In February 2026, OCR settled with an Illinois substance abuse treatment center for $103,000 after a phishing breach exposed the records of 1,980 patients. The clinic had never conducted a security risk analysis. Six days later, OCR launched civil enforcement of 42 CFR Part 2, the federal regulation governing substance use disorder (SUD) patient records. The message was clear: enforcement is not waiting for the Security Rule overhaul.
And that overhaul just got pushed back. HHS moved the HIPAA Security Rule final action to its Long-Term Actions agenda in the Fall 2026 Unified Agenda, projecting July 2027 for finalization. The original target was May 2026.
That delay does not mean you have time to wait. Several major HIPAA regulatory changes are already in effect, and the Security Rule requirements, once finalized, will demand compliance within 240 days of publication.
Here is what is live now, what is coming, and what your practice should be doing today.
HIPAA Regulatory Changes: What Is in Effect vs. What Is Coming
Privacy Rule: 42 CFR Part 2 SUD Records Are Now Under HIPAA
The 42 CFR Part 2 final rule took effect April 16, 2024, with a compliance deadline of February 16, 2026. That deadline has passed. If your organization treats patients with substance use disorders, you are already required to comply.
The changes are significant. SUD patient records, historically governed by stricter confidentiality rules than the rest of HIPAA, are now aligned with the HIPAA Privacy Rule for treatment, payment, and health care operations (TPO). Specifically:
- Single consent: Patients sign one consent covering all future uses and disclosures for TPO. The old requirement of separate consent for each disclosure is gone.
- Breach notification: The HIPAA Breach Notification Rule now applies to SUD records. Breaches must be reported to HHS and affected individuals.
- OCR enforcement: The Office for Civil Rights, not SAMHSA, now handles Part 2 complaints and enforcement. Penalties range from $141 to $2.1 million per violation category.
- Notice of Privacy Practices: Your NPP must be updated to address SUD record protections, permitted disclosures, and the limitations on use in legal proceedings.
If your practice handles SUD treatment records and has not updated its consent forms, NPP, and breach procedures, you are already out of compliance. OCR’s Part 2 enforcement settlement at Top of the World Ranch makes the risk concrete.
Security Rule Final Action: Delayed to Mid-July 2027
The proposed HIPAA Security Rule overhaul (RIN 0945-AA22) is the first major update to the Security Rule since 2013. HHS published the Notice of Proposed Rulemaking on January 6, 2025. The 60-day comment period closed March 7, 2025, drawing nearly 5,000 comments, many from healthcare organizations arguing the requirements were too costly and too prescriptive.
HHS originally targeted May 2026 for final action. That date has slipped to July 2027. Once published, covered entities and business associates will have 240 days to comply, putting the likely compliance deadline around March 2028.
The proposed requirements include:
- Multi-factor authentication (MFA) mandatory for all access to electronic protected health information (ePHI). No exceptions, no alternatives. Password-only access to any system containing ePHI becomes a violation. Our MFA implementation guide walks through exactly how to set this up.
- Encryption required at rest and in transit. The “addressable” designation that allowed organizations to document alternatives is eliminated. Every implementation specification becomes required.
- Vulnerability scanning at least every six months, using automated tools to identify weaknesses across systems that store or transmit ePHI. This is a new explicit requirement under the proposed rule.
- Penetration testing annually. Organizations must conduct or contract for penetration testing to simulate real-world attacks against their systems. Results must be documented and remediated.
- Technology asset inventory and network mapping required and kept current. You must know every device, system, and connection that touches ePHI.
- Security incident response and contingency plans tested annually, with specific recovery time requirements.
The full breakdown of all seven major changes is in our Security Rule changes deep dive.
What the Delay Means (and Does Not Mean)
The delay to July 2027 does not change the direction of travel. The NPRM is published. The comment period is closed. HHS is reviewing feedback and will likely adjust some requirements, but the core framework, mandatory MFA, required encryption, regular vulnerability testing, is not going away.
It does give organizations more preparation time. Use it.
What Your Practice Should Do Right Now
You do not need to wait for the Security Rule to finalize. Every requirement in the proposed rule reflects cybersecurity best practices that OCR already expects under the existing Security Rule’s general standards. Organizations that have been fined in recent enforcement actions were not lacking compliance with proposed future rules. They were failing current ones.
Immediately (if not done):
- Conduct a security risk analysis under 45 CFR 164.308(a)(1). This is already required and is the number one reason practices get fined. Our risk assessment guide covers the process.
- Enable MFA on every system that accesses ePHI. Start with email and your EHR. Use an authenticator app, not SMS.
- Update your Notice of Privacy Practices to address 42 CFR Part 2 if you handle SUD records.
Within 90 days:
- Run a vulnerability scan across your network. Automated vulnerability scanners like Nessus, Qualys, or OpenVAS will identify exposed services, unpatched software, and misconfigured systems.
- Inventory every device and system that stores or transmits electronic protected health information. You cannot protect what you have not mapped.
- Review your incident response plan. If you do not have one, build one. If it has not been tested, test it.
Before the final rule publishes:
- Budget for penetration testing. Annual pen tests will be required. Get quotes now so the cost is not a surprise.
- Encrypt everything. If any ePHI is stored unencrypted or transmitted without TLS, fix it before the compliance deadline removes any flexibility.
Frequently Asked Questions
Is the HIPAA Security Rule update canceled? No. HHS moved the final action to its Long-Term Actions agenda with a projected date of July 2027. The rulemaking is still active.
Do I need to comply with 42 CFR Part 2 changes now? Yes. The compliance deadline was February 16, 2026. If your organization handles substance use disorder treatment records, you must already have updated consent forms, breach notification procedures, and your Notice of Privacy Practices.
What is the difference between vulnerability scanning and penetration testing? Vulnerability scanning uses automated tools to identify known weaknesses in systems and software. Penetration testing goes further: a security professional actively attempts to exploit vulnerabilities to determine what an attacker could actually access. The proposed Security Rule requires both.
Will the final Security Rule be different from the proposed rule? Likely yes. HHS received nearly 5,000 comments, many raising concerns about cost and implementation burden. The final rule may adjust timelines, provide exceptions for small entities, or modify specific technical requirements. The core mandates for MFA, encryption, and vulnerability testing are expected to remain.
How much will compliance cost a small practice? Costs vary significantly by practice size and current security posture. MFA is essentially free (Microsoft Authenticator, Google Authenticator). Vulnerability scanning tools range from free (OpenVAS) to a few hundred dollars per year. Penetration testing typically costs $3,000 to $15,000 annually for a small practice.
Sources
- HHS Fact Sheet: 42 CFR Part 2 Final Rule
- HIPAA Security Rule NPRM, Federal Register (January 6, 2025)
- HHS HIPAA Security Rule Overview
- HHS 42 CFR Part 2 Enforcement
- HHS HIPAA Regulatory Initiatives
- OCR Top of the World Ranch Settlement (February 2026)
- HIPAA Security Rule Delay to July 2027, Clark Hill Analysis
Related Reading
- New HIPAA Security Rule 2026: 7 Major Changes and Your Compliance Deadline
- OCR Fined a Substance Abuse Clinic $103K: Why 42 CFR Part 2 Enforcement Matters Now
- HIPAA MFA Requirement 2026: A Plain-English Guide for Small Practices
- What Is ePHI Under HIPAA?
- HIPAA Encryption Requirements 2026
This content is for educational and informational purposes only and should not be construed as legal advice. Organizations should consult legal counsel for guidance specific to their compliance obligations under HIPAA and 42 CFR Part 2.
One Guy Consulting offers affordable HIPAA compliance packages for practices of all sizes. Learn more