August 22, 2026

If you hold electronic protected health information (ePHI), treat the 2026 HIPAA Security Rule conversation as a planning input, not a finished statute. HHS OCR issued a proposed rule on December 27, 2024, and published it in the Federal Register on January 6, 2025. The current Security Rule remains in effect until a final rule says otherwise. This post is not legal advice. Watch HHS OCR for the final text.

The proposal is the first major Security Rule rewrite since 2013. The direction is consistent: fewer "addressable" outs, more operational proof. If you already use a managed security services provider, that is an evaluation problem, not a brochure problem.

What the proposal is trying to change

Data compliance and security infrastructure illustration

OCR's NPRM is a response to more frequent, larger health-care breaches. The department's own page cites a sharp rise in large-breach reports and in people affected, including the Change Healthcare incident. The proposed rule would tell covered entities and business associates, more specifically, what they must do to protect ePHI, and it would expect written policies that are reviewed, tested, and updated.

A buyer-facing one-sheet that tracks the expected 2026 changes summarizes the same shift in five lines you can put on an MSSP scorecard:

  1. Multi-factor authentication for systems that access ePHI.
  2. Network segmentation that isolates critical systems.
  3. A recovery objective you can demonstrate (the one-sheet uses 72 hours for critical systems after an incident).
  4. A current asset inventory and network map that matches real data flows.
  5. Evidence of operational enforcement, not only written policy.

Those five items are planning language. They are not a substitute for counsel, and they are not a claim that the NPRM has been finalized.

Why this belongs in an MSSP evaluation

Managed security services evaluation scorecard

A managed security services provider is judged by scope, telemetry, response authority, and evidence. That is the same test on How to Evaluate a Managed Security Services Provider (link to https://thedatapartner.com/managed-cybersecurity-provider-evaluation/). HIPAA does not change the test. It makes the evidence more specific.

Ask who owns MFA on every path to ePHI, including remote access and vendor tools. Ask where segmentation exists today and who can prove it after a change. Ask what restore time the provider will put in writing, and what they will show you in a tabletop. Ask for an asset and flow inventory that is dated, not a slide from last year's QBR. Ask for logs, tickets, and after-action notes, not a policy PDF.

If the provider cannot name those owners, they are selling a stack, not a service.

What not to do with a 240-day clock

If a final rule is published, many summaries use a 240-day path (60 days to effective, then 180 days to comply for most provisions). That clock is useful only after the Federal Register text is final. Do not re-paper your environment against a proposal and call it done. Do not accept an MSSP quote that says "HIPAA compliant" with no MFA, restore, or inventory evidence.

Use the clock, if it arrives, to sequence work you already needed: who authenticates, what is isolated, what can be restored, and what you can show an auditor.

A short worksheet

Secure network architecture with authentication and connected locations

Write these down before you take a demo:

  • Where ePHI actually lives (including backups and vendors).
  • Which access paths still lack MFA.
  • Which networks still share a flat path to clinical or claims systems.
  • Last successful restore of a critical system, with a date.
  • Who produces the asset map, and how often it is updated.

Bring that list to the MSSP evaluation scorecard (link to https://thedatapartner.com/managed-cybersecurity-provider-evaluation/). If healthcare data is in scope, those rows are not optional extras.

Sources