HIPAA Security Rule 2027 Readiness Kit
The 2027 Security Rule is already written. "Addressable" disappears — MFA, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required. Get ahead of it while OCR keeps enforcing the current rule.
What this actually gives you
- The proposed text has been public since 6 January 2025, and OMB now targets July 2027 for final action — the requirements are written down, in public, years before they bind.
- "Addressable" disappears. MFA, encryption, an asset inventory with a network map, 72-hour restoration, annual audits, six-monthly scans and annual business-associate verification all become required.
- OCR enforces the current rule meanwhile — and its top findings are exactly MFA, asset inventory and risk analysis. Work done now counts twice.
- Every MSP, SaaS platform, billing company and law firm holding PHI must certify its safeguards to each customer annually. Customers will ask before the rule does.
- Several vendor write-ups claim the Breach Notification Rule moves to 72 hours. It does not — the 24-hour and 72-hour clocks are contingency-activation notice and system restoration.
The proposed text has been public since 6 January 2025, and OMB now targets July 2027 for final action. That is unusual and it is the whole opportunity: the requirements are written down, in public, years before they bind. Nobody has to guess what is coming.
"Addressable" disappears. The word that let a covered entity document why it had not implemented a safeguard is gone from the proposal. Multi-factor authentication, encryption at rest and in transit, an asset inventory with a network map, 72-hour restoration of critical systems, annual compliance audits, six-monthly vulnerability scans and annual business-associate verification all become required.
Meanwhile OCR enforces the rule you are under today — and its top findings are exactly the things the new rule makes mandatory: MFA, asset inventory and risk analysis. Work done now counts twice. That is the argument this kit is built around.
Business associates are on the clock first, socially if not legally. Every MSP, SaaS platform, billing company and law firm holding PHI will have to certify its safeguards to each customer annually. Customers will start asking before the rule requires it, and the kit runs in either direction — covered-entity mode or business-associate mode — with file 01 setting the mode every other file reads.
What you get
01 Applicability & Mode (XLSX) — the regulated-entity test, the CE / BA / BOTH mode that drives the rest of the kit, the assumed compliance date, and what changes depending which side of the relationship you are on.
02 Proposed-Rule Control Crosswalk (XLSX) — 27 controls, each with the proposed requirement, its NPRM citation, what changes versus the current rule, the NIST CSF 2.0 and 405(d) HICP mapping, the evidence and the cadence. Its decision engine separates what you are exposed on now — MFA, encryption — from what is merely a future-requirement gap, and asks a business associate the question its customers will: could you certify this today?
03 Asset Inventory & ePHI Flows + Network Map Narrative (XLSX + DOCX) — the inventory carrying the NPRM's own fields (criticality, support end date, MFA, encryption, backup scope, network segment), the ePHI flow register, and the written network map with zones and flow narratives. Everything else in the rule scopes from this, which is why it is the file to fill first.
04 72-Hour Restoration Plan (DOCX) — criticality analysis, backup design, per-system restoration procedures with tested times, the 24-hour contingency notice, the annual test plan, and how it meshes with incident response.
05 Annual Compliance Audit Workplan (XLSX) — a 15-control audit workplan with tests, evidence and sample sizes, and a testing calendar that computes next-due and overdue for every cadence the proposal introduces.
06 BA Verification Tracker + Pack (XLSX + DOCX) — obtain-side and provide-side trackers, the subject-matter-expert analysis template, the certification itself, BAA amendment clauses, request and response letters, and a reviewer checklist.
07 Leadership Report (PPTX) — two slides: what the rule requires and where you stand, then the plan, the exposure and the decisions you need.
08 Practitioner Guide (PDF) — where the rule stands, what changes, the two modes, the inventory foundation, MFA and encryption, the 72 hours, the cadences, BA verification, sequencing, the annual audit, the MSP-as-BA problem, failure patterns and an FAQ.
hipaa27.json — the controls, cadences and thresholds, machine-readable.
One correction the kit makes explicitly. Several vendor write-ups claim the Breach Notification Rule moves to 72 hours. It does not. The 24-hour and 72-hour clocks in the proposal are contingency-activation notice and system restoration — different obligations entirely. File 04 §4 and the guide §6 say so in as many words, because getting this wrong sends a breach response down the wrong track.
Built on the proposal, and honest about it. Every threshold — the 15/30-day patching windows, one-hour termination, 24-hour notices, 72-hour restoration, six-month scans, the 240-day compliance period, the paragraph citations — is marked "verify final" in the files rather than presented as settled. The final-rule edition is free to everyone who has bought it, stated in the licence and the changelog, and re-download always serves the current edition.
Pairs with the HIPAA Readiness Accelerator for the wider 23-tab HIPAA programme, I've Been Breached for the incident itself, the TPRM Program Kit and Vendor Risk Operations Kit for running BA oversight as a vendor programme, and the Security Metrics & KPI Library for measuring it quarterly.
A practitioner's toolset, not legal advice. The BA certification in file 06 §3 is a document its signer is accountable for — never certify a safeguard the crosswalk records as a gap.
Also available in a bundle
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee