← All field notes
HIPAA · 7 minute read

By Securelay Research

Current rule and proposed update are not the same thing.

HHS continues to identify the existing HIPAA Security Rule as the rule currently in effect. Its proposed cybersecurity update is important, but it remains a proposed rule. A credible healthcare security plan meets today’s obligations, monitors the rulemaking, and never presents a proposal as final law.

Comparison of the HIPAA Security Rule currently in effect and the proposed cybersecurity update.
Original Securelay editorial comparison based on HHS Office for Civil Rights material reviewed 19 March 2026.
Primary source HHS — HIPAA Security Rule currently in effectPrimary source HHS — Summary of the HIPAA Security Rule

Anchor the program in the rule in force

The current Security Rule sets national standards for electronic protected health information held or transmitted by covered entities and business associates. HHS describes administrative, physical, and technical safeguards for confidentiality, integrity, and availability. Its current summary emphasizes accurate risk analysis, risk management, assigned security responsibility, access management, and periodic evaluation.

Track the proposal without converting it into a promise

HHS issued the proposed update in December 2024 to strengthen cybersecurity protections. Proposed controls can inform forward-looking design, but procurement material, policies, and customer statements should label them as proposed until the rulemaking produces a final rule. Maintain a requirements register that records source, status, owner, implementation evidence, and review date.

Treat connected AI as another ePHI path

If an AI assistant, retrieval pipeline, or support workflow handles ePHI, map where that information is created, received, maintained, and transmitted. Minimize unnecessary fields, authorize access for the specific role and purpose, retain useful security events without copying ePHI into logs, and test what happens when a provider or policy dependency fails.

Keep the product boundary exact

On integrated routes, Securelay can de-identify configured sensitive values before configured AI connections, enforce configured access decisions, and record value-free evidence. It does not make an organization HIPAA compliant, replace a risk analysis, control unintegrated routes, or substitute for legal and clinical governance.

Put the control on the data path.Discuss an architecture review