The HIPAA Security Rule update home health agencies keep hearing about has generated more confusion than almost any regulatory item in recent years, largely because it is being described as settled when it is not. Below are the questions Bay Area home health and home hospice agencies ask most often about what was proposed, where it stands, and what is actually enforceable right now.
1. Is the HIPAA Security Rule update final?
No. The HIPAA Security Rule update is not final. HHS published it as a proposed rule in January 2025, and no final rule has been issued since. The Security Rule in force today is unchanged and remains fully enforceable for home health and home hospice agencies.
That distinction is the source of most of the confusion. A proposed rule signals where regulators intend to go. It creates no new obligation until it is finalized and its compliance date arrives.
2. When was the HIPAA Security Rule update proposed, and when could it be finalized?
HHS published the proposal in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025. Federal regulators originally targeted May 2026 for final action and let that date pass without publishing. The Office of Management and Budget now lists July 2027.
Agenda dates are planning projections rather than legal deadlines, and this one has already moved once. Four outcomes remain possible: the rule is finalized as written, narrowed, delayed again, or withdrawn. More than 100 hospital and provider organizations have formally asked HHS to withdraw or scale it back.
3. What would the proposed HIPAA Security Rule update change for home health agencies?
The central change is the removal of the addressable designation. Under the current rule, an agency can decline to implement certain safeguards exactly as written if it documents a reasonable alternative. The proposal would make every implementation specification required. The main provisions include:
- Encryption of ePHI required at rest and in transit, with limited exceptions
- Multi-factor authentication required on systems that access ePHI
- A documented technology asset inventory covering everything that touches ePHI, paired with a network map
- Vulnerability scanning at least every six months and penetration testing at least every twelve
- Access for a departing workforce member ending within one hour of termination
- Written procedures to restore critical systems and data within 72 hours of a loss
- Written verification from business associates, certified by someone with authority, that safeguards are in place
For a fuller walkthrough of each provision and what it would take to satisfy, see our guide to preparing for the HIPAA Security Rule update.
4. Does the proposed HIPAA Security Rule update apply to home care agencies?
Generally no. HIPAA applies to covered entities, and home health and home hospice agencies qualify because they bill for medical services and handle ePHI. Agencies providing non-medical personal care are generally not covered entities, so neither the current Security Rule nor the proposed update applies to them directly.
There are specific paths that change that answer. A home care agency can become a business associate through a contract with a covered entity, or can take on covered entity status through a particular service line or billing arrangement. Outside those paths, client information, payer data, and contractual privacy terms still create real exposure. The governing authority is simply different.
5. How long would a home health agency have to comply if the rule is finalized?
Roughly 240 days. As proposed, the rule would take effect 60 days after publication in the Federal Register, with compliance required 180 days after that. Business associates would get a short additional window for existing contracts.
Eight months is a compressed schedule for an agency with no internal IT staff. Encryption verification across every platform, an MFA rollout to field clinicians, an asset inventory built from nothing, and a scanning and testing cadence are each multi-week projects, and they would run concurrently with delivering care.
6. Does the proposal require home health agencies to report a breach within 72 hours?
No. The 72-hour figure in the proposal is a target for restoring critical systems and data after a loss, not a breach reporting deadline. Breach notification remains at 60 days under the Breach Notification Rule, and the proposal does not change it.
The proposal does introduce two separate 24-hour clocks: notice from a business associate that has activated its contingency plan, and notice when a workforce member’s ePHI access is changed or terminated. The 72-hour reporting claim circulates widely in vendor marketing. An agency hearing it should treat it as a signal to check the rest of what that vendor is saying.
7. Do California home health agencies and hospices face a faster breach reporting deadline?
Yes. Under California Health and Safety Code Section 1280.15, a licensed home health agency or hospice must report unlawful or unauthorized access to a patient’s medical information to the California Department of Public Health and to the affected patient within 15 business days of detecting it. The federal rule allows up to 60 days.
For Bay Area agencies, the state requirement is the binding one, and it runs from detection rather than from confirmation. An agency that cannot quickly determine what a compromised account could reach will spend most of that window establishing the facts rather than reporting them.
8. What is being enforced today while the HIPAA Security Rule update is still proposed?
The current Security Rule, and actively. The HHS Office for Civil Rights has brought twelve enforcement actions under its Risk Analysis Initiative as of early 2026, and expanded the initiative this year to cover risk management as well, meaning acting on what an analysis finds rather than only producing one. Nearly every action turned on the same finding: no accurate, thorough, current risk analysis.
That requirement predates the proposal by two decades. Consider a director of nursing reviewing compliance documentation from a home network on a Sunday evening, signed into Axxess, KanTime, or MatrixCare with a password and nothing else. Nothing in that picture depends on a rulemaking outcome, and every part of it is already in scope. The IBM Cost of a Data Breach Report 2026 put the average healthcare breach at $6.64 million across the industry, and the average time to identify and contain a breach at 247 days.
9. What should a home health agency do before the HIPAA Security Rule update is final?
Concentrate on the safeguards that are already required today and that the proposal would only formalize. That work is not a bet on a regulatory outcome, because it carries forward whether the rule is finalized, narrowed, or withdrawn. The short list:
- Run a current risk analysis and map where ePHI actually lives across your EMR, EVV records, email, and file storage
- Turn on multi-factor authentication for every system that reaches ePHI, using our practical MFA rollout guide as a sequence
- Build a device list covering personal phones as well as agency hardware, following our device inventory walkthrough
- Verify encryption is switched on at rest and in transit across your core platforms rather than assuming the vendor handled it
- Name a responsible party for permissions, and close access when a caregiver or scheduler leaves
- Write and test an incident response plan sized against California’s 15-business-day reporting requirement
- Document the program with dated evidence that controls were reviewed, not a policy binder nobody opens
10. How can an IT partner help a home health agency prepare for the HIPAA Security Rule update?
An IT partner turns a moving regulatory target into a maintained program. In practice that means running the risk analysis and keeping it current, deploying and enforcing MFA without disrupting a caregiver’s first visit of the day, enrolling devices in Intune, JumpCloud, or Apple Business Manager so a lost phone is recoverable, managing access and offboarding, testing incident response, and tracking the proposal so nobody inside the agency has to.
The tracking piece matters more than it sounds. The most common result of the confusion around this rule is an agency that either spent early against requirements that may change or skipped controls that are enforceable now. Working with a provider offering home-based care IT support across the San Francisco Bay Area means that judgment call is made by someone reading the rulemaking rather than the marketing.
“The question we get most is whether an agency has to do something about this rule in 2026, The answer is typically that they already had to. Everyone asks about the proposed rule. Almost nobody asks about the one they have been under since 2005. That gap is exactly where the enforcement actions tend to come from.”
Brendan Duebner, President of IT Total Care
Need Help Making Sense of the HIPAA Security Rule Update?
IT Total Care works with home health, home hospice, and home care agencies throughout the San Francisco Bay Area, from San Mateo County through the South Bay. We help agencies separate what the proposal might require from what is enforceable today, and build a security program that covers both. Learn more about our approach to healthcare IT, or read where the HIPAA Security Rule update actually stands for the full picture.
Contact Us to talk through what your agency needs.




