HIPAA Security Rule NPRM: What Medical Billing Companies Should Prepare for
Prepare your healthcare billing services for the proposed HIPAA Security Rule NPRM. Learn key technical safeguards, MFA rules, and compliance steps.

Healthcare billing services evaluating federal regulatory changes must prepare for the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Notice of Proposed Rulemaking (NPRM) regarding the HIPAA Security Rule. Published on January 6, 2025, this proposal marks the first major structural overhaul of federal health data security standards since the 2013 Omnibus Rule. The federal regulatory agenda sets July 2027 as the target for final rule action, followed by an estimated 180 to 240 day compliance window.
The NPRM proposes eliminating "addressable" implementation specifications, transforming safeguards like Multi-Factor Authentication (MFA) and data encryption into mandatory requirements for all covered entities and Business Associates. With OCR reporting a record 772 large data breaches (500+ records) in 2025 and annual statutory penalty caps standing at $2,190,294 per violation category in 2026, billing organizations must begin gap assessments now without treating unfinalized proposals as current law.
Key Takeaways
- The HHS OCR Security Rule NPRM proposes the most extensive cybersecurity changes since 2013.
- The target date for final rule action is July 2027, followed by a 180 to 240 day implementation window.
- All "addressable" specifications become mandatory, eliminating documentation workarounds for MFA and encryption.
- Business Associates face direct compliance liability, with annual penalty caps at $2,190,294 per violation category.
- Existing HIPAA Security Rule provisions remain fully enforceable while the proposed rule undergoes administrative review.
What the HIPAA Security Rule NPRM involves in 2026
The Notice of Proposed Rulemaking (NPRM) for the HIPAA Security Rule updates federal technical, administrative, and physical safeguard requirements governing electronic Protected Health Information (ePHI). For medical practices and third-party RCM vendors operating healthcare billing services, the proposed rule establishes standardized cybersecurity baselines regardless of company size.
Historically, organizations utilized "addressable" specifications to document why certain security measures, such as full-disk encryption or hardware-based authentication, were not reasonable for their operating environment. The proposed rule removes this flexibility, establishing universal technical mandates across all systems processing claims, remits, and eligibility data.
CURRENT RULE VS. PROPOSED NPRM MATRIX
Feature | Existing Security Rule | Proposed NPRM Standard |
|---|---|---|
Specification Type<br>MFA Requirement<br>Data Encryption<br>Vulnerability Scan<br>Pen Testing | Required & Addressable<br>Addressable / Best Practice<br>Addressable (at rest/transit)<br>Periodic<br>Discretionary | Universal Mandatory<br>Mandatory across all ePHI<br>Mandatory (at rest/transit)<br>Mandatory every 6 months<br>Mandatory annual requirement |
While the proposed rule remains under regulatory review, existing enforcement active under current law targets organizations failing to maintain documented risk analyses. Practices managing specialized service lines, including behavioral health billing, must ensure transient claim files remain encrypted across clearinghouse connections.
Regulatory timeline and federal agenda targets through 2027
Understanding the administrative rulemaking timeline prevents billing executives from panicking over unfinalized proposals or delaying necessary infrastructure upgrades.
The administrative timeline for the proposed rule includes:
- NPRM Publication: Released in the Federal Register on January 6, 2025, establishing an initial public comment period.
- Federal Target Action: Listed on the Unified Agenda for potential final action in July 2027 following extensive stakeholder feedback.
- Implementation Grace Period: Anticipated 180 to 240 day compliance window following publication of the Final Rule before OCR begins active enforcement.
- Current Enforcement Baseline: Existing Security Rule requirements remain 100% active and enforceable today.
[REGULATORY TIMELINE FLOW]
Jan 6, 2025: NPRM Published in Federal Register
│
▼
July 2027: Target Final Action on Federal Agenda
│
▼
180–240 Days: Compliance Grace Period Post-Publication
│
▼
2028: Mandatory OCR Enforcement of Final StandardsNavigating federal rulemaking timelines requires ongoing operational balance. You should strengthen core technical controls today based on active OCR settlements while tracking the final text before over-committing to unfinalized administrative directives.
Core structural shift: Elimination of addressable safeguards
The single most significant conceptual change in the NPRM is the elimination of "addressable" implementation specifications. Under current HIPAA Security Rule framework (45 CFR § 164.312), an organization faced with an addressable specification can perform one of three actions:
- Implement the specification as written.
- Implement an equivalent alternative measure that achieves the same security goal.
- Document why the specification is unreasonable and decline implementation.
The proposed rule eliminates options two and three for key technical controls. OCR rationale stems from breach data showing that threat actors exploit documented addressable gaps, particularly unencrypted databases and single-factor remote access portals.
ADDRESSABLE VS. MANDATORY TRANSITION LIST
Safeguard Specification | Current Status | Proposed NPRM Status |
|---|---|---|
Encryption in Transit (SSL/TLS<br>Encryption at Rest (AES-256)<br>Multi-Factor Authentication<br>Hardware Asset Inventory | Addressable<br>Addressable<br>Addressable<br>Addressable | Universal Mandatory<br>Universal Mandatory<br>Universal Mandatory<br>Universal Mandatory |
For medical billing companies managing cloud servers, EHR interfaces, and local billing terminals, converting addressable guidelines into mandatory rules requires re-architecting data pipelines to ensure zero unencrypted ePHI exists on local endpoints.

Mandatory technical controls: MFA, encryption, and log audits
The proposed NPRM outlines explicit technical parameters that billing organizations must maintain across every platform processing patient financial or clinical data.
Four mandatory technical controls form the backbone of the proposed standard:
[MANDATORY TECHNICAL CONTROLS]
├── 1. Multi-Factor Authentication (MFA)
│ └── Enforced for all remote and local user sessions accessing ePHI
├── 2. End-to-End Encryption
│ └── AES-256 at rest; TLS 1.3 in transit across all claim networks
├── 3. Bi-Annual Vulnerability Scans
│ └── Automated internal/external vulnerability checks every 6 months
└── 4. Centralized Audit Logging
└── Immutable 12-month log retention for all user access eventsMulti-Factor Authentication must protect all entry points, including billing staff logging into local practice management software, clearinghouse portals, and secure FTP servers. Single-factor passwords, even when rotated every 90 days, fail proposed compliance thresholds.
Encryption standards require AES-256 bit encryption for database volumes storing ePHI and TLS 1.3 protocol for all transmitted EDI 837 claims and EDI 835 ERA files.
Centralized audit logging mandates that billing systems record user logons, claim modifications, patient record exports, and permission changes, preserving immutable log files for at least 12 months.
Impact on Business Associate Agreements and RCM vendor liability
Medical billing companies operate as Business Associates (BAs) under HIPAA rules. The proposed NPRM expands direct legal liability for BAs, establishing that third-party vendors are independently responsible for technical control failures even if the covered entity medical practice failed to specify those controls in the Business Associate Agreement (BAA).
Recent OCR enforcement highlights this shift. In 2025, OCR reached formal resolution agreements with multiple Business Associates following ransomware events, citing failure to conduct accurate risk assessments.
BUSINESS ASSOCIATE COMPLIANCE RESPONSIBILITIES
Operational Area | Required Business Associate Control |
|---|---|
Subcontractor Oversight<br>Incident Response<br>Risk Analysis<br>Offshoring Safeguards | Enforce identical MFA/encryption on sub-capita<br>Formal 72-hour internal breach detection window<br>Annual documented risk assessment across all ePHI<br>Encryption verification for remote offshore staff |
If your billing company utilizes offshore sub-contractors or remote data entry specialists, the proposed rule mandates strict endpoint monitoring and session recording to prevent unauthorized ePHI downloads.
Organizations considering whether to maintain in-house billing infrastructure or partner with enterprise RCM vendors can evaluate structural operational trade-offs in our guide on outsourcing medical billing.
State-level data privacy overlays: New York, Florida, and Pennsylvania
Federal HIPAA Security Rule regulations establish a national baseline, but state-level data privacy statutes add strict compliance overlays for regional healthcare billing services.
Practices operating across the Mid-Atlantic and Southern regions must navigate state-specific security requirements:
STATE-LEVEL DATA PRIVACY OVERLAYS
State | Key Privacy Statute | Specific Security Mandate |
|---|---|---|
New York<br>Florida<br>Pennsylvania | NY SHIELD Act<br>FIPA (FL Stat § 501.171)<br>Breach of Info Act | Mandatory administrative/tech controls<br>30-day breach notice to Department<br>Notice required for compromised ePHI |
In New York, the Stop Hacks and Improve Electronic Data Security (SHIELD) Act mandates that any business holding private information of NY residents maintain reasonable administrative, technical, and physical safeguards. Billing operations utilizing medical billing in New York face state attorney general enforcement in addition to federal OCR scrutiny.
In Florida, the Florida Information Protection Act (FIPA) requires notice to affected individuals within 45 days and notice to the Florida Department of Legal Affairs within 30 days of breach discovery. Billing networks managing medical billing in Florida must align incident response timelines with both state and federal triggers.
In Pennsylvania, updated breach notification rules require notifying affected residents without unreasonable delay when unencrypted ePHI is accessed by unauthorized users. Regional billing centers serving medical billing in Pennsylvania must maintain verified encryption records to qualify for safe harbor protections under state law.
OCR enforcement trends and 2026 penalty structures
HHS OCR enforcement data demonstrates an active focus on risk analysis failures, unauthorized ePHI access, and delayed breach notifications.
Key OCR statistics highlight enforcement priorities:
- Record Breach Volume: OCR recorded 772 large data breaches involving 500+ records in 2025, breaking prior annual records by count.
- Catastrophic Impact: In 2024, 725 large breaches compromised over 192 million healthcare records, largely driven by major clearinghouse disruptions.
- Annual Penalty Caps: As adjusted for inflation in 2026, the annual statutory penalty cap reaches $2,190,294 per violation category for non-compliance.
HIPAA CIVIL MONETARY PENALTY TIERS (2026)
Culpability Tier | Per Violation Penalty | Annual Cap Per Category |
|---|---|---|
Tier 1: Did Not Know<br>Tier 2: Reasonable Cause<br>Tier 3: Willful Neglect (Corrected)<br>Tier 4: Willful Neglect (Uncorrected) | 71,162<br>71,162<br>71,162<br>$71,162 min | 2,190,294<br>2,190,294 |
Failing to perform an enterprise-wide risk analysis is the most frequent finding in OCR resolution agreements. Regulators view an outdated or non-existent risk assessment as evidence of reasonable cause or willful neglect.
To mitigate compliance exposure and prevent cash flow disruptions from billing errors, review our operational analysis on preventing claim denials.

Step-by-step preparation checklist for billing companies
Preparing for proposed Security Rule changes while remaining fully compliant with current law requires a phased implementation strategy. Billing company executives should execute a four-phase readiness plan:
[4-PHASE PREPARATION ROADMAP]
Phase 1: Gap Assessment & Risk Analysis (Months 1–2)
├── Inventory all hardware, software, and ePHI repositories
└── Audit current MFA coverage across all remote and local portals
Phase 2: Technical Control Hardening (Months 3–4)
├── Enforce AES-256 encryption across all stored databases
└── Upgrade clearinghouse EDI connections to TLS 1.3 protocol
Phase 3: Policy & BAA Modernization (Months 5–6)
├── Update Business Associate Agreements with explicit BA liability
└── Establish 6-month automated vulnerability scanning schedule
Phase 4: Workforce Training & Simulation (Ongoing)
└── Conduct semi-annual phishing simulations and log audit reviewsPhase 1: Enterprise ePHI Inventory
Map every digital asset that creates, receives, maintains, or transmits ePHI. Include local workstations, billing servers, cloud databases, clearinghouse connections, and backup drives.
Phase 2: MFA Enforcement
Roll out Multi-Factor Authentication to 100% of user accounts. Replace SMS-based verification codes with hardware security keys or authenticator apps to prevent SIM-swapping vulnerabilities.
Phase 3: Encryption Verification
Perform technical validation confirming that ePHI is encrypted at rest using AES-256 bit encryption and in transit using TLS 1.3. Secure backup files with unique encryption keys.
Phase 4: Bi-Annual Vulnerability Scans
Contract with third-party cybersecurity specialists or utilize automated tools to conduct internal and external vulnerability scans every six months, maintaining audit logs of remediation actions.
When to audit your healthcare billing services infrastructure
Managing technical safeguards, threat monitoring, and regulatory tracking demands specialized technical resources. Medical practices and smaller billing operations often find that internal IT teams lack dedicated healthcare compliance bandwidth.
A comprehensive revenue cycle and compliance audit identifies technical security vulnerabilities, billing workflow bottlenecks, and documentation gaps before they attract regulatory penalties.
IN-HOUSE VS. ENTERPRISE BILLING AUDITS
Audit Parameter | In-House IT Review | Specialized RCM Partner |
|---|---|---|
Technical Risk Assessment<br>EDI Security Scrubbing<br>HIPAA BA Liability<br>AR Days Optimization | Self-reported checklist<br>Basic gateway check<br>Practice bears risk<br>45+ days average | Independent gap audit<br>TLS 1.3 & EDI 837 validation<br>Shared risk & compliance<br>Under 30 days target |
If your organization faces expanding billing volume, complex multi-state regulations, or technical security questions, an external infrastructure review provides actionable clarity. Conduct a comprehensive medical billing audit or request a free audit with MD Revenue Group to protect your practice revenue and ensure complete compliance readiness.
