Compliance

0 min read

HIPAA Updates in 2026: What Changed, What's Proposed & What Got Vacated

Shamai Cohen

Shamai Cohen

CEO of FaxSIPit Services Inc.

HIPAA Updates

In this article

Get fresh insights, bi-weekly

Stay ahead of fax compliance, security, and integration trends. Join our community of IT pros and MSPs.

As of August 2026, only one major new HIPAA rule has actually taken effect this year: the February 16, 2026 deadline to update your Notice of Privacy Practices for substance use disorder records. The change most people mean when they search "2026 HIPAA changes," the big Security Rule cybersecurity overhaul, is still only proposed. And the 2024 rule on reproductive health privacy that many organizations spent late 2024 preparing for was struck down in court and is no longer in effect.

That gap between what is law and what is only headlines is where compliance mistakes happen. This is a running changelog of the HIPAA updates in 2026: what is final, what is proposed, what got vacated, and which deadlines have already passed. Every status below is checked against HHS and the Federal Register. At FaxSIPit, we build HIPAA-compliant cloud fax for healthcare, legal, and financial organizations, and we co-created HTTPS faxing back in 2008, so we track these rules closely because they govern how our customers move protected health information every day.

Key Takeaways

  • Only one major new HIPAA rule became binding in 2026. Covered entities that handle substance use disorder records had to update their Notice of Privacy Practices by February 16, 2026. That deadline is final and has passed. This year's higher penalty amounts are a routine annual inflation adjustment, not a new rule.

  • The big Security Rule cybersecurity overhaul is still only proposed. It was published in January 2025, has no final rule, and its projected final action has slipped to July 2027. Mandatory encryption and multi-factor authentication are not law yet.

  • The 2024 reproductive health privacy rule was vacated. A federal court struck it down nationwide on June 18, 2025. It is not enforceable, except for one narrow piece that survived.

  • HIPAA penalties went up with the 2025 inflation adjustment. The top tier now reaches a maximum of $2,190,294 per violation category per year.

  • Enforcement never paused. The Office for Civil Rights kept settling cases through 2025 and 2026, and nearly every one names the same root failure: no risk analysis covering all electronic protected health information.

2026 HIPAA Changes at a Glance

Here is the whole year in one place. Each row is a distinct regulatory item, its current status as of August 2026, and the date that matters most.

Change

Status

What it means

Key date

Part 2 / SUD records Notice of Privacy Practices update

Final (in effect)

Covered entities handling SUD records had to update their NPP

February 16, 2026 (passed)

HIPAA Security Rule cybersecurity overhaul

Proposed

Not law; prepare, do not comply yet

Final action projected July 2027

Reproductive Health Privacy Rule (2024)

Vacated

Struck down by a federal court; not enforceable

Vacated June 18, 2025

"Coordinated Care" Privacy Rule modifications

Proposed

Faster records access and other changes; may finalize in 2026

Final rule expected August 2026

Civil monetary penalty amounts

Final (adjusted)

Higher fines to track inflation

Published January 28, 2026

OCR enforcement (Risk Analysis Initiative, ransomware, Right of Access)

Active

Ongoing settlements

Through 2025 and 2026

HHS and OCR reorganization

Implemented

OCR restructured, not dissolved; enforcement continues

2025 to May 2026

What's Final: The February 16, 2026 Notice of Privacy Practices Deadline

The one HIPAA-related change that became mandatory in 2026 is the updated Notice of Privacy Practices requirement tied to the 42 CFR Part 2 final rule on substance use disorder records. This is final and in effect. The compliance deadline was February 16, 2026, and it has passed.

42 CFR Part 2 protects the confidentiality of records from federally assisted substance use disorder treatment programs. The final rule aligning Part 2 more closely with HIPAA was published in the Federal Register on February 16, 2024, took effect on April 16, 2024, and set a compliance date of February 16, 2026. Covered entities and health plans that also handle Part 2 records had to update their Notice of Privacy Practices by that date to reflect the new rules on how this sensitive information can be used and shared.

The one HIPAA-related change that became mandatory in 2026. The compliance deadline has passed.

The one HIPAA-related change that became mandatory in 2026. The compliance deadline has passed.

One detail is easy to miss. The rule's requirement to account for certain disclosures under Section 2.25 is tolled, meaning paused, until HHS revises the related HIPAA provision at 45 CFR 164.528. That piece is not yet in force. The Notice of Privacy Practices update, however, was due on February 16, 2026, and applies now.

If your organization handles both HIPAA-covered information and Part 2 records and has not refreshed its Notice of Privacy Practices, that is the first gap to close. Our HIPAA fax requirements checklist walks through the related transmission and documentation obligations.

What's Only Proposed: The HIPAA Security Rule Cybersecurity Overhaul

The change generating the most "2026 HIPAA" headlines is still a proposal, not law. HHS has proposed a major update to the HIPAA Security Rule that would make today's "addressable" technical safeguards strictly required, including universal encryption of electronic protected health information, mandatory multi-factor authentication, vulnerability scans at least every six months, and annual penetration testing. None of that is currently mandatory. Treat it as something to prepare for, not something to comply with today.

Here is where the proposal actually stands. The Office for Civil Rights issued the Notice of Proposed Rulemaking on December 27, 2024, and it was published in the Federal Register on January 6, 2025. The public comment period closed on March 7, 2025. Since then, the 2026 Unified Agenda moved the rule to its Long-Term Actions list and pushed projected final action to July 2027, back from an earlier May 2026 target. HHS's own Regulatory Impact Analysis puts first-year industry compliance costs at roughly $9 billion. Once a final rule does publish, the proposal describes an effective date 60 days later, a compliance window of roughly 180 days after that, and up to a year to update business associate agreements.

Where the proposed Security Rule overhaul actually stands. It is not law, and final action has slipped to 2027.

Because this is a proposal, the specific requirements can still change before any of it becomes enforceable. We cover the proposed Security Rule in full, including each safeguard and the timeline, in our complete HIPAA Security Rule guide.

The proposal does point at a direction worth noting now: it makes encryption of electronic protected health information in transit an explicit expectation rather than an optional one. Fax is a common channel for that information, and it is one many organizations forget to secure. We encrypt the last mile over TLS on every fax and every plan, which is exactly the transmission leg the Security Rule cares about most. You can see how that works on our cloud fax platform.

What Got Struck Down: The Reproductive Health Privacy Rule

The 2024 HIPAA Privacy Rule to Support Reproductive Health Care Privacy is not in effect. A federal court vacated it nationwide on June 18, 2025. This was a court decision, not a repeal by HHS, and the distinction matters for how you read it.

The rule was published in April 2024 and would have added special protections for reproductive health information, including an attestation requirement before certain disclosures. In Purl v. HHS, the U.S. District Court for the Northern District of Texas vacated the rule nationwide. The Fifth Circuit dismissed the appeal on September 10, 2025. The attestation requirement is gone at the federal level.

One narrow piece survived, and it connects to the deadline above. The court left standing the rule's changes to 45 CFR 164.520, the section governing the Notice of Privacy Practices. That surviving carve-out is part of what keeps the February 16, 2026 Part 2 Notice of Privacy Practices update alive. So the reproductive health protections are gone, but a slice of the Notice of Privacy Practices changes remains in force.

Two cautions. There is no HHS rescission rule in the Federal Register undoing this; the change came entirely from the court, so describe it as vacated by court order, not repealed by the agency. And state laws protecting reproductive health information can still apply, so check your own state's requirements.

The distinction matters for how you document the change. Note that state laws protecting reproductive health information can still apply.

Also Proposed: The 2021 "Coordinated Care" Privacy Rule Modifications

A separate and older set of HIPAA Privacy Rule changes is back on the agenda and could finalize in 2026. It is still proposed today. First introduced in a 2021 Notice of Proposed Rulemaking, this package would strengthen patients' right to access their own records, shorten the response time for access requests from 30 days to 15, let patients inspect and photograph their records in person, and reduce some administrative burdens on providers.

Part of the proposed Coordinated Care Privacy Rule modifications. Still only proposed, with a final rule expected as soon as August 2026.

Part of the proposed Coordinated Care Privacy Rule modifications. Still only proposed, with a final rule expected as soon as August 2026.

HHS signaled renewed movement on it in early 2026. A tribal consultation notice published in the Federal Register on January 14, 2026 set a consultation meeting for February 6, 2026, a step that usually precedes finalizing a rule. Industry trackers reading the 2026 regulatory agenda expect a final rule as soon as August 2026, though that timing is a projection, not a guarantee. This is one to watch closely if your organization fields a high volume of patient record requests.

New HIPAA Penalty Amounts for 2026

HIPAA civil monetary penalties went up with the latest inflation adjustment, published in the Federal Register on January 28, 2026. This is a routine annual inflation update to existing penalty tiers, not a new penalty rule. These are the current operative amounts. The adjustment reflects the 2025 figures; a separate 2026 column has not been published yet.

Penalty tier

Minimum per violation

Maximum per violation

Annual cap per violation category

Tier 1: No knowledge

$145

$73,011

$2,190,294

Tier 2: Reasonable cause

$1,461

$73,011

$2,190,294

Tier 3: Willful neglect, corrected

$14,602

$73,011

$2,190,294

Tier 4: Willful neglect, not corrected

$73,011

$2,190,294

$2,190,294

The tiers turn on culpability. A violation you had no reasonable way to know about sits in Tier 1. A violation caused by willful neglect that you never fixed sits in Tier 4, where a single category of violations can reach $2,190,294 in a calendar year. One caveat the Federal Register figures do not show: since 2019, OCR has used enforcement discretion to apply lower annual caps to Tiers 1 through 3, so in practice only Tier 4 exposure reaches the full amount. That policy has not been superseded by rulemaking, so the lower caps still govern most cases.

For the full breakdown of HIPAA fines, common violation types, and how penalties are calculated, see our HIPAA violation statistics.

Minimum civil monetary penalty per violation by tier, from the inflation adjustment published January 28, 2026.

Minimum civil monetary penalty per violation by tier, from the inflation adjustment published January 28, 2026.

Enforcement Stayed Active: OCR Settlements in 2025 and 2026

Despite a deregulatory climate in Washington, the Office for Civil Rights did not stop enforcing HIPAA. It settled a steady run of cases through 2025 and 2026, and one failure appears again and again: the organization never ran a complete risk analysis covering all of its electronic protected health information.

Most of these fall under OCR's Risk Analysis Initiative, which targets exactly that failure. Several are also ransomware cases. OCR announced each of these settlements through its own press releases across 2025 and 2026.

Organization

Amount

Date

Focus

Health Fitness Corporation

$227,816

March 21, 2025

Risk Analysis Initiative

Northeast Radiology

$350,000

April 10, 2025

Risk analysis; 298,532 patients

Comprehensive Neurology

$25,000

April 25, 2025

Ransomware; risk analysis

Comstar

$75,000

May 30, 2025

Ransomware; 585,621 individuals

BST & Co. CPAs

$175,000

August 18, 2025

Ransomware; risk analysis

Oregon Health & Science University

$200,000

March 6, 2025

Right of access

Concentra

$112,500

December 16, 2025

Right of access

MMG Fusion

$10,000

March 5, 2026

Risk analysis; breach affected 15 million people

Four ransomware settlements

$1,165,000 total

April 23, 2026

Ransomware; 427,000+ individuals

The settlements span March 2025 through April 2026, so enforcement clearly continued through the year. The lesson from the pattern is consistent: a risk analysis has to account for every place electronic protected health information lives and moves, and document transmission is one of those places.

Fax is part of that surface. We support that documentation with TLS-encrypted transport, full audit trails, configurable retention up to seven years, and business associate agreement signing on every plan, so the fax channel is covered when OCR investigates. It does not remove your obligation to run the risk analysis, but it closes one common gap in it.

Did Trump Change HIPAA?

No. HIPAA itself was not repealed or rewritten. The Privacy Rule, the Security Rule, and the Breach Notification Rule are all still in force, and organizations must still comply with them. The 2025 change in administration affected the timing of pending rules and some sub-regulatory guidance, not the core law.

A regulatory freeze early in 2025 paused pending federal rulemaking, which is part of why the proposed Security Rule update slipped later into the schedule. That is a delay to a proposal, not a change to existing HIPAA obligations.

The other 2025 development was structural. HHS reorganized, creating a new Assistant Secretary for Enforcement with oversight of the Office for Civil Rights and consolidating departmental divisions and regional offices. OCR then restructured internally in May 2026, moving HIPAA work into a new Health Information Privacy, Data, and Cybersecurity Division (HHS announcement). OCR was not dissolved, and HHS stated the reorganization is "not expected to result in reduction of OCR's workforce." OCR kept settling HIPAA cases right through the change, including several enforcement actions dated in 2026.

Frequently Asked Questions

What are the new HIPAA changes for 2026?

The HIPAA updates for 2026 come down to one binding change: the updated Notice of Privacy Practices requirement for substance use disorder records under 42 CFR Part 2, with a compliance deadline of February 16, 2026. The widely discussed Security Rule cybersecurity overhaul is still only proposed, and the 2024 reproductive health privacy rule was vacated by a federal court in June 2025. So most of the new HIPAA regulations people ask about are either proposed or off the table, not yet enforceable.

How often is HIPAA updated?

HIPAA has no fixed update schedule. Changes happen when HHS issues new rules through the federal rulemaking process, which can take years from proposal to final rule. Some years bring several changes and some bring none. The pace in 2025 and 2026 has been unusually active because of the proposed Security Rule, the Part 2 alignment, and ongoing litigation.

Where is the best place to find official HIPAA changes?

The authoritative sources are HHS, specifically the Office for Civil Rights, and the Federal Register, where every proposed and final rule is published. Vendor summaries and news articles can help you track developments, but confirm the status and dates against the primary sources, because secondary coverage often blurs what is final versus what is only proposed.

What is the biggest HIPAA change coming next?

The largest change on the horizon is the proposed HIPAA Security Rule cybersecurity overhaul, which would make encryption, multi-factor authentication, and regular security testing mandatory rather than optional. Its projected final action is July 2027, and the specifics could still change. We track it in full in our HIPAA Security Rule guide.

The Bottom Line

The practical read on HIPAA in 2026 is short. Update your Notice of Privacy Practices for Part 2 substance use disorder records if you have not, because that deadline has passed. Prepare for the proposed Security Rule but do not treat it as law yet, because it may not finalize until 2027. Set aside the 2024 reproductive health rule, because a court vacated it. And keep running a complete risk analysis, because enforcement never slowed and that single failure drives most settlements.

Rules like these are the reason we exist. FaxSIPit is our cloud fax platform for regulated healthcare, legal, and financial organizations, built on a dedicated fax network with encrypted transport and audit trails on every plan, so the documents that carry protected health information move securely and leave a record you can show an auditor. If secure, provable fax is part of your compliance picture, see how we handle HIPAA-compliant fax.

Sources

  1. Federal Register: Confidentiality of Substance Use Disorder (SUD) Patient Records, Final Rule

  2. Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, Proposed Rule

  3. CourtListener: Purl v. U.S. Department of Health and Human Services, Docket and Order

  4. Federal Register: Tribal Consultation on Proposed Modifications to the HIPAA Privacy Rule

  5. Federal Register: Annual Civil Monetary Penalties Inflation Adjustment

  6. HHS: HIPAA Regulatory Initiatives

  7. HHS: Restructuring of the Office for Civil Rights

  8. HHS: OCR Settlement with Health Fitness Corporation

  9. HHS: OCR Settlement with Northeast Radiology

  10. HHS: OCR Settles Four Ransomware Investigations

  11. HHS: OCR Settlement with MMG Fusion

Follow FaxSIPit on LinkedIn for more fax insights and news

Follow FaxSIPit on LinkedIn for more fax insights and news

Follow FaxSIPit on LinkedIn for more fax insights and news

Shamai Cohen

Shamai Cohen

Shamai Cohen is the CEO of FaxSIPit Services Inc., a cloud fax infrastructure company headquartered in Vancouver, Canada. With a background in economics and over a decade at FaxSIPit — from project coordinator to chief executive — Shamai leads the company's mission to deliver compliance, continuity, and confidence in fax solutions for regulated industries. Under his leadership, FaxSIPit serves 300+ channel partners across 40+ countries and continues to expand its direct enterprise offering for healthcare, legal, and financial organizations.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.