HIPAA Final Rule Updates: Security, Part 2, and Enforcement

Recent HIPAA final rule updates cluster into three tracks with very different statuses: the 2024 reproductive health privacy rule was vacated nationwide in June 2025 and is no longer in effect; the proposed overhaul of the HIPAA Security Rule, published in January 2025, remains under review and has not been finalized; and the alignment of 42 CFR Part 2 substance use disorder records with HIPAA reached its compliance deadline on February 16, 2026, and is now being actively enforced by the HHS Office for Civil Rights.

Reproductive Health Privacy Rule Is No Longer In Effect

HHS published the “HIPAA Privacy Rule to Support Reproductive Health Care Privacy” on April 26, 2024, in response to concerns after Dobbs v. Jackson Women’s Health Organization that medical records could be used to investigate people for lawful reproductive care.1Federal Register. HIPAA Privacy Rule To Support Reproductive Health Care Privacy It barred covered entities and business associates from using or disclosing PHI to investigate or impose liability on anyone for seeking, obtaining, providing, or facilitating reproductive health care that was lawful under the circumstances in which it was provided. It also added an attestation requirement for certain PHI requests and required updates to Notices of Privacy Practices.2HHS.gov. Final Rule Fact Sheet: HIPAA Privacy Rule To Support Reproductive Health Care Privacy

On June 18, 2025, Judge Matthew Kacsmaryk of the U.S. District Court for the Northern District of Texas vacated the rule nationwide in Purl v. United States Department of Health and Human Services. The court found that HHS had exceeded its statutory authority, including by limiting state authority over public health investigations and child abuse reporting in a way HIPAA does not permit.3Groom Law Group. Texas Judge Vacates HIPAA Reproductive Health Care Rule4HK Law. HIPAA’s Reproductive Health Rule Is Vacated Nationally The Trump administration, which took office in January 2025, did not defend the rule on the merits and instead challenged only standing and the scope of relief.5Georgetown Law. Purl’s HIPAA Ruling Rolls Back Essential Reproductive Privacy Protections Nationwide The Fifth Circuit dismissed the appeal on September 10, 2025, leaving the vacatur intact.6American Health Law Association. Appeals Closed: HIPAA Reproductive Health Care Privacy

The practical effect: the prohibition on reproductive health disclosures, the attestation requirement, and the related privacy notice updates are all gone. Organizations that had already updated policies, trained staff, revised business associate agreements, and modified their Notices of Privacy Practices had to reverse those changes and return to the pre-rule framework.7Quarles & Brady. HIPAA Reproductive Health Rule Vacated Nationally Entities that had already distributed updated notices were advised to send corrected versions within 60 days of the material change.8Stinson LLP. Federal Court Strikes Down HIPAA Reproductive Health Privacy Rule The court did preserve, by severing them, the provisions requiring notice updates tied to substance use disorder records, since those came from a separate rulemaking.3Groom Law Group. Texas Judge Vacates HIPAA Reproductive Health Care Rule

One boundary worth flagging: the vacatur removed federal HIPAA protections specific to reproductive health, but state privacy laws still apply. Some states, including California, have their own restrictions on disclosing abortion-related information.8Stinson LLP. Federal Court Strikes Down HIPAA Reproductive Health Privacy Rule

The Proposed Security Rule Overhaul Is Still In Review

On January 6, 2025, HHS published “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” the most significant proposed update to the Security Rule since 2013.9Federal Register. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information The proposal would replace the current flexible framework with a prescriptive one by eliminating the distinction between “required” and “addressable” implementation specifications and making nearly all safeguards mandatory.10HHS.gov. HIPAA Security Rule NPRM Fact Sheet

What Would Change

If finalized as proposed, regulated entities would face a much longer list of concrete obligations:

  • Mandatory encryption of electronic PHI at rest and in transit, with limited exceptions.
  • Multi-factor authentication for access to systems containing ePHI, with limited exceptions.
  • An ongoing technology asset inventory and a network map showing how ePHI moves through the organization, updated at least annually.
  • Vulnerability scans at least every six months and penetration testing at least every twelve months.
  • More detailed written risk analyses identifying all reasonably anticipated threats and vulnerabilities.
  • Procedures capable of restoring systems and data within 72 hours of an incident.
  • Internal compliance audits at least every 12 months.
  • Annual written verification from business associates that they have deployed the required technical safeguards.10HHS.gov. HIPAA Security Rule NPRM Fact Sheet

Industry Response and Current Status

The public comment period closed March 7, 2025, and drew 4,747 comments.9Federal Register. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information11CHIME. CHIME Comments to HHS on Proposed HIPAA Security Rule12Compliancy Group. Proposed HIPAA Security Rule Update

Cost is central to the objections. HHS’s own regulatory impact analysis put first-year compliance costs at roughly $9 billion, with recurring costs of about $6 billion in years two through five, and industry commenters argued those figures were still too low.11CHIME. CHIME Comments to HHS on Proposed HIPAA Security Rule The National Rural Health Association called mandatory encryption, MFA, and continuous documentation “cost-prohibitive” for small and rural facilities and asked HHS to extend the compliance window to at least three years, rather than the 180 days proposed.13National Rural Health Association. NRHA Comments on HIPAA Security Rule NPRM

OCR’s Spring 2025 Unified Agenda listed a May 2026 finalization target, but OCR Director Paula M. Stannard confirmed at HIMSS 2026 that comment review is still ongoing. If finalized as proposed, regulated entities would have 240 days from publication to comply: 60 days until the rule takes effect and 180 days after that to reach compliance.12Compliancy Group. Proposed HIPAA Security Rule Update14Alston & Bird. HIPAA Security Rule Overhaul Whether the final rule will be scaled back is still unresolved.

Substance Use Disorder Records Are Now Aligned With HIPAA

Separately, HHS finalized a rule on February 16, 2024, aligning the confidentiality regulations for substance use disorder patient records under 42 CFR Part 2 with the HIPAA Privacy Rule and the HITECH Act, as required by Section 3221 of the CARES Act.15HHS.gov. Fact Sheet: 42 CFR Part 2 Final Rule The main changes:

  • Patients can now give a single consent covering future uses and disclosures for treatment, payment, and health care operations, rather than a separate consent for each disclosure.
  • A new category of “SUD counseling notes,” analogous to psychotherapy notes under HIPAA, requires separate consent.
  • Part 2’s older criminal penalty structure is replaced with HIPAA’s civil and criminal enforcement framework.
  • Part 2 records are now subject to the HIPAA Breach Notification Rule.
  • Part 2 records still cannot be used in legal proceedings against a patient without specific consent or a court order, preserving a protection that goes beyond standard HIPAA.15HHS.gov. Fact Sheet: 42 CFR Part 2 Final Rule

The rule took effect April 16, 2024, with a compliance deadline of February 16, 2026.16American Psychiatric Association. 42 CFR Part 217HHS.gov. Part 2 Information18HIPAA Journal. February 16, 2026 Compliance Deadline: Part 2 Final Rule

What OCR Is Actually Enforcing

OCR’s enforcement work in 2025 and early 2026 has concentrated on cybersecurity failures, particularly ransomware, hacking, and inadequate risk analysis. The agency’s “Risk Analysis Initiative” targets entities that failed to conduct adequate security risk assessments. Recent actions include a $1.5 million civil money penalty against Warby Parker tied to credential-stuffing breaches affecting nearly 198,000 individuals between 2018 and 2022, an $800,000 settlement with BayCare Health System over access controls that let a former employee view medical records, and a $3 million settlement with Solara Medical Supplies over a phishing attack.19HHS.gov. Penalty Against Warby Parker20Nixon Peabody. 2025 HIPAA Enforcement Tally Rises Following Three New Settlements21HHS.gov. Enforcement Highlights

OCR has also restarted HIPAA compliance audits for the first time since 2017. The third audit phase, announced in March 2025, is examining 50 covered entities and business associates with a focus on Security Rule risk analysis and risk management. Results have not been published.22HHS.gov. HIPAA Audit Program

The 2021 Patient Access Proposal Remains Pending

One other HIPAA rulemaking is worth knowing about because it has been sitting unresolved for years. A proposed modification to the Privacy Rule published in January 2021 would shorten the maximum time to provide patients access to their records from 30 days to 15 days, require covered entities to post fee schedules online, and let patients inspect their records in person and take notes or photographs.23Federal Register. Proposed Modifications to the HIPAA Privacy Rule To Support and Remove Barriers to Coordinated Care The proposal drew over 1,400 comments and has never been finalized or formally withdrawn. A Tribal Consultation meeting was scheduled for February 2026, suggesting the current administration may still be weighing it.24HIPAA Journal. HIPAA Updates and Changes