Where the proposed rule actually stands, what it would require, and which preparations are worth making before any of it becomes law
No. The HIPAA Security Rule update home health agencies have been hearing about since early 2025 is still a proposed rule, not law. HHS published it, the comment period closed, and no final rule has been issued. The Security Rule in force today is the same one that has governed ePHI, meaning electronic protected health information, for more than a decade, and federal regulators are actively enforcing it.
That distinction matters because agencies are being sold against it. Home health and home hospice operators across the San Francisco Bay Area are being told that encryption is now mandatory and that the addressable designation is gone. Neither is true, yet. What is true is that the direction of travel is clear, and most of what the proposal would require is work a covered agency benefits from either way.
This article covers where the proposal stands, what it would change, how much time agencies would get if it lands, and which preparations are worth making while the outcome is still open.
Is the HIPAA Security Rule update final for home health agencies?
The HIPAA Security Rule update is not final, for home health agencies or for anyone else. HHS published the proposed rule in the Federal Register on January 6, 2025, the public comment period closed on March 7, 2025, and the HHS Office for Civil Rights has not issued a final rule in the year and a half since. The current Security Rule remains in full effect and fully enforceable.
The timeline has moved more than once. OCR originally targeted May 2026 for final action. That date passed with nothing published. The Office of Management and Budget now lists July 2027 for final action on its Unified Agenda, and that entry is a planning projection rather than a legal deadline. Agendas slip, and this one already has. Four outcomes remain genuinely possible: the rule is finalized as written, narrowed, delayed again, or withdrawn.
What are the proposed HIPAA Security Rule MFA and encryption requirements?
The proposed HIPAA Security Rule would remove the addressable designation and make every implementation specification required, including ePHI encryption at rest and in transit and multi-factor authentication on systems that reach ePHI. Under the current rule, an agency can decline to implement an addressable control as written if it documents why an alternative is reasonable. Under the proposal, that flexibility disappears.
What the proposal would require of home health and home hospice agencies:
- Encryption of ePHI: required at rest and in transit, with limited exceptions, rather than addressable.
- Multi-factor authentication: required on systems that access ePHI, again with limited exceptions.
- A technology asset inventory: a documented list of every system and device that creates, receives, maintains, or transmits ePHI, kept current and paired with a network map.
- Defined testing schedules: vulnerability scanning at least every six months and penetration testing at least every twelve.
- Faster access termination: a former workforce member losing access to ePHI within one hour of the end of employment, with notification to certain parties within 24 hours when access is changed or terminated.
- Contingency timelines: written procedures to restore critical systems and data within 72 hours of a loss, plus 24-hour notice from a business associate that has activated its contingency plan.
- Stronger business associate oversight: written verification, certified by someone with authority at the vendor, that required safeguards are in place.
One correction is worth making, because the error circulates widely and some vendors repeat it. The 72-hour figure is a system and data restoration target, not a breach reporting deadline. Breach notification stays at 60 days under the Breach Notification Rule. Any provider telling a home health agency it will have 72 hours to report a breach has misread the proposal.
How long would a home health agency have to comply if the rule is finalized?
Roughly 240 days. If the rule is finalized as proposed, it would take effect 60 days after publication in the Federal Register, and compliance would be required 180 days after that. Business associates would get a short additional window. That is the full runway from the day the rule appears to the day it is enforceable against your agency.
Eight months sounds generous until you price the work. Encrypting ePHI across every platform, deploying MFA to field staff who document visits on their own phones, building and maintaining an asset inventory, standing up a scanning and testing schedule, and documenting all of it is a multi-quarter project for an agency with no internal IT department. Home health and hospice margins do not leave much room for an unplanned eight-month compliance sprint, which is the real argument against waiting for certainty.
Does a July 2027 target mean home health agencies can wait until 2027?
No. A July 2027 entry on the federal agenda says nothing about what OCR is enforcing today, and OCR is enforcing the current Security Rule aggressively. Its Risk Analysis Initiative had produced twelve enforcement actions as of early 2026, and OCR expanded the initiative this year to cover risk management as well, meaning acting on what an analysis finds rather than simply filing it.
Nearly every one of those settlements traces back to the same finding: no accurate, thorough, current risk analysis. That requirement is not new and is not proposed. It is in force now, it is the most commonly cited failure in HIPAA enforcement, and it is also the foundation the proposed rule builds on. An agency that does this work is not betting on a rulemaking outcome.
The financial backdrop is worth naming honestly. IBM’s Cost of a Data Breach Report 2026, released in July 2026, put the average healthcare breach at $6.64 million, the highest of any sector studied. That figure describes healthcare as a whole, and a 40-clinician home health agency will never see a loss at that scale. The more transferable number from the same report is 247 days, the average time across all industries to identify and contain a breach.
Consider how ePHI actually moves through a home health agency. A field clinician opens the EMR app on a personal phone between visits and pulls up a medication list from a client’s driveway. A scheduler covering forty or more shifts signs into Axxess or WellSky from a home laptop. Visit records move through a state-mandated EVV system. None of that sits behind an office network, and an account without a second factor is reachable from anywhere in the world. Against that, 247 days is a long time for nobody to notice.
“Most of the home health agencies we talk to are waiting for a final rule before they make major changes, which is understandable. That being said, nearly every first assessment we do turns up an issue that is already being enforced such as a system holding ePHI with no MFA on it. It is clear that the security rule is only going to get tighter and a great idea for home health providers to begin strengthening their compliance today.”
Brendan Duebner, President of IT Total Care
What does California already require of home health agencies and hospices?
California already imposes a reporting clock far shorter than the federal one. Under California Health and Safety Code Section 1280.15, licensed home health agencies and hospices must report unlawful or unauthorized access to, or use or disclosure of, a patient’s medical information to the California Department of Public Health and to the affected patient no later than 15 business days after detecting it. The federal Breach Notification Rule allows up to 60 days.
For a Bay Area agency, the state clock is the binding one, and it starts at detection rather than at confirmation. An agency that cannot quickly establish whether a lost phone held ePHI, or which accounts a departed caregiver still had open, will spend most of those 15 business days reconstructing the answer. The proposed federal rule would tighten timelines further, but home health and hospice agencies in California are already operating on the faster schedule, which is a good reason to build the detection and access records now rather than after a rulemaking concludes.
What should a home health agency do about the HIPAA Security Rule update now?
Focus on the preparations that are already required today and that the proposal would only formalize. Nine steps cover most of it: run a current risk analysis, turn on MFA, inventory the devices that reach ePHI, verify encryption, tighten access controls, sharpen incident response, confirm business associate agreements, document the program, and assign someone to watch the rule.
- Start with a current risk analysis. OCR is enforcing this today and the proposal builds on it. Map where ePHI actually lives across your EMR, whether that is Axxess, WellSky, or Homecare Homebase, along with EVV records, email, and file storage.
- Turn on MFA for every system that touches ePHI. That means EMR logins, Microsoft 365 or Google Workspace, and any remote access. It is low cost, available today, and already proposed to become mandatory. Our step-by-step MFA guide for home care agencies walks through the rollout without disrupting field staff.
- Inventory the devices that reach ePHI. Include field caregivers using an EMR app on personal phones between visits, and confirm each device has a screen lock and can be wiped remotely if it goes missing. Our guide to building a device inventory list covers what to capture and how to keep it current.
- Confirm ePHI encryption is enabled at rest and in transit. Most cloud EMR platforms and most Microsoft 365 and Google Workspace tiers support it, but it is not always switched on by default. Verify it across your core platforms rather than assuming the vendor handled it.
- Review who has access to ePHI and name a responsible party for permissions. Remove access promptly when a caregiver or scheduler leaves. The proposal would compress that to one hour after employment ends, which is only achievable if one named person owns the sequence.
- Tighten your incident response plan. The proposal sets a 72-hour window to restore critical systems and data and a 24-hour notification clock when a workforce member’s access changes, and California’s 15-business-day reporting requirement already applies. Detection speed drives all three.
- Keep a short, current list of your business associates and confirm agreements are in place. Billing companies, EMR vendors, answering services, and IT providers all handle ePHI on your behalf, and the proposal would add verification obligations on top of the agreements themselves.
- Document what you actually do. OCR expects a living, continuous risk management program, not a binder assembled once and shelved. Dated evidence that a control was reviewed is worth more than a polished policy nobody follows.
- Task someone on your team with monitoring the proposed rule. One person, checking quarterly, is enough to keep the agency from being surprised in either direction.
The sequencing matters as much as the list. Do not over-invest in requirements that may never take effect, and do not treat a delayed rule as permission to skip controls that are already enforceable.
What is the right posture while the rule is still proposed?
Treat the proposal as a preview, not a deadline. Build the controls that are already required and that would carry forward if the rule is finalized: risk analysis, MFA, a device inventory, disciplined access management, a tested incident response plan, and documentation that shows the program is alive. Every one of those helps support HIPAA compliance under the rule in force today, which is the only rule an auditor can cite this year.
Hold off on the spending that only makes sense if the proposal lands exactly as written. Scanning and penetration testing cadences, formal criticality analyses, and vendor certification workflows are worth planning for and not worth buying against a projection. If the rule is finalized, an agency that has done the first list will have a manageable gap to close. If it is narrowed or withdrawn, that agency is still in better shape than it was.
Ready to Prepare for the HIPAA Security Rule Update?
IT Total Care is a veteran-owned managed service provider based in Foster City, working with home health, home hospice, and home care agencies throughout the San Francisco Bay Area. Our home-based care IT support covers risk analysis, MFA deployment, device management, access and offboarding, and incident response planning, and we track the proposed rule so your team does not have to. Learn more about our approach to healthcare IT.
Contact Us to talk through where your agency stands.




