Video
September 16, 2025

HIPAA Security Rule Updates: What Healthcare Organizations Need to Know

No items found.
Image of a medical professional in a white lab coat typing on a laptop with a cybersecurity themed overlay on the image

Table of Contents

Share with network

Related Insights

How a healthcare organization scaled IT leadership through Office of the CIO servicesHow a healthcare organization scaled IT leadership through Office of the CIO services

How a healthcare organization scaled IT leadership through Office of the CIO services

Lorem ipsum dolor set

Your next CFO probably isn't looking for a jobYour next CFO probably isn't looking for a job

Your next CFO probably isn't looking for a job

Lorem ipsum dolor set

Replay: Responsible AI Starts Here: Governance & Controls in ActionReplay: Responsible AI Starts Here: Governance & Controls in Action

Replay: Responsible AI Starts Here: Governance & Controls in Action

Lorem ipsum dolor set

What a recent high-profile cybersecurity incident reveals about healthcare cyber riskWhat a recent high-profile cybersecurity incident reveals about healthcare cyber risk

What a recent high-profile cybersecurity incident reveals about healthcare cyber risk

Lorem ipsum dolor set

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Lorem ipsum dolor set

The Department of Health and Human Services is proposing the first major update to the HIPAA Security Rule since 2013. These changes are a direct response to the growing wave of cyber threats targeting healthcare organizations.

The proposal’s key changes include removing the previous distinction between “required’ and “addressable” safeguards, placing a heavier emphasis on documentation, and a focus on modernizing the expected technical safeguards.

While the updates are still in the proposal phase, organizations can prepare now by strengthening risk assessments, locking down technical safeguards, updating incident response plans, and investing in training. Learn more below.

The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.

contact our team

contact our team

contact our team.