WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Pro Bono
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
HHS-OCR Announces Proposed Modifications to the HIPAA Security Rule
Alerts
January 14, 2025

Overview

The U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR) has announced proposed modifications to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (the Proposed Rule). The Proposed Rule was published in the Federal Register for comment on January 6, 2025. It aims to strengthen the security and privacy of electronic protected health information (ePHI) in response to the evolving threat landscape and emerging technological challenges. If finalized as proposed, the Proposed Rule will have significant implications for healthcare organizations, their business associates, and other entities subject to HIPAA compliance requirements (the “regulated entities”). This alert represents the first in a multipart series outlining the most pertinent of the proposed rules and the potential implications for regulated entities.

Background

While the Security Rule has been a frequent subject of published enforcement actions and regulatory guidance by HHS-OCR, the Rule itself has not been revised since 2013. The Proposed Rule aims to preserve some of the flexibility and scalability embodied by the existing Rule, while also providing more prescriptive requirements that reflect and clarify HHS-OCR’s expectations regarding the appropriate level of security of ePHI.

The Security Rule generally requires regulated entities to implement reasonable technical, physical, and administrative safeguards intended to mitigate the potential impermissible use or disclosure of PHI. However, in order to allow for flexibility and scalability across different regulated entities, the current formulation of the rule distinguishes between “required” implementation specifications and “addressable” implementation specifications. The Proposed Rule would eliminate the distinction between “required” and “addressable” specifications, to reflect HHS-OCR’s view that all specifications are effectively required. The currently “addressable” items, which are the subject of the proposed revisions, include measures such as multifactor authentication, network segmentation, and penetration testing.

The Proposed Rule also includes considerable enhancements to existing documentation requirements, including requirements that covered entities establish procedures to restore the loss of PHI within 72 hours, more robust incident response plan requirements, and annual compliance audits. Similarly, the Proposed Rule would require greater cooperation and reporting from business associates on issues of cybersecurity, compliance, and incident response.

If promulgated as drafted, these heightened requirements would present a significant burden for regulated entities with tighter resource and bandwidth constraints but may result in considerable security improvements for regulated entities nationwide.

Key Takeaways for Regulated Entities

At this stage, the Proposed Rule is tentative and subject to further review and comment from the public and regulators. However, regulated entities would be well-served to note HHS-OCR’s position that—even for the existing Security Rule—“addressable” does not necessarily mean “optional,” and that many of the key controls that are currently noted as “addressable” are, in fact, effectively required for overall compliance.

Further, HHS-OCR’s commentary surrounding the Proposed Rule indicates that a number of collateral cybersecurity frameworks, although not specifically required by the existing Security Rule, were strongly influential on the new requirements reflected in the Proposed Rule. Regulated entities should consider whether alignment with one of these collateral frameworks may help to mitigate the risk of sanction from HHS-OCR in the present regulatory environment, as well as to ease the transition to newly required controls in whichever form they may take.

The Wilson Sonsini team is continuing to closely monitor developments associated with data protection and cybersecurity regulations, including HIPAA. If you have any questions or need assistance with compliance planning or incident response preparations, please do not hesitate to contact Tracy Shapiro, Haley Bavasi, Demian Ahn, Colin Black, or any other member of our data, privacy, and cybersecurity practice.

Contributors

  • Tracy Shapiro
  • Demian Ahn
  • Colin Black
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.