healthcare-in-action-proofpoint-brand-image

Don't Let the HIPAA Timeline Delay Your Data Security Strategy

Share with your network!

Key Takeaways

  • The current target date for final rulemaking has been pushed to July 2027, but cyber threats targeting healthcare continue to grow.
  • The proposed updates place greater emphasis on protecting electronic protected health information (ePHI) through stronger cybersecurity and data security practices.
  • Now is the time for healthcare organizations to improve visibility into sensitive data, reduce data exposure and strengthen governance, not wait for the final rule.
  • A layered data security strategy can help organizations prepare for future compliance while reducing today's risk.

When HHS published its proposed updates to the HIPAA Security Rule in January 2025, it represented the most significant overhaul of the regulation in more than a decade. The proposal reflects today's cybersecurity reality: healthcare organizations remain a top target for ransomware, insider threats and data breaches.

Although regulators currently anticipate final rulemaking in July 2027, the risks facing healthcare organizations haven't changed. Rather than focusing on the timeline and the potential changes to enforcement, security and privacy teams would be better served by understanding the reasons behind the changes.

First, if you are protecting patient data for your organization, you are protecting the most profitable information for an attacker to steal. Depending on which source you use, a health record is between ten times and fifty times more valuable than Personally Identifiable Information alone. There are many reasons for this, including the permanence of the information, and the ability to monetize it in many ways.

Second, the original HIPAA rules were written for a different time. At the time, electronic health data was typically shared through a more limited set of systems, and concerns focused heavily on storage and access controls. In 2025, it was clear that the definition of what health information is had expanded and the ways in which it could be shared and compromised had grown. In 2026, the rapid expansion of the use of Artificial Intelligence (AI), especially in healthcare, has further expanded the risk surface.

Third, the regulatory environment has matured since the original HIPAA rules were written. At one time, regulations were thought of as punitive rules that fined organizations for making mistakes or not complying with the letter of the law. Modern global regulations have become collaborative, attempting to help organizations mature their security posture. Additionally, they have expanded the size of penalties for non-compliance but have reserved heavy-handed enforcement for organizations who are not complying willfully.

The timeline has shifted, but the focus is clear. Healthcare organizations should not wait for the rules to be finalized to think about protecting health information in the modern world. There are clear steps that can be taken immediately to strengthen your security posture and put your team in a better place to comply with whatever the final changes to the HIPAA rule may be.

A stronger focus on protecting healthcare data

The proposed Security Rule spans administrative, physical and technical safeguards. While the updates cover a broad range of requirements, the data security implications center on a few key priorities:

  • Better visibility into where ePHI resides
  • Stronger protection for sensitive data across cloud and hybrid environments
  • Greater oversight of who has access to regulated information
  • Improved monitoring and governance of how sensitive data is used
  • (Likely) How Health Information can be used by and transferred between AI systems

This reflects the reality of today's healthcare environment. ePHI is no longer confined to electronic health record systems. Sensitive data moves through email, collaboration platforms, cloud repositories, file shares and an expanding number of AI-enabled applications, making visibility and governance more important than ever.

Additionally, many healthcare organizations are on the cutting edge of how AI systems can be used to benefit humanity. There are use cases spanning better use of resources, faster access to care, and better outcomes for patients. AI applications in healthcare are already delivering meaningful improvements. We cannot slow the adoption, nor should we want to.

However, all of these use cases require sensitive information to be accessed and transferred between AI systems, often between multiple organizations. Knowing that PHI is valuable to attackers, security teams must be vigilant to ensure benefits to society can be realized without undue risk to sensitive information.

Turning HIPAA preparedness into a modern data security strategy

The proposed Security Rule reinforces a broader shift in healthcare cybersecurity. Compliance is no longer just about implementing individual security controls, it's about demonstrating that organizations understand where sensitive data resides, how it's used and how it's protected. Organizations also need evidence that those controls are working from discovering where sensitive data resides to maintaining the visibility and audit trails needed to investigate incidents, demonstrate appropriate governance and continuously reduce risk.

Here are three priorities organizations should focus on today.

1. Gain visibility into sensitive data

The proposed rule updates reinforce the importance of maintaining accurate asset inventories, conducting ongoing risk analyses and understanding where ePHI resides. Those objectives become increasingly challenging as healthcare organizations adopt cloud platforms, collaboration tools and AI applications.

Organizations should prioritize capabilities that can:

  • Discover and classify sensitive data across cloud and hybrid environments.
  • Identify excessive permissions and unnecessary data exposure.
  • Understand how AI applications access and interact with sensitive information.

Proofpoint helps organizations address these challenges through Data Security Posture Management (DSPM) and Data Security for AI, providing the visibility needed to understand where sensitive data exists and how it is being used including within AI-enabled workflows.

2. Apply consistent protection wherever data moves

Sensitive data no longer moves through a single communication channel. It flows through email, cloud applications, collaboration platforms, endpoints and increasingly, AI services.

The proposed Security Rule updates reinforce the need for consistent protection regardless of where sensitive data resides or how it's shared.

Healthcare organizations should look for capabilities that:

  • Apply consistent data protection policies across communication channels.
  • Prevent accidental and intentional disclosure of sensitive information.
  • Reduce common user mistakes, such as misaddressed emails and incorrect attachments.

Proofpoint Enterprise DLP, Adaptive Email DLP and Data Security for AI help extend consistent protection across email, endpoints, cloud applications and AI interactions helping ensure that sensitive data is governed consistently wherever it moves.

3. Turn visibility into governance

Blocking a data loss event is important, but it's only part of the story.

Security and compliance teams also need the ability to understand what happened, investigate why it happened and demonstrate that appropriate safeguards and oversight are in place. That means maintaining an audit trail of sensitive data activity, supporting forensic investigations and identifying patterns that can help reduce future risk.

Healthcare organizations should look for capabilities that:

  • Preserve visibility into sensitive data activity.
  • Support forensic investigations and incident response.
  • Identify patterns of risky user behavior.
  • Provide actionable insight for security, privacy and compliance teams.

Proofpoint Insider Threat Management, Enterprise DLP and Digital Communications Governance help organizations move beyond prevention by providing the visibility and governance needed to investigate incidents, understand user behavior and demonstrate appropriate oversight of sensitive information.

Just as importantly, this operational visibility enables organizations to continuously improve their security posture. Rather than simply responding to incidents, security and compliance teams can identify recurring trends, refine policies, focus user education where it's needed most and demonstrate measurable progress over time.

The timeline changed. The mission hasn't.

The proposed changes to the HIPAA Security Rule may still evolve before it's finalized, but the direction is clear: healthcare organizations need stronger visibility, better governance and more effective protection of sensitive data.

The additional time before the rule takes effect gives organizations an opportunity to:

  • Identify where ePHI resides
  • Reduce unnecessary data exposure
  • Strengthen protection across email, cloud and AI applications
  • Improve governance and insider risk visibility

Organizations that begin building these capabilities today won't just be better prepared for future HIPAA requirements, they'll also be better positioned to defend against today's evolving threats.

After all, regulatory timelines may move. Attackers won't wait.

Learn how Proofpoint helps healthcare organizations discover, protect and govern sensitive data across email, cloud, endpoints and AI, visit https://www.proofpoint.com/us/products/data-security-governance.