Skip to main content
A doctor using and looking at a digital tablet in a hospital.

HIPAA at 30: What Healthcare Leaders Should Know

HIPAA turns 30 as healthcare organizations prepare for evolving security requirements.

Thirty years after the Health Insurance Portability and Accountability Act of 1996 (HIPAA) became law, the healthcare environment looks markedly different. Health information now moves through cloud platforms, connected medical technologies, mobile applications, and a broad network of service providers. Yet the central responsibility remains: protect health information while supporting the care and operations that depend on it.

HIPAA’s 30th anniversary offers healthcare organizations an opportunity to reflect on how the law has evolved and consider whether their security and privacy programs have kept pace.

From Insurance Portability to Health Information Protection

President Bill Clinton signed HIPAA into law on August 21, 1996. The legislation was originally intended in part to improve the portability of health insurance coverage. It addressed concerns such as maintaining coverage when changing jobs and obtaining coverage with preexisting conditions.1 In his signing statement, Clinton said the legislation would protect the healthcare of millions of working Americans and give their families “peace of mind.”2

Over time, HIPAA became closely associated with another important objective: establishing national standards for the privacy and security of health information.

Shortly after HIPAA became law, the U.S. Department of Health & Human Services (HHS) published the Privacy Rule in December 2000 and the Security Rule in February 2003. Then came the introduction of the Breach Notification Interim Rule in August 2009, and Omnibus HIPAA Rulemaking with provisions from the Health Information Technology for Economic and Clinical Health (HITECH) Act in January 2013, which finalized the Breach Notification Rule and shored up security and privacy protections.3 Minor updates and provisions have been made since 2013, but the safeguards and requirements have largely remained untouched.

Together, these requirements helped shape the privacy and security framework healthcare organizations use today.

The Risk Environment Has Changed

The foundational objectives of the HIPAA Security Rule remain relevant. At its core, the rule is intended to secure electronic protected health information (ePHI), including patient information stored, processed, or transmitted electronically. The technology environment surrounding that information, however, has become far more distributed and interconnected.

A patient record may pass through clinical systems, billing platforms, cloud environments, and third-party applications. Business associates and subcontractors may support services that involve access to ePHI. New technologies also may introduce data uses or dependencies that were not contemplated when the Security Rule was first published.

Understanding the current risk environment is particularly important for these reasons. A security risk assessment should reflect the organization’s current technology stack and operational processes rather than a historical inventory of systems. It should consider where ePHI is created, received, maintained, or transmitted. It also should account for relevant technologies and relationships that could affect that information.

Security and privacy assessments can help organizations identify vulnerabilities or gaps in their safeguards. They also can provide a clearer basis for prioritizing remediation efforts.

Proposed HIPAA Changes Point Toward Greater Specificity

HHS has continued to consider updates to the HIPAA regulations. A December 2020 Notice of Proposed Rulemaking (NPRM) focused primarily on proposed changes to the Privacy Rule. Separate rulemaking followed in December 2024, when the HHS Office for Civil Rights issued a proposal to strengthen the HIPAA Security Rule.

The NPRM proposes strengthening the Security Rule’s standards and implementation specifications with new proposals and clarifications, including but not limited to:

  • Remove the distinction between “required” and “addressable” implementation specifications and make implementation specifications required with specific, limited exceptions.
  • Require greater specificity for conducting a risk analysis.
  • Add specific compliance time periods for many existing requirements.
  • Strengthen requirements for planning for contingencies and responding to security incidents.
  • Require encryption of ePHI at rest and in transit, with limited exceptions.
  • Require the use of multifactor authentication (MFA), with limited exceptions.
  • Require vulnerability scanning at least every six months and penetration testing at least once every 12 months.

The proposal also addresses network segmentation, documentation, and the restoration of certain systems and data following an incident.4 These provisions remain proposed and may change before any final rule is published. Current Security Rule requirements continue to apply in the meantime.

The federal regulatory agenda projects final action for July 2027.5

That date is a planning projection rather than a confirmed publication date. Healthcare organizations should monitor the rulemaking process and avoid treating the proposal as final. At the same time, many of its themes reflect practical cybersecurity considerations that organizations should consider now.

Actions to Consider Now

Healthcare organizations don’t need to wait for a final rule to weigh whether their programs reflect their current operations and risk profile. Leadership teams can consider several actions, including:

  • Review the most recent security risk analysis and confirm that it reflects current systems, locations, and data flows.
  • Confirm that technology inventories identify the systems that create, receive, maintain, or transmit ePHI.
  • Revisit the organization’s vendor or third-party relationships and related risk-management processes.
  • Assess the use of encryption and MFA across systems involving ePHI.
  • Review incident response and contingency plans against current operational dependencies.
  • Track remediation items through completion and document decisions about risk treatment.
  • Reflect on whether workforce training addresses current threats and employee responsibilities.

These steps should be tailored to the organization’s circumstances. A smaller provider may have different technologies and resources than a large health system, but each organization can benefit from understanding where its ePHI resides and the risks that could affect it.

How Forvis Mazars Can Help

HIPAA’s first 30 years created a lasting framework for health information privacy and security. Its next chapter may bring more detailed expectations for cybersecurity governance and technical safeguards.

Thirty years is a long time for any regulation, especially one written before cloud computing, mobile devices, and today’s cybersecurity threats became part of everyday business. Organizations are facing very different challenges than they were in 1996. The conversation today is less about understanding what HIPAA requires and more about applying those requirements in increasingly complex technology environments. As regulatory expectations and cybersecurity risks continue to evolve, organizations that regularly assess their privacy and security programs may find themselves better prepared for what comes next.

IT Risk & Compliance professionals at Forvis Mazars can help healthcare organizations and their service providers gauge current security and privacy practices, identify potential gaps, and develop a risk-based roadmap. To discuss your organization’s HIPAA program, connect with our professionals today.

  • 1“HIPAA History,” hipaajournal.com, January 2, 2026.
  • 2“Anniversary of HIPAA,” govinfo.gov, August 18, 2020.
  • 3“HIPAA for Professionals,” hhs.gov.
  • 4“HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information,” hhs.gov, December 27, 2024.
  • 5“View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information,” reginfo.gov.

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.