Aug 18 / Dianne Pledgie

Happy Birthday, HIPAA! Big Changes to Privacy and Security Rules Expected

This week marks 30 years since President Bill Clinton signed the Health Insurance Portability and Accountability Act (HIPAA) into law on August 21, 1996. Health care has changed dramatically since then:

  • Patient records, once paper documents, are now created, maintained and sent electronically;
  • Threat actors now launch sophisticated attacks on health care entities of all sizes, hoping to extract ransom payments for the return of health information; and
  • Patients now wear devices that monitor a range of health metrics and transmit that data directly to their care team.

The HIPAA regulations have evolved over the past three decades and, as described below, more changes are expected.

The First 30 Years

HIPAA was originally designed to help workers keep health coverage when they changed or lost jobs (the “portability”) and to crack down on health care fraud and abuse (the “accountability”). Congress authorized the U.S. Department of Health and Human Services (HHS) to standardize electronic health care transactions. Health care providers and patients are most familiar with the HIPAA regulations issued by the HHS, Office for Civil Rights (OCR) under that authority, including the:

  • Privacy Rule: Issued in 2000; compliance required by 2003
  • Security Rule: Issued in 2003; compliance required by 2005

In 2009, Congress made significant changes to HIPAA through the HITECH Act, which was implemented via the subsequent Breach Notification Rule in 2009 and the Omnibus Rule in 2013.

In 2020, Congress required HHS to update parts of the Privacy Rule and 42 CFR Part 2 through the CARES Act, which was implemented through the February 2024 Final Rule aligning 42 C.F.R. Part 2 with HIPAA — with full compliance required by February 16, 2026.

What is Next

In the Fall 2026 Unified Agenda, HHS updated the content and timeframes for several proposed and potential changes to the HIPAA regulations. While Unified Agenda timeframes are estimates (not binding compliance deadlines), the next year could include several major changes to the HIPAA regulations, including:


Join us for two timely Powers Knowledge trainings covering this topic and other legal developments impacting your organization. In September, join us for Powers Wednesday, a complimentary webinar open to all who register. in October, attend our Cyber Scaries for 2026 webinar discussion the risks that are shaping the 2026 cybersecurity landscape. See below for more information.

For more information, please contact:

Dianne Pledgie
Principal
dianne.pledgie@powerslaw.com

Want to know more?

Below are upcoming trainings you may find helpful. Visit our Catalogue page for a full list.