2026 HIPAA Security Rule Changes: What HHS Says They Cost
The proposed 2026 Security Rule update would be the most significant HIPAA change in over a decade. HHS priced it in the proposal's own regulatory impact analysis, and that analysis is the only source for what the rule would cost. This page reports what HHS put against each provision, and is equally explicit about the provisions HHS declined to price at all.
Rule status: proposed, not final
This rule is still a proposal. The comment period closed on 7 March 2025 and no final rule had been published as at July 2026. HHS's Unified Agenda moved the rule to Long-Term Actions and now projects final action in July 2027, having previously projected May 2026. There is no compliance obligation and no compliance date, because there is no final rule. Nothing on this page is in force. Source: 90 FR 898, 6 January 2025, RIN 0945-AA22, the proposed rule as published on the Federal Register. The regulatory impact analysis is Section V, pages 992 to 1007.
HHS's own estimates
First year, national
$9 billion
$9,314,106,174 exactly
Years 2-5, per year
$6 billion
Undiscounted recurring cost
Regulated entities
1,822,600
822,600 CE + 1,000,000 BA
Per entity, annualized
$1,235
The only per-entity figure
That $1,235 is the entire per-entity story, and it is flat. HHS derives it from its annualized cost of $2.3 billion divided by 1,822,600 regulated entities, and notes that the per-entity costs represent the costs per establishment. This is a different basis from the $9 billion first-year total and the $6 billion recurring annual figure above, which is why they do not divide to the same per-entity number. It carries no segment differentiation and no size differentiation whatsoever: the same figure applies to a solo dental practice and to a thousand-bed health system. The RIA contains no cost estimate for a dental practice, a clinical laboratory, a home health agency or a pharmacy, and the word “dental” does not appear in it once. Segments appear only as establishment counts, with no dollars attached to any of them.
The RIA's real dimension: by provision, nationally
These are HHS's Table 6 first-year costs by provision. Every one is a national total across all 1,822,600 regulated entities, not a per-entity cost, and the hours column is HHS's own estimate of the burden per entity. Dividing a national total by the entity count to get your own number would be our arithmetic over HHS's aggregate rather than an HHS figure, and HHS did not apportion its total that way, so this site does not either.
| Provision | HHS hours per entity | National first-year cost |
|---|---|---|
| Update policies and procedures | 3.5 | $1,108M |
| Network segmentation | 4.5 | $984M |
| Penetration testing | 3 | $656M |
| Security Rule compliance audit | 2 | $437M |
| Multi-factor authentication | 1.5 | $328M |
| Revise business associate agreements | 1 | $309M |
| Update workforce training | 2 | $252M |
Penetration testing is the only line carrying a published sensitivity range, from $437M to $2,186M, which is a five-fold spread and an honest signal of how uncertain HHS is about it. Read the hours column carefully as well: HHS estimates two hours per entity for a Security Rule compliance audit, and three and a half for updating policies and procedures. Whether those are plausible is exactly the kind of thing the comment period existed to test.
The provisions HHS declined to price
HHS put two of the most-discussed provisions in its unquantifiable bucket and attached no dollar figure to either: completing a technology asset inventory, which HHS calls "a baseline expectation for the existing requirement of conducting a risk assessment", and "deploying encryption for ePHI in a more concerted manner". Vulnerability scanning has no cost line anywhere in the RIA. HHS's reasoning is that these are "more in the nature of clarifications to and increased specificity of existing requirements" and too variable to quantify.
These are the two provisions the commentary most often calls the expensive part of the rule, and they are the two with no government figure behind them. This site prints no estimate for them, because an estimate here would be filling a gap HHS itself declined to fill.
Provision by provision
All safeguards become required
ProposedReplaces: Addressable vs required distinction
Today an organisation can document why an addressable safeguard is not reasonable and appropriate and implement an equivalent alternative. The proposal removes that route. This is the most far-reaching change because it touches every regulated entity, and the burden lands hardest on organisations that used the addressable route heavily.
Encryption mandatory for all ePHI
ProposedReplaces: Risk-based encryption exceptions
Encryption at rest and in transit without risk-based exceptions. HHS declined to attach any dollar figure to this provision, placing it in its unquantifiable bucket on the reasoning that it is more in the nature of a clarification and increased specificity of an existing requirement.
MFA for all ePHI access
ProposedReplaces: No prior MFA requirement
A new standalone requirement across every ePHI access point. This one HHS did price, at a $328M national first-year total across all regulated entities, on an estimate of 1.5 hours per entity.
Technology asset inventory and network maps
ProposedReplaces: No prior standalone requirement
A maintained inventory of every asset that handles ePHI, with network maps showing data flows. HHS attached no dollar figure to this either, calling it a baseline expectation for the existing requirement of conducting a risk assessment.
Vulnerability scanning every 6 months
ProposedReplaces: Risk-based frequency
A fixed cadence in place of today's risk-based approach. There is no vulnerability-scanning cost line anywhere in the RIA, so HHS published no estimate of what this provision costs.
Annual penetration testing
ProposedReplaces: No prior requirement
A standalone annual requirement, separate from the risk analysis. HHS priced this at a $656M national first-year total, and it is the one provision where the RIA publishes a sensitivity range, from $437M to $2,186M. That spread is HHS acknowledging how little it knows about the market rate.
72-hour system restoration
ProposedReplaces: No specific timeline required
Critical ePHI systems restorable within 72 hours, replacing today's general contingency plan requirement. Cloud-native estates often meet this already; on-premises environments frequently do not.
Annual compliance audits
ProposedReplaces: No prior audit requirement
A formal annual audit against the Security Rule, internal or external. HHS priced this at a $437M national first-year total on an estimate of 2 hours per entity, which is a striking assumption about what a compliance audit involves.
What HHS says about small entities
Under the Regulatory Flexibility Act, HHS counts 740,348 small entities and proposes to certify that the rule would not have a significant economic impact on a substantial number of them. Its size bands are SBA annual-receipts thresholds by NAICS code, from $9M to $47M for providers, not clinical segments. HHS's significance test is a cost above 3 percent of annual revenue, which against its $1,235 per-entity figure means only a firm with revenue below $41,167 would cross it.
Preparing for a proposal
There is no compliance date to work back from, so a countdown would be theatre. What is defensible is to do the things that are already required today and that would also count if the rule is finalised. In rough order of how much they matter under the rule as it stands:
- A current risk analysis. Already required under 45 CFR 164.308(a)(1)(ii)(A), and the single most enforced provision in OCR's published record. OCR's Risk Analysis Initiative focuses selected investigations on it specifically. See risk assessment cost.
- Know what you have. The asset inventory is a proposed requirement, but HHS's own framing is that it is a baseline expectation of the risk analysis you already owe. No risk analysis is credible without it, whatever happens to the rule.
- MFA across ePHI access. Not required today, but it is the most common gap in breach post-mortems, and for an organisation already on Microsoft 365 it is frequently a $0 line, because Entra ID Free includes multifactor authentication. See the published identity rates.
- Audit logs someone actually reads. Capturing them is usually the vendor's job and reviewing them is yours under 164.308(a)(1)(ii)(D). This is a process, not a purchase, and it recurs in OCR's findings.
What this page does not do is tell you to budget a percentage uplift. HHS published no such percentage, its per-entity figure is flat across every size and segment, and the two provisions most likely to dominate a real budget are the two it declined to quantify. A number invented to fill that gap would be worse than the gap.