Blog
HIPAA Security Rule delay: Why modernizing identity security can’t wait
For the past year, healthcare Chief Information Security Officers (CISOs), compliance leaders, and IT directors have been bracing for the first major overhaul of the HIPAA Security Rule in over a decade. Driven by the Office for Civil Rights (OCR) and the Department of Health and Human Services (HHS), these proposed updates aim to modernize healthcare cybersecurity standards in response to devastating ransomware attacks and evolving data privacy threats.
However, recent developments indicate that the finalization of the HIPAA Security Rule updates has been postponed, with a finalized update now extending toward 2027.
For some organizations, this delay might feel like welcome breathing room to reallocate budgets or temporarily pause compliance readiness initiatives. But for forward-thinking healthcare security leaders, this regulatory pause is not a signal to slow down. The vulnerabilities that prompted the HHS to draft these updates have not disappeared—and if your organization is waiting for a finalized mandate to modernize your access controls, you are inherently accepting unnecessary risk.
Here is why achieving continuous identity security must be your foundational priority today, regardless of when the regulatory ink dries.
Threats are outpacing traditional identity security maturity
Most healthcare organizations already have foundational identity controls in place—such as basic access management, Single Sign-On (SSO), or manual provisioning workflows. But as the threat landscape accelerates, relying on these point-in-time capabilities is no longer enough. Compliance is a trailing indicator of security; regulations like the HIPAA Security Rule are historically designed to establish a baseline floor for data protection, not the ceiling.
The OCR’s push for updated security standards was heavily influenced by systemic vulnerabilities across the healthcare supply chain that bypass traditional network defenses. When a threat actor breaches a healthcare network today, they rarely hack their way in through zero-day exploits. Instead, they log in using stolen or compromised credentials that provide dangerously excessive, over-provisioned access.
Clinical environments are inherently dynamic. Clinicians frequently shift departments or hold concurrent roles, while non-employee populations like travel nurses and affiliated physicians often reside outside your primary HR systems entirely. Relying on manual IT workflows to piece together these disconnected data sources inevitably leads to dangerous access creep and over-provisioning. To secure patient data without slowing down care, healthcare organizations must automate identity lifecycles—integrating directly with healthcare-specific authoritative sources, like EHRs, to ensure access is instantly right-sized the moment a clinician's status changes.
The AI wildcard: A massive new cohort of identities
The urgency to modernize your identity security is compounded by the rapid integration of artificial intelligence in healthcare. The clinical workspace is shifting from software operated purely by humans to autonomous workflows driven by AI—introducing a massive new cohort of non-human identities that require strict, real-time governance.
Healthcare organizations are increasingly deploying agentic AI—autonomous AI agents capable of executing complex workflows, like ingesting a patient's historical EHR data, cross-referencing lab results, and routing summaries to specialists. To perform these tasks, these AI agents rely on service accounts and machine identities. Unlike human workers, these identities never sleep, they interact with systems at machine speed, and they often hold highly privileged access to sensitive ePHI databases.
If an AI agent’s service account is compromised, the blast radius is catastrophic. Yet, in many healthcare organizations, these non-human identities are grossly under-governed, provisioned with standing privileges, and rarely subjected to rigorous access certifications.
Assess your readiness for the future of healthcare identity
While the exact final text and timeline of the HIPAA Security Rule updates remain in flux, the directional mandate from HHS is clear: healthcare organizations must exert tighter, continuous control over who—and what—accesses electronic protected health information.
Preparing for these changes does not require waiting for a finalized mandate from OCR and HHS. It requires a proactive assessment of your current identity security posture. Do you have continuous visibility into what data your AI agents can access? Can you dynamically revoke access the moment a user's context changes?
Ready to secure your clinical environment for the AI era?
The regulatory landscape is shifting, and threat actors aren't waiting for compliance deadlines. Uncover your hidden vulnerabilities and evaluate how your current identity program stacks up against impending mandates.