    0nCore's HIPAA Scanner checks:

  • Transport Security (14 checks)
  • Privacy Disclosures (10 checks)
  • Security Headers (13 checks)
  • Authentication Controls (12 checks)
  • Data Exposure (14 checks)
  • Plus 7 administrative attestation checks. Results include dual scoring (current law vs NPRM), prioritized remediation roadmap, and state-specific compliance overlays.


    Scan your healthcare website for free at rocketopp.com/hipaa. 63 checks, 30 seconds, no PHI collected.

    Share this article

    Let's Start a Conversation

    Ready to leverage AI and automation for your business? We'd love to hear about your challenges and goals.

    Schedule a Call