This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

2026 HIPAA Security Rule Changes: What HHS Says They Cost

The proposed 2026 Security Rule update would be the most significant HIPAA change in over a decade. HHS priced it in the proposal's own regulatory impact analysis, and that analysis is the only source for what the rule would cost. This page reports what HHS put against each provision, and is equally explicit about the provisions HHS declined to price at all.

Rule status: proposed, not final

This rule is still a proposal. The comment period closed on 7 March 2025 and no final rule had been published as at July 2026. HHS's Unified Agenda moved the rule to Long-Term Actions and now projects final action in July 2027, having previously projected May 2026. There is no compliance obligation and no compliance date, because there is no final rule. Nothing on this page is in force. Source: 90 FR 898, 6 January 2025, RIN 0945-AA22, the proposed rule as published on the Federal Register. The regulatory impact analysis is Section V, pages 992 to 1007.

HHS's own estimates

First year, national

$9 billion

$9,314,106,174 exactly

Years 2-5, per year

$6 billion

Undiscounted recurring cost

Regulated entities

1,822,600

822,600 CE + 1,000,000 BA

Per entity, annualized

$1,235

The only per-entity figure

That $1,235 is the entire per-entity story, and it is flat. HHS derives it from its annualized cost of $2.3 billion divided by 1,822,600 regulated entities, and notes that the per-entity costs represent the costs per establishment. This is a different basis from the $9 billion first-year total and the $6 billion recurring annual figure above, which is why they do not divide to the same per-entity number. It carries no segment differentiation and no size differentiation whatsoever: the same figure applies to a solo dental practice and to a thousand-bed health system. The RIA contains no cost estimate for a dental practice, a clinical laboratory, a home health agency or a pharmacy, and the word “dental” does not appear in it once. Segments appear only as establishment counts, with no dollars attached to any of them.

The RIA's real dimension: by provision, nationally

These are HHS's Table 6 first-year costs by provision. Every one is a national total across all 1,822,600 regulated entities, not a per-entity cost, and the hours column is HHS's own estimate of the burden per entity. Dividing a national total by the entity count to get your own number would be our arithmetic over HHS's aggregate rather than an HHS figure, and HHS did not apportion its total that way, so this site does not either.

ProvisionHHS hours per entityNational first-year cost
Update policies and procedures3.5$1,108M
Network segmentation4.5$984M
Penetration testing3$656M
Security Rule compliance audit2$437M
Multi-factor authentication1.5$328M
Revise business associate agreements1$309M
Update workforce training2$252M

Penetration testing is the only line carrying a published sensitivity range, from $437M to $2,186M, which is a five-fold spread and an honest signal of how uncertain HHS is about it. Read the hours column carefully as well: HHS estimates two hours per entity for a Security Rule compliance audit, and three and a half for updating policies and procedures. Whether those are plausible is exactly the kind of thing the comment period existed to test.

The provisions HHS declined to price

HHS put two of the most-discussed provisions in its unquantifiable bucket and attached no dollar figure to either: completing a technology asset inventory, which HHS calls "a baseline expectation for the existing requirement of conducting a risk assessment", and "deploying encryption for ePHI in a more concerted manner". Vulnerability scanning has no cost line anywhere in the RIA. HHS's reasoning is that these are "more in the nature of clarifications to and increased specificity of existing requirements" and too variable to quantify.

These are the two provisions the commentary most often calls the expensive part of the rule, and they are the two with no government figure behind them. This site prints no estimate for them, because an estimate here would be filling a gap HHS itself declined to fill.

Provision by provision

All safeguards become required

Proposed

Replaces: Addressable vs required distinction

Today an organisation can document why an addressable safeguard is not reasonable and appropriate and implement an equivalent alternative. The proposal removes that route. This is the most far-reaching change because it touches every regulated entity, and the burden lands hardest on organisations that used the addressable route heavily.

Encryption mandatory for all ePHI

Proposed

Replaces: Risk-based encryption exceptions

Encryption at rest and in transit without risk-based exceptions. HHS declined to attach any dollar figure to this provision, placing it in its unquantifiable bucket on the reasoning that it is more in the nature of a clarification and increased specificity of an existing requirement.

MFA for all ePHI access

Proposed

Replaces: No prior MFA requirement

A new standalone requirement across every ePHI access point. This one HHS did price, at a $328M national first-year total across all regulated entities, on an estimate of 1.5 hours per entity.

Technology asset inventory and network maps

Proposed

Replaces: No prior standalone requirement

A maintained inventory of every asset that handles ePHI, with network maps showing data flows. HHS attached no dollar figure to this either, calling it a baseline expectation for the existing requirement of conducting a risk assessment.

Vulnerability scanning every 6 months

Proposed

Replaces: Risk-based frequency

A fixed cadence in place of today's risk-based approach. There is no vulnerability-scanning cost line anywhere in the RIA, so HHS published no estimate of what this provision costs.

Annual penetration testing

Proposed

Replaces: No prior requirement

A standalone annual requirement, separate from the risk analysis. HHS priced this at a $656M national first-year total, and it is the one provision where the RIA publishes a sensitivity range, from $437M to $2,186M. That spread is HHS acknowledging how little it knows about the market rate.

72-hour system restoration

Proposed

Replaces: No specific timeline required

Critical ePHI systems restorable within 72 hours, replacing today's general contingency plan requirement. Cloud-native estates often meet this already; on-premises environments frequently do not.

Annual compliance audits

Proposed

Replaces: No prior audit requirement

A formal annual audit against the Security Rule, internal or external. HHS priced this at a $437M national first-year total on an estimate of 2 hours per entity, which is a striking assumption about what a compliance audit involves.

What HHS says about small entities

Under the Regulatory Flexibility Act, HHS counts 740,348 small entities and proposes to certify that the rule would not have a significant economic impact on a substantial number of them. Its size bands are SBA annual-receipts thresholds by NAICS code, from $9M to $47M for providers, not clinical segments. HHS's significance test is a cost above 3 percent of annual revenue, which against its $1,235 per-entity figure means only a firm with revenue below $41,167 would cross it.

Preparing for a proposal

There is no compliance date to work back from, so a countdown would be theatre. What is defensible is to do the things that are already required today and that would also count if the rule is finalised. In rough order of how much they matter under the rule as it stands:

What this page does not do is tell you to budget a percentage uplift. HHS published no such percentage, its per-entity figure is flat across every size and segment, and the two provisions most likely to dominate a real budget are the two it declined to quantify. A number invented to fill that gap would be worse than the gap.

Frequently Asked Questions

When do the 2026 HIPAA Security Rule changes take effect?
They do not, and they may never. The Notice of Proposed Rulemaking was published in the Federal Register on 6 January 2025 and the comment period closed on 7 March 2025. The rule is still a proposal. The comment period closed on 7 March 2025 and no final rule had been published as at July 2026. HHS's Unified Agenda moved the rule to Long-Term Actions and now projects final action in July 2027, having previously projected May 2026. There is no compliance obligation and no compliance date, because there is no final rule. The administration retains discretion to finalise it as proposed, narrow it, delay it further or drop it altogether. Organisations planning against it are planning against a proposal, which is a reasonable thing to do for the provisions with long lead times, but it is not the same as preparing for a deadline.
How much will the 2026 rule changes cost?
HHS priced its own rule, and its figures are the only ones with a source. They sit on three different bases, so it is worth keeping them straight. In the regulatory impact analysis at 90 FR 898, 6 January 2025, HHS estimates approximately $9 billion in total first-year costs ($9,314,106,174 exactly, in the Paperwork Reduction Act section), and roughly $6 billion a year in undiscounted recurring cost across years two through five. Separately, on an annualized basis, HHS reports about $2.3 billion, and it is this figure it divides by 1,822,600 regulated entities to reach the one per-entity number it publishes: approximately $1,235 in annualized cost per regulated entity, which it notes represents cost per establishment. That per-entity figure is flat, with no breakdown by clinical segment and no differentiation by organisation size. If you have seen a percentage uplift or a per-size band attributed to this rule, it did not come from HHS.
Which provisions did HHS decline to price?
HHS put two of the most-discussed provisions in its unquantifiable bucket and attached no dollar figure to either: completing a technology asset inventory, which HHS calls "a baseline expectation for the existing requirement of conducting a risk assessment", and "deploying encryption for ePHI in a more concerted manner". Vulnerability scanning has no cost line anywhere in the RIA. HHS's reasoning is that these are "more in the nature of clarifications to and increased specificity of existing requirements" and too variable to quantify. This matters more than it sounds. The asset inventory and the encryption mandate are the two provisions most often described as the expensive ones, and they are precisely the two HHS attached no dollar figure to. Vulnerability scanning has no cost line anywhere in the RIA either. So the provisions the commentary treats as the headline cost of the rule are the ones its own author declined to quantify, and any figure you see against them is somebody's estimate rather than a government one.
Does the rule cost less for a small practice?
HHS does not say, and its own analysis is structured so that it cannot. The RIA applies a flat, undifferentiated respondent count across all regulated entities, so the $1,235 per-entity figure is the same for a solo practice and a health system. What HHS does address is small-entity impact under the Regulatory Flexibility Act. Under the Regulatory Flexibility Act, HHS counts 740,348 small entities and proposes to certify that the rule would not have a significant economic impact on a substantial number of them. Its size bands are SBA annual-receipts thresholds by NAICS code, from $9M to $47M for providers, not clinical segments. HHS's significance test is a cost above 3 percent of annual revenue, which against its $1,235 per-entity figure means only a firm with revenue below $41,167 would cross it. That last clause is the striking one: on HHS's own numbers, the rule clears its own significance threshold for almost every real business, which is a large part of why the proposal drew the response it did.
Do the 2026 changes apply to business associates?
Yes, and business associates are the majority of HHS's denominator rather than an afterthought. Its 1,822,600 regulated entities are 822,600 covered entity establishments plus 1,000,000 business associates, so more than half of the entities the rule reaches are BAs. The proposed obligations apply equally: the same technical safeguards, the same asset inventory, the same scanning and penetration testing cadence, the same restoration requirement and the same compliance audit. A separate population of 742,411 health plan sponsors is costed separately in the RIA. See the business associate guide for how BA obligations differ from a covered entity's today.
What should I do now?
Nothing that you would regret if the rule never lands, which is a real possibility. The provisions worth acting on now are the ones that are defensible under the current rule anyway: a current risk analysis, which is already required and is the single most enforced provision in OCR's published record; MFA across ePHI access, which is already the most common finding in breach post-mortems; and knowing what systems you actually have, which no risk analysis is credible without. Each of those improves your position under the rule as it stands today and would count toward the proposal if it is finalised. Building against the proposal's specific cadences and thresholds before they are final is speculative, because the proposal is not a deadline and the thresholds may not survive.

Updated 2026-07-17