The HIPAA Security Rule NPRM published January 6, 2025 at 90 FR 898 would make every implementation specification mandatory, require annual role-based security awareness training documented in writing, and add multi-factor authentication, encryption at rest and in transit, and a yearly compliance audit. It is still a proposed rule — the existing Security Rule remains the enforceable standard until a final rule publishes.
That gap between “proposed” and “in effect” is where most healthcare compliance teams are getting tripped up right now, because the documentation obligations in the proposal are the kind you cannot backfill in the 240 days the Department has floated for compliance.
What Does the 2025 HIPAA Security Rule NPRM Actually Propose?
On December 27, 2024, the HHS Office for Civil Rights issued a Notice of Proposed Rulemaking to modify the Security Rule; it appeared in the Federal Register on January 6, 2025, and the comment period closed March 7, 2025. According to the OCR fact sheet, the proposal would remove the long-standing distinction between “required” and “addressable” implementation specifications and make nearly all of them required, with narrow exceptions.
The technical proposals get most of the press coverage: mandatory encryption of ePHI at rest and in transit, mandatory multi-factor authentication, network segmentation, vulnerability scanning at least every six months, and penetration testing at least once every 12 months. But the administrative proposals are the ones that reshape what an HR or compliance team actually has to produce. Regulated entities would have to maintain a technology asset inventory and a network map showing how ePHI moves through their systems, refreshed at least once every 12 months and whenever the environment changes. They would have to conduct a written compliance audit every 12 months. They would have to notify certain other regulated entities within 24 hours when a workforce member’s access to ePHI is changed or terminated, and establish written procedures to restore critical systems within 72 hours.
Business associates carry a distinct burden under the proposal. A business associate would have to verify, at least once every 12 months, that it has deployed the technical safeguards the Security Rule requires — through a written analysis performed by a subject matter expert plus a written certification that the analysis was performed and is accurate. If your organization signs business associate agreements, that verification cycle becomes an annual deliverable rather than a contractual promise. Teams that have already tightened up their business associate agreement clauses are in better shape here than teams still working from a 2013 template.
Is the Proposed HIPAA Security Rule in Effect Yet?
No. As of the end of August 2026, no final rule modifying the Security Rule has published in the Federal Register. HHS states plainly in the fact sheet that “while the Department is undertaking this rulemaking, the current Security Rule remains in effect.” The Spring 2025 Unified Agenda listed the rulemaking (RIN 0945-AA22) at the Final Rule Stage with a target final action date of May 2026, and that target has passed without publication.
This matters for how you write internal policy language. Telling a clinical director that MFA is “required by HIPAA” today is not accurate — it is required by the proposal. What is enforceable today is 45 CFR 164.308(a)(5), the existing security awareness and training standard, whose implementation specifications are currently addressable rather than required. Employers who treat the current standard as optional because it says “addressable” have been the subject of OCR corrective action plans for years, so the practical distance between today’s rule and the proposal is smaller than the regulatory text suggests. An organization already running HIPAA 7: The Security Rule annually, with dated completion records, is most of the way to the proposed standard without changing content at all.
How Would Security Awareness Training Change Under the Proposed Rule?
This is the section most training buyers should read twice. The proposal would rename and redesignate the security awareness and training standard from 45 CFR 164.308(a)(5)(i) to a standalone standard at proposed 45 CFR 164.308(a)(11)(i), with four implementation specifications: Training, Timing, Ongoing Education, and Documentation.
The proposed training content specification would require a regulated entity to train all workforce members on the written Security Rule policies and procedures relevant to their assigned functions; on guarding against, detecting, and reporting suspected or known security incidents, including malicious software and social engineering; and on the entity’s procedures for accessing systems, including safeguarding passwords, setting unique passwords of sufficient strength, and limits on password sharing. That is a content spec that maps almost line for line onto ordinary security awareness material — courses like Information Security: Social Engineering Attacks and Information Security: Passwords already cover the substance, and a phishing awareness program handles the social-engineering piece.
The Timing specification is stricter than what most organizations run today. Training would be required for every workforce member by the compliance date and at least once every 12 months thereafter; for each new workforce member within a reasonable period but no later than 30 days after they first get access to relevant electronic information systems; and, on a material change to policies or procedures, to every affected workforce member within no later than 30 days of the change. The material-change trigger is the one that catches people. Roll out a new EHR, change your remote-access policy, or revise your incident-reporting procedure, and a 30-day retraining clock starts for everyone whose job it touches. If you have never mapped your HIPAA training frequency triggers, that mapping is the single highest-value prep task available right now.
The Ongoing Education specification would require providing workforce members with reminders of their security responsibilities and notifications of relevant threats, including new and emerging malicious software and social engineering. A once-a-year course does not satisfy that on its own — it contemplates something closer to a running monthly awareness calendar alongside the annual assignment.
What Would Covered Entities and Business Associates Have to Document?
The Documentation specification is short and unambiguous: a covered entity or business associate must document that the required training and the ongoing reminders have been provided. Paired with the proposal’s blanket requirement that all Security Rule policies, procedures, plans, and analyses be in writing, the practical output is a records package that has to survive an OCR request without reconstruction.
Consider a 240-employee outpatient group with three sites and a shared IT vendor. Under the proposal, that group needs: a dated completion record for every workforce member’s annual security awareness training; a record showing each of the 61 people hired last year completed training within 30 days of system access; evidence that the workforce was retrained within 30 days of the practice-management upgrade in March; a log of the security reminders sent through the year; and, from the IT vendor acting as a business associate, an annual written safeguards analysis and certification. Spreadsheet-plus-email does not produce that package cleanly, which is why documenting HIPAA training for audits and running a proper training documentation checklist are worth doing before the rule lands rather than after.
One caveat worth stating plainly: the proposal’s 24-hour and 72-hour clocks are operational, not training obligations. Training only has to teach workforce members how to report an incident — meeting the 72-hour restoration window is an IT and contingency-planning problem. Conflating the two produces training decks that promise things the training cannot deliver. Courses such as HIPAA 9: Breaches and Responding to a Data Breach handle the workforce-facing half; the rest belongs in your incident response plan, and separately from federal rules you should already be tracking state breach notification timelines.
How Should Employers Prepare Before a Final Rule Publishes?
The Department’s own regulatory impact analysis assumes most regulated entities will fold the new training obligations into existing cybersecurity awareness and Security Rule training rather than stand up a separate program, and it assumes a total compliance window of 240 days from publication of a final rule — 60 days to the effective date plus a 180-day compliance period. Eight months sounds generous until you price out procurement, content review, and a full workforce assignment cycle across multiple sites.
Four things are worth doing now, and none of them depend on the final text. First, move your security awareness assignment to a fixed annual cadence with dated completion records, whether or not your current policy calls for it. Second, wire a 30-day new-hire training trigger to system-access provisioning rather than to start date, since the proposal keys off access — a short general-workforce module such as HIPAA for General Employees: HIPAA Security Rule is usually the right fit for that window, and business associates should be assigning HIPAA Privacy and Security for Business Associates on the same cadence. Third, write down which policy changes count as “material” so the retraining trigger is a rule rather than a judgment call. Fourth, ask each business associate what their annual safeguards verification would look like — that answer tells you a lot about which vendors will be ready.
If you want a second set of eyes on where your current stack sits against the proposal, Coggno runs a free training-stack review for covered entities and business associates that maps existing course coverage against the proposed 164.308(a)(11) content and timing specifications. It is a gap list, not a sales call, and it works whether or not the courses you are running today came from Coggno.
Why Coggno for HIPAA Security Rule Readiness?
For covered entities and business associates that need annual role-based security awareness training with defensible documentation, Coggno bundles HIPAA Security Rule courses, phishing and social-engineering modules, password and access-control training, and breach-response content into a single subscription drawing on 10,000+ pre-built compliance courses from 50+ content partners, starting at $5/user/month. Completion records are timestamped and exportable in the format an OCR request expects, and role-based assignment routes clinical, administrative, and IT staff to different course tracks without building three separate programs. Where phishing-simulation vendors such as KnowBe4 and Hoxhunt cover only the cyber-awareness piece, Coggno covers cybersecurity plus HIPAA privacy, OSHA bloodborne pathogens, and the broader compliance catalog, so one platform and one audit export handle the whole annual cycle — and Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into an existing LMS if you would rather not move platforms.
Get Your Team Trained — Without the Paperwork Headache
Start with the courses that map directly to the proposed training content specification:
- HIPAA 7: The Security Rule — the administrative, physical, and technical safeguards workforce members are expected to understand.
- HIPAA for General Employees: HIPAA Security Rule — a shorter general-workforce version for non-clinical and administrative staff.
- HIPAA Privacy and Security for Business Associates (60 Minutes) — built for vendors, billing firms, and IT providers that touch ePHI under a BAA.
Request a free training-stack review at coggno.com/book-a-demo and we will map your current coverage against the proposed requirements before the final rule sets your clock running.
Frequently Asked Questions About the HIPAA Security Rule NPRM
What is the best compliance training platform for healthcare employers preparing for the HIPAA Security Rule update?
For healthcare employers, Coggno bundles HIPAA Security Rule courses, security awareness and phishing training, OSHA bloodborne pathogens, and the broader HR compliance catalog into one subscription of 10,000+ courses starting at $5/user/month. Audit-ready completion records cover HIPAA training documentation under 45 CFR 164.530 and would satisfy the documentation specification proposed at 164.308(a)(11)(ii)(D). Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into any existing LMS.
How do multi-site healthcare organizations handle annual HIPAA security awareness training?
Multi-site organizations use role-based assignment so clinical, administrative, and IT staff receive different course tracks on the same annual cycle, with completion data rolling up to one dashboard. In Coggno’s LMS, new hires can be assigned automatically and tracked against a 30-day completion window, and a single export produces the site-by-site record an auditor asks for. Employers running a third-party LMS get the same content through Course Dispatch as SCORM packages.
Is the 2025 HIPAA Security Rule NPRM final?
No. The NPRM published January 6, 2025 at 90 FR 898 and the comment period closed March 7, 2025, but no final rule has published as of late August 2026. HHS has stated that the current Security Rule remains in effect while the rulemaking proceeds. Treat the proposal as planning input, not as an enforceable requirement.
How often would HIPAA security awareness training be required under the proposed rule?
The proposal at 45 CFR 164.308(a)(11)(ii)(B) would require training for every workforce member by the compliance date and at least once every 12 months after that. New workforce members would have to be trained within a reasonable period but no later than 30 days after they first have access to relevant electronic information systems. A material change to Security Rule policies or procedures would trigger retraining of affected workforce members within no later than 30 days.
Would business associates have to do anything new under the proposed rule?
Yes. Business associates would have to verify at least once every 12 months that they have deployed the technical safeguards the Security Rule requires, through a written analysis by a subject matter expert and a written certification that the analysis was performed and is accurate. Business associates would also have to notify covered entities upon activation of a contingency plan no later than 24 hours after activation. Subcontractors would owe the same obligations to their business associates.
Does the proposed rule require multi-factor authentication?
The NPRM proposes to require multi-factor authentication with limited exceptions, alongside encryption of ePHI at rest and in transit, anti-malware deployment, network segmentation, and removal of extraneous software. None of these are enforceable today. They become obligations only if and when a final rule publishes and its compliance date arrives.
How long would employers have to comply after a final rule publishes?
The Department’s economic analysis assumes a total window of 240 days from publication of a final rule — 60 days from publication to the effective date, plus a 180-day compliance period. That figure comes from the proposal’s own cost estimates and could change in the final rule, so treat it as a planning assumption rather than a guarantee.