Speaking Engagements
The 21st Century ROAD to Unlocking Community Bank Growth
September 17, 2026
Ashley Golden, a 2026 summer associate with Troutman Pepper Locke who is not admitted to practice law in any jurisdiction, also contributed to this article.
Since enacting HIPAA’s Privacy and Security Rules, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has seen repeated delays in finalizing proposed rule updates. The 2025 Security Rule is the latest example. This update is poised to create sweeping changes that would be materially time-consuming and costly for covered entities and business associates to implement, which is why all eyes have been on the status of its implementation. While delays may be more likely absent a binding deadline, the underlying causes reveal more about whether, when, and in what form a rule may be finalized.
Historically, HIPAA rule updates have been subject to delays due to external pressures, such as political drivers, enhanced cybersecurity threats, or simply poor timing. The first major update to HIPAA came after the HITECH Act passed in 2009, directing HHS to implement significant amendments. OCR published the proposed rule in July 2010, but only finalized it in the January 2013 HIPAA Omnibus Rule.[1] Although the final rule publication was delayed, the HITECH Act updates were finalized under a single president’s administration, unlike the current scenario for the present proposed Security Rule update.
The next largest proposed Privacy Rule modification, the 2021 Coordinated Care update, was created at the end of President Donald Trump’s first administration and lay dormant throughout President Joe Biden’s term.[2] However, since the commencement of Trump’s second administration, the proposed rule has shown meaningful signs of revival with its submission to the Office of Information and Regulatory Affairs (OIRA)[3] and the OCR’s tribal consultation, both occurring in 2026.[4]
Conversely, the 2024 Reproductive Health Care updates to the Privacy Rule were finalized in just one year, serving as an outlier driven by political factors following Dobbs v. Jackson Women’s Health Organization.[5] Nevertheless, a Texas federal court vacated most of the final rule in June 2025,[6] illustrating that timely finalization does not guarantee survival.
The proposed 2025 Security Rule update represents a substantive revision with widespread backlash and critique. Published 14 days before Trump’s second term began,[7] the incoming administration inherited a freshly proposed and harshly criticized rule it did not create, raising speculation about cross-administration delays.
The proposed rule generated nearly 5,000 comments by March 2025. The original May 2026 finalization target has since passed, with a new projected goal for finalization set for July 2027.[8]
While numerous factors impact finalization of the Security Rule update, the tension between mounting pressure for stronger and more modern cybersecurity standards and widespread opposition to the onerous compliance burden is at the forefront.
The Change Healthcare breach in 2024, the largest health care data breach in U.S. history, renewed urgency to address the gaps that the proposed Security Rule update purports to target. Notwithstanding such pressure, industry opposition has been broad and organized. A coalition of 100 health care organizations wrote to Secretary Robert F. Kennedy in December 2025 urging full withdrawal of the proposed rule, citing inconsistencies with the administration’s deregulatory priorities.[9] This level of organized pushback against an already cross-administration proposed rule suggests that revision or prolonged delay would be more likely than finalization in its current form.
Another key consideration is whether the Security Rule update will be finalized independently or consolidated with the pending Privacy Rule update, resembling the 2013 Omnibus Rule. While the Privacy Rule’s 2026 OIRA submission has renewed consolidation speculation, the updated Security Rule’s July 2027 finalization date may signal a stronger likelihood of independent finalization. Whether an omnibus approach would accelerate finalization or result in further delay is uncertain but raises the possibility that both updates could ultimately come to fruition.
Ultimately, the future of the Security Rule update is uncertain. Nevertheless, we present the following scenarios in the order we view as the most likely to least likely:
The Troutman Pepper Locke team is ready to assist with your HIPAA, privacy, cybersecurity, and compliance needs. We will keep you up to date on any updates surrounding the proposed Security Rule. Please contact Brent Hoard at brent.hoard@troutman.com or Emma Trivax at emma.trivax@troutman.com for more information.
[1] Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules, 78 Fed. Reg. 5566 (Jan. 25, 2013) (codified at 45 C.F.R. pts. 160, 164).
[2] Modifications to the HIPAA Privacy Rule to Support and Remove Barriers to Coordinated Care and Individual Engagement, 86 Fed. Reg. 6446 (proposed Jan. 21, 2021) (to be codified at 45 C.F.R. pts. 160, 164).
[3] HIPAA Privacy Rule: Changes to Support Coordinated Care and Individual Engagement and Reduce Regulatory Burdens Pending EO 12866 Regulatory Review, Off. of Info. & Regul. Affs. (Apr. 2, 2026), https://www.reginfo.gov/public/do/eoDetails?rrid=1334515.
[4] Tribal Consultation on Proposed Modifications to the HIPAA Privacy Rule, 91 Fed. Reg. 1481 (Jan. 14, 2026).
[5] HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy: Fact Sheet, U.S. Department of Health and Human Services (July 1, 2025), https://www.hhs.gov/hipaa/for-professionals/special-topics/reproductive-health/final-rule-fact-sheet/index.html.
[6] Id.
[7] HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, 90 Fed. Reg. 898 (proposed Jan. 6, 2025) (to be codified at 45 C.F.R. pts. 160, 164).
[8] HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, Off. of Info. & Regul. Affs. (July 2026), https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22.
[9] Letter from 100 Healthcare Organizations to Robert F. Kennedy, Sec’y, Dep’t of Health & Hum Servs. (Dec. 8, 2025).
This just in
Speaking Engagements
The 21st Century ROAD to Unlocking Community Bank Growth
September 17, 2026
Sponsored Events
Women in Public Finance 30th Annual Conference
September 16 – 18, 2026
Sheraton Grand Chicago Riverwalk
301 E North Water St, Chicago, IL 60611
Sponsored Events
Philly BioBreak Reception Fall 2026
September 15, 2026 | 5:30 PM – 8:00 PM ET
Lobby of 2300 Market Street
2300 Market Street, Philadelphia, PA 19103
Speaking Engagements
Healthcare Securities Class Actions, SEC Enforcement & Emerging Capital Markets Risks
September 2, 2026