
Are you ready for modifications to HIPAA? We can help.
Where Should We Send Your Cheat Sheet?
Enter your details and we will email it to you!
Welcome to the most active regulatory environment we have ever seen! As the Office for Civil Rights (OCR) works to rapidly update HIPAA and other privacy and security regulations, as well as increase enforcement, it has become more important than ever to keep up with changing regulations! At HIPAAtrek, our compliance experts track these changes, so you don’t have to.

HIPAA changes are inevitable as the world—and especially the storage and sharing of Protected Health Information (PHI)—changes. Privacy and security regulations may be updated for a number of reasons, including keeping up with changing technology, strengthening enforcement standards, and clarifying specific civil rights.
The adoption of telehealth, the use of smartphones in clinical settings, and the digital transmission of ePHI all impact regulations. As technology changes and Healthcare is the number one industry targeted by cyberattacks, regulations must adapt to protect patient data from new and growing threats.
Additionally, the OCR works to clarify and expand patient rights and PHI protections on an ongoing basis. The Proposed Modifications to the HIPAA Privacy Rule, for instance, are designed to strengthen individuals’ rights to access their own health information. Similarly, the Information Blocking regulation was created under the 21st Century Cures Act to protect the flow of information between patients and providers.

HIPAA changes may also be created in response to the political environment in some states or across the United States. The Reproductive Health NPRM of 2023, which would impact the HIPAA Privacy Rule, is one such example.
Finally, individual states or the OCR may change or create new regulations to clarify or strengthen enforcement standards, giving additional authority to healthcare privacy and security regulations.

The largest change to HIPAA we have ever seen, over 30% of HIPAA will change under this NPRM, impacting BAAs, Policies, and NPPs.
Final action anticipated August 2026.

Advances interoperability through expanded uses of certified APIs for prior authorization, care management, and care coordination.
Final action anticipated August 2026.

Aims to enhance national cybersecurity by mandating reporting of specific cyber incidents and ransom payments from HIPAA covered entities.
Final action anticipated September 2026.

Supports the right of access by addressing the amount of time that covered entities have to respond to requests for PHI.
NPRM anticipated November 2026.

The first ever change to the Security Rule, proposes modifications to improve cybersecurity in healthcare, with strengthened requirements for safeguarding EPHI under HIPAA.
Final action anticipated July 2027.
Learn More About Security Rule Changes ⟶
Based on our conversations with the OCR, many of the provisions of this regulation are effectively being enforced under regulatory discretion. We recommend complying with the best practices outlined in this rule.

Implements the Electronic Health Record Reporting Program, requirements for IT Certification under the ONC, and enhancements for information sharing.
Effective March 11, 2024.

Advances interoperability through standards adoption; public health IT certification; expanded uses of certified APIs; and information sharing under the Information Blocking regulations.
Effective January 15, 2025.

A further amendment to the Information Blocking regulations to revise exceptions and establish a new exception to Information Blocking (Protecting Care Access Exception).
Effective December 17, 2024.

Advances interoperability, as defined by the Public Health Service Act and impacting Information Blocking regulations.
Effective October 1, 2025.

A new provision of the Cures Act outlining disincentives for providers committing Information Blocking, effectively beginning the enforcement of Information Blocking.
Effective July 31, 2024.

With an expanded definition of a lawful holder, the regulations previously impacting only substance use providers will now encompass most healthcare organizations.
Effective February 16, 2026.

Strengthens privacy protections for reproductive health information, ensuring it cannot be used to investigate or penalize those seeking, obtaining, or providing reproductive health care.
Compliance Date December 23, 2024.
This regulation was largely overturned by a federal district court in Texas in June 2025. However, you may still need to comply with state regulations specific to reproductive health records.
HIPAAtrek was built by HIPAA compliance experts who have been in your shoes, so we know how challenging sweeping changes to HIPAA can be.

That’s why we work diligently to support our clients through changing regulations with:
HIPAAtrek includes a personalized roadmap to upcoming regulatory changes as a part of our Privacy Gap Assessment and Security Risk Analysis. Learn more.

Know where your privacy program stands, so you can build on a strong foundation once the changes are finalized.

Understand the specifics of these changes, and begin preparations by identifying policies and BAAs that will require updates.

Create buy-in among the C-suite, sharing your action plan and budget proactively.
Learn more on our blog:
We made you a free cheat sheet to guide your compliance as regulations change.


The best way to ensure your organization’s compliance in this quickly changing regulatory environment is to begin with an understanding of your current HIPAA compliance. Our Security Risk Analyses and Privacy Gap Assessments specifically include a personalized roadmap to changing regulations, so you can build from a strong foundation, even as regulations change.
In consultation with your team, our in-house compliance experts will:
Ready to learn more? Fill out this form and a member of our team will follow up with more details.