ciso.diy

HIPAA — the programme you run now, and the Security Rule change coming

The Security Rule NPRM published 6 January 2025 would end "addressable": multi-factor authentication, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required. It has not been finalised — OMB targets July 2027 — while OCR continues enforcing the current rule, and its recurring findings are exactly the things the new rule makes mandatory.

Key dates

2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.

In force Notice of proposed rulemaking published (90 FR 898) — "addressable" would end
Pending OMB target for final action on the Security Rule verify

What practitioners need to know

Lifted verbatim from the kits below, each attributed to the product that says it.

  • All three safeguard categories — Administrative, Physical, Technical — plus the 2026 additions.

    — HIPAA Compliance Checklist 2026
  • Carries a priority flag for the items with the tightest OCR enforcement history, so remediation starts where the fines actually land.

    — HIPAA Compliance Checklist 2026
  • One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.

    — Pillar 01 — The Compliance Operating System
  • A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.

    — Pillar 01 — The Compliance Operating System
  • Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.

    — Pillar 01 — The Compliance Operating System
  • 2026 is the first assessment year with no grace argument — PCI DSS v4.0.1 is the only active version and all 51 future-dated requirements have been mandatory since 31 March 2025.

    — PCI DSS for Healthcare Kit
  • A patient portal that embeds the gateway’s JavaScript is SAQ A-EP, whatever the vendor deck said. 6.4.3 and 11.6.1 were pulled from SAQ A in January 2025 and replaced with an eligibility criterion.

    — PCI DSS for Healthcare Kit
  • Roughly 70% of PCI’s controls are already the HIPAA Security Rule’s — and the HIPAA proposed rule moves toward PCI, not away.

    — PCI DSS for Healthcare Kit
  • Your billing company is both a service provider and a business associate. So is the gateway, the EHR payment module and the IVR vendor — collect the AOC, the BAA and the annual verification together.

    — PCI DSS for Healthcare Kit
  • When an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences — computed here from a single discovery time.

    — PCI DSS for Healthcare Kit

Kits that cover it

5 products, cheapest first.

Compliance

HIPAA Compliance Checklist 2026

Updated for the 2026 Security Rule Final Rule — covers all 12 new mandatory requirements plus the core Administrative, Physical, and Technical safeguards in a single actionable checklist.

PDF
$14.99 View →
Security Program Pillars Featured

Pillar 01 — The Compliance Operating System

Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.

PDF 3 licences
From $149.00 View →
Compliance Featured

PCI DSS for Healthcare Kit

Healthcare takes card payments too — and PCI is assessed separately from HIPAA by people who do not care that you have a Security Rule programme. One control set for both, the SAQ decision that vendors keep getting wrong, and the dual clock when an incident touches PHI and cardholder data at once.

ZIP 3 licences
From $199.00 View →
Compliance Featured

HIPAA Security Rule 2027 Readiness Kit

The 2027 Security Rule is already written. "Addressable" disappears — MFA, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required. Get ahead of it while OCR keeps enforcing the current rule.

ZIP 3 licences
From $199.00 View →
Compliance Featured

HIPAA Readiness Accelerator

The 23-tab HIPAA programme workbook — Privacy Rule, Breach Notification and all three safeguard sets in one place, plus IoMT, telemedicine, AI clinical decision support, biometric and pediatric registers, BAA tracking, evidence, training and an executive dashboard. Largest product in the catalogue.

Excel Word 3 licences
From $499.00 View →

Bundles

5 bundles cover this alongside adjacent work — always below the sum of the parts.

Other regimes: EU AI Act · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum

Working to a date? The compliance calendar. Not legal advice.