This week marks 30 years since President Bill Clinton signed the Health Insurance Portability and Accountability Act (HIPAA) into law on August 21, 1996. Health care has changed dramatically since then:
- Patient records, once paper documents, are now created, maintained and sent electronically;
- Threat actors now launch sophisticated attacks on health care entities of all sizes, hoping to extract ransom payments for the return of health information; and
- Patients now wear devices that monitor a range of health metrics and transmit that data directly to their care team.
The HIPAA regulations have evolved over the past three decades and, as described below, more changes are expected.
The First 30 Years
HIPAA was originally designed to help workers keep health coverage when they changed or lost jobs (the “portability”) and to crack down on health care fraud and abuse (the “accountability”). Congress authorized the U.S. Department of Health and Human Services (HHS) to standardize electronic health care transactions. Health care providers and patients are most familiar with the HIPAA regulations issued by the HHS, Office for Civil Rights (OCR) under that authority, including the:
- Privacy Rule: Issued in 2000; compliance required by 2003
- Security Rule: Issued in 2003; compliance required by 2005
In 2009, Congress made significant changes to HIPAA through the HITECH Act, which was implemented via the subsequent Breach Notification Rule in 2009 and the Omnibus Rule in 2013.
In 2020, Congress required HHS to update parts of the Privacy Rule and 42 CFR Part 2 through the CARES Act, which was implemented through the February 2024 Final Rule aligning 42 C.F.R. Part 2 with HIPAA — with full compliance required by February 16, 2026.
What is Next
In the Fall 2026 Unified Agenda, HHS updated the content and timeframes for several proposed and potential changes to the HIPAA regulations. While Unified Agenda timeframes are estimates (not binding compliance deadlines), the next year could include several major changes to the HIPAA regulations, including:
- Privacy Rule: Instead of issuing one Final Rule based on its 2021 Proposed Changes to the HIPAA Privacy Rule To Support, and Remove Barriers to, Coordinated Care and Individual Engagement, OCR now expects to issue:
- HIPAA Privacy Rule: Changes to Support Coordinated Care and Individual Engagement and Reduce Regulatory Burden: Due to be released in August 2026, this Final Rule is expected to modify the Privacy Rule to improve information sharing for care coordination and case management for individuals; facilitate greater family and caregiver involvement in the care of individuals experiencing emergencies or health crises; enhance flexibilities for disclosures in emergency or threatening circumstances; and reduce administrative burdens on HIPAA covered entities.
- HIPAA Privacy Rule to Promote Individuals’ Timely Access to their Protected Health Information: Due to be released in November 2026, this Proposed Rule will solicit comments related to modifying the amount of time covered entities have to respond to requests for protected health information made pursuant to the right of access.
- Security Rule: Originally scheduled for release in May 2026, OCR pushed out amendment of the Security Rule to its Long-Term Actions agenda and identified July 2027 as the anticipated timeframe for a Final Rule based on the HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information.
For more information, please contact:
Want to know more?
