DEV Community

Tahir Almas
Tahir Almas

Posted on Originally published at ictfax.org

Your Vendor Says the HIPAA Security Rule Overhaul Is Final. The Register Says Otherwise

Originally published at ictfax.org

Search for the HIPAA Security Rule overhaul this week and you will be told it is final, that it took effect in March 2026, that it finalises in May, and that you have 240 days to comply. I checked the Federal Register on 4 October 2026. It is still a proposed rule. There is no final action, no effective date and no clock running.

We covered the agenda slip back in July, when final action moved out to 2027 and the rule was reclassified into long-term actions. What is new is that two months on, the deadline claims have not gone away. They have multiplied.

What the record actually holds

There is exactly one document. It is titled HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information. Its type is Proposed Rule. It was published on 6 January 2025 at 90 FR 898, under RIN 0945-AA22, and the comment period closed on 7 March 2025.

Note the citation, because a surprising number of write-ups give it as 90 FR 800. That is the wrong page, and it is a useful tell. A citation that gets copied wrong across a dozen sites usually means nobody in that chain opened the document.

No final rule has been published. The proposal has now sat for more than eighteen months since comments closed.

The two-minute check

You do not have to take my word for any of this, and you should not have to take a vendor's either. The Federal Register has a free API and it answers this question directly.

Query the documents endpoint for the rule title, ask for the type and citation fields, and read what comes back. If the type says Proposed Rule, there is no deadline. If a final rule existed it would be there, with an effective date attached, because that is what publication means.

I would make this a habit rather than a one-off. Any time somebody sells you a compliance date, the primary record is one request away, and the gap between what circulates and what is filed is wider than most people expect.

Why I am not telling you to relax

Here is where I would push back on my own headline. The deadline is fiction. The controls are not.

Almost everything in that proposal is either already required under the Security Rule as it stands, or is the sort of thing OCR has been citing in settlements for years. Encryption, unique user identification, asset inventory, audit logging. None of that is waiting on a final rule, and a fax server that fails on those today fails on them whatever happens in 2027.

The one I would start with is storage. TLS and SRTP protect the hop, and teams tend to stop there because the transport is the part the product page talks about. The TIFF or PDF left sitting in a spool directory afterwards is the artefact that turns up in breach reports, and encryption at rest is addressable under 164.312(a)(2)(iv) today.

Unique user identification under 164.312(a)(2)(i) is required right now, not proposed. Shared logins on a fax queue remain the single most common thing OCR finds when it looks at a document system, and it is the cheapest finding to avoid.

Then the inventory, which is less glamorous and more useful than it sounds: every place a fax comes to rest. Spool directories, archive shares, the mail gateway, the multifunction printer nobody has logged into since 2019. The asset inventory the proposal would mandate is the same list a risk analysis has always needed, and most teams discover at least one copy they had forgotten.

The practical point about planning

If a 2026 date is in your remediation plan, take it out. Not because the work is wrong, but because a fake deadline makes the work fragile. When the date passes and nothing happens, the budget conversation gets harder, and the next real deadline gets less attention than it deserves.

Plan the controls on their own merit. They survive the rule being finalised, delayed again, or rewritten.

FAQ

Is the HIPAA Security Rule overhaul dead?

No. It is a live proposal that has not been finalised. Being moved to long-term actions signals that nobody expects it soon, not that it has been withdrawn.

So nothing changed since January 2025?

Not in the Federal Register. The proposal published, comments closed in March 2025, and the regulatory agenda later pushed final action back. No final rule has appeared.

Does the existing Security Rule already require encryption?

It is addressable rather than required, which means you implement it or document why an equivalent alternative is reasonable. In practice, for stored PHI on a fax server, I have never seen a convincing version of that documentation.

What is 90 FR 898?

Volume 90 of the Federal Register, page 898. It is the citation for the proposed rule published on 6 January 2025. If a source gives you 90 FR 800, that source did not check.

Should we wait for the final rule before changing anything?

No, and that is the one piece of advice I would give without hedging. Waiting means your risk analysis is out of date for another two years while the controls you need are already enforceable.

How do I check rulemaking status myself?

Use the Federal Register documents API, search the rule title, and read the type and citation fields. It is public, free and needs no account.

Verified against the Federal Register documents API on 4 October 2026. Document number 2024-30983, RIN 0945-AA22, published 6 January 2025 at 90 FR 898, type Proposed Rule, comments closed 7 March 2025.

Top comments (0)