On October 1, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) sent its final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) to the White House Office of Management and Budget (OMB) for review. The HIPAA Journal reports that the rule is expected to publish before the end of the year.
The text under review is not public. Even so, your team can plan for a second reporting clock now, because Congress already wrote its length into the statute.
What happened on October 1
CISA submitted the rule to OMB on Thursday, October 1, according to federal regulatory review records cited by BankInfoSecurity. The agency had missed a statutory deadline of October 2025, then target dates of May 2026 and September 2026.
The submission came days after the White House's top cyber official said cutting overlap with existing reporting mandates has been a focus of the final rule, according to BankInfoSecurity. That matters for healthcare, which already reports breaches to HHS, and CISA estimated its 2024 proposal could reach nearly 300,000 organizations.
Paubox covered CIRCIA in July, when the final rule was still targeted for September, and again in August, when a GAO review found heavy overlap among federal cyber reporting rules.
Related: What to know about CIRCIA and HIPAA reporting timelines
What Congress already set
Two deadlines come straight from the CIRCIA statute. A covered entity must report a covered cyber incident to CISA "not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred," and the statute bars CISA from requiring that report any earlier than 72 hours.
A covered entity that pays a ransom has a separate deadline of 24 hours after the payment, and that applies even when the ransomware attack itself does not qualify as a covered cyber incident.
CISA's CIRCIA page describes the same two requirements. The statute adds supplemental reports whenever substantial new or different information comes to light, plus a duty to preserve data related to the incident.
What the final rule still decides
The statute leaves the effective date, the manner and form of reports, and the timing of supplemental reports to the final rule, so the details that decide when your clock runs are still in the unpublished text.
Under the 2024 proposed rule, an entity in a critical infrastructure sector would be covered if it exceeded the Small Business Administration size standard for its industry or met a sector-based criterion. For healthcare, the proposed criteria included owning or operating a large or critical access hospital, or manufacturing certain essential drugs or Class II or III medical devices.
For a mid-sized healthcare organization, the size test turns on revenue. The NPRM ties the size criterion to SBA standards, and the SBA standards for healthcare industries are set by annual revenue, such as $16 million for physician offices and $47 million for general hospitals.
Under that proposed test, a health system or large specialty group with revenue above those lines would likely be covered, while a smaller practice might not. Owning a hospital with 100 or more beds, or a critical access hospital, would bring an organization in under the proposed sector criteria at any size.
The proposal drew "substantial criticism due to its broad scope and overlap with existing reporting requirements," according to the HIPAA Journal. Law firm Wiley noted on October 6 that comments on the proposal focused on "the scope of covered entities, incident reporting triggers, reporting timelines, recordkeeping requirements, and the need to harmonize CIRCIA with existing federal, state, and international reporting obligations," and that it "remains unclear how extensively CISA modified the proposed rule."
For healthcare, harmonization turns on one provision: the statute exempts an entity that already reports substantially similar information to another federal agency within a substantially similar timeframe, but only once CISA and that agency have an agreement in place.
How the CISA clock sits next to HIPAA's
Under the HHS Breach Notification Rule, covered entities must notify affected individuals "without unreasonable delay and in no case later than 60 days following the discovery of a breach" of unsecured protected health information (PHI).
Breaches affecting 500 or more people also go to the HHS Secretary, and to prominent media when more than 500 residents of a state are affected, on the same 60-day outer limit. Smaller breaches can be logged and reported to HHS within 60 days of the end of the calendar year.
CIRCIA starts at a reasonable belief that a covered cyber incident happened, while HIPAA starts at discovery of a breach of unsecured PHI. A ransomware attack that takes down clinical systems could start the CISA clock days before your team knows whether any patient data left the building.
Email is a likely place for the two clocks to meet: Paubox's 2026 Healthcare Email Security Report counted 170 email-related breaches reported to the HHS Office for Civil Rights (OCR) in 2025, each one already on a HIPAA clock. If CIRCIA covers your organization, an email compromise serious enough to count as a covered cyber incident could add a 72-hour CISA report on top.
Go deeper: GAO finds 70% of federal cyber reporting rules overlap
What your team can settle before the text is public
- Decide in writing who, across IT, legal, and compliance, determines that a "reasonable belief" exists, and how that decision gets logged.
- Map the 72-hour CISA report, the 24-hour ransom payment report, and the HIPAA 60-day notices side by side in one incident response plan, with an owner for each filing.
- Compare your organization to the 2024 size and sector criteria, then revisit once the final rule publishes.
- If a vendor incident could start your CISA clock, review your business associate agreement (BAA) with vendors to assure your team has enough time to fix issues.
- Keep a documented trail of what you knew and when, since the statute requires supplemental reports and data preservation.
On the HIPAA side, HHS guidance treats PHI that has been encrypted to its specification as secured, which means a breach of that data does not trigger HIPAA notification.
Encryption won't remove a CIRCIA report, because CISA's clock depends on the incident, but it can cut the number of filings a single email incident produces. HIPAA compliant email that encrypts every message by default is worth adding to the plan.
FAQs
Does a CIRCIA report satisfy HIPAA breach notification?
No. The two obligations go to different agencies under different triggers, and a report to CISA does not notify patients or HHS. Paubox covered how the two regimes overlap in its post on CIRCIA and HIPAA reporting timelines.
When does CIRCIA reporting become mandatory?
Reporting is required only once the final rule takes effect, on dates the rule itself sets. Until then, CISA encourages voluntary reporting, and Paubox's GAO overlap coverage explains how CIRCIA would add to the reporting stack healthcare already carries.
