The Big HIPAA Security Update Got Delayed to 2027, But Your 2026 Risk Assessment Just Got Harder

You may have seen the news that the federal government pushed back a major update to HIPAA's security rules by a full year. The new target date is July 2027, instead of 2026. If you run a physician practice, medical group, or ACO and already feel buried in compliance work, an extra year probably sounds like great news.

Here's the catch. The delay only applies to the big new rule that hasn't been finalized yet. It doesn't change what you're already required to do, and if your practice or group reports MIPS Promoting Interoperability this year, the government actually just made your annual security risk assessment more important, not less.

Why This Update Was Proposed in the First Place

The rules that govern how healthcare organizations protect patient data were written in 2003 and last updated in 2013. A lot has changed since then. Nearly everything in healthcare now runs on computers and networks, and hackers have taken notice. Attacks on hospitals, clinics, and health systems have been climbing for years.

The clearest example is the 2024 ransomware attack on Change Healthcare, a company that processes billing and insurance claims for a huge share of the country. The breach affected roughly one in three patients nationwide, and it happened because hackers got in through a remote access system that didn't require a second form of login verification (something most people know as two-factor authentication). That incident became the poster child for why regulators think the current rules aren't strong enough anymore.

So in January 2025, federal regulators proposed a set of stricter requirements. Instead of treating things like encryption and two-factor login as "nice to have," the new rule would make them mandatory. It would also require regular security testing, more frequent scans for vulnerabilities, and a much more detailed yearly review of where patient data lives and how it moves through your systems.

Healthcare organizations pushed back hard. Regulators received nearly 5,000 public comments, many arguing the new rules would be too expensive and too fast to implement, especially for small and rural practices already running on thin margins. The government estimated the changes would cost the industry $9 billion in the first year alone. That pushback is likely why the deadline got pushed to 2027.

What Hasn't Changed, and What Actually Got Tougher

Even with the delay, you're still required to do a yearly security risk assessment under existing HIPAA rules. That requirement isn't new and it isn't going anywhere. Regulators are still actively enforcing it.

What did change is this: if your practice, group, or ACO reports MIPS Promoting Interoperability, the requirement for 2026 got stricter. In past years, you just had to say you'd done a security risk assessment. Now you have to confirm two things:

  • That you actually did (or reviewed) a security risk assessment covering every system you use for reporting, and

  • That you're fixing whatever problems that assessment found, or at least that you have a written plan to fix them this same year

If you can't honestly check both boxes, you don't just lose a few points. Your entire Promoting Interoperability score drops to zero, which can drag down your whole MIPS score even if everything else you reported was solid. For ACOs, this applies across every practice and provider group participating together.

Don't Waste the Extra Time

The bigger rule change is still coming. It's just been pushed back, not cancelled. Practices and groups that use this extra year to get ahead of it will be in much better shape when it finally lands, and they'll walk into this year's MIPS reporting with an assessment that can actually hold up to scrutiny.

That's where we come in. Chirpy Bird handles annual security risk assessments built to satisfy both your everyday HIPAA obligations and the tougher MIPS Promoting Interoperability requirements for 2026, including the follow-through plan regulators now expect. Whether you're a solo physician, a multi-provider group, or an ACO reporting across several practices, we handle the assessment, the paperwork, and the fix-it plan so your MIPS score and your compliance standing aren't left exposed while everyone waits on the next big rule.

Due for your annual risk assessment, or not sure if your current one covers the new 2026 requirements? Reach out to Chirpy Bird to get it scheduled before reporting season closes.

Previous
Previous

When PI Reweighting Helps, Hurts, or Simply Moves the Risk

Next
Next

OCR Is Watching: The Risk Analysis Initiative & What It Means for Your Practice