The federal government's newly published rulemaking agenda lays out a busy year for health privacy regulation, with two final rules expected in August and three more proposals to follow, while the long-awaited Security Rule overhaul slips to 2027.

 

What happened

The Office of Management and Budget has released its 2026 Unified Agenda, the twice-yearly document in which federal agencies state which regulations they expect to propose or finalize, and the Department of Health and Human Services (HHS) has listed an active slate of health privacy and data exchange rules for the remainder of the year. The Office for Civil Rights (OCR), the HHS division that enforces the Health Insurance Portability and Accountability Act (HIPAA), intends to finalize its update to the HIPAA Privacy Rule in August 2026, more than five years after the changes were first proposed. A second final rule, expected in the same month, would trim health information technology certification requirements. Three proposed rules follow later in the year, covering patient access timelines, electronic transaction standards, and application programming interfaces. The one conspicuous absence is the HIPAA Security Rule overhaul, which HHS moved to its long-term actions list with a target of July 2027.

 

Going deeper

The Privacy Rule final rule, listed on the HHS agenda and originally proposed in January 2021, would strengthen individuals' right to access their protected health information, improve information sharing for care coordination and case management, allow greater family and caregiver involvement in emergencies, and reduce administrative burdens on covered providers and health plans. A separate proposed rule expected in November would revisit how quickly organizations must answer patient records requests, building on an earlier proposal to shorten the response window from 30 days to no later than 15 calendar days. December brings a proposal from the Centers for Medicare and Medicaid Services to replace Version 5010 of the X12 standards, the shared technical format that insurers, providers, and clearinghouses use to exchange claims and payment information electronically, with an updated version. Two rules known as HTI-5 and HTI-6 round out the health IT side, one finalizing cuts to certification criteria and information blocking requirements in August, the practice of unreasonably interfering with the exchange of electronic health information, and one proposing new standards for application programming interfaces, the software connections that let one system pull data from another, in November.

 

What was said

"The proposed update is the most sweeping rewrite in 20 years, and OCR is juggling a huge volume of industry feedback, cost concerns and the broader deregulatory posture of the administration," said Rachel Seeger, founder of consulting firm North Country Communications and a former longtime adviser at HHS OCR, speaking to BankInfoSecurity in July 2026 about the postponed Security Rule. She predicted that further delay beyond July 2027 is the most likely scenario.

 

In the know

Placement on the long-term actions list carries meaning beyond a date change. Agencies use that category for rules they do not expect to finalize within the next twelve months, so the change from the final rule stage tells regulated entities the Security Rule rewrite has effectively been shelved for now rather than merely rescheduled. The proposal itself, issued by OCR in December 2024, would remove the flexibility that lets organizations treat certain safeguards as addressable rather than required, mandating encryption of electronic protected health information, multifactor authentication, network segmentation, and regular vulnerability testing across the sector. OCR received 4,745 public comments by its own count, and a coalition of more than 100 organizations led by the College of Healthcare Information Management Executives wrote to the HHS secretary in December 2025 urging full withdrawal, pointing to compliance costs the government itself estimated at roughly $9 billion in the first year. Nothing in the delay changes current obligations, since the existing Security Rule remains fully enforceable and OCR has continued bringing enforcement actions under it throughout the rulemaking pause.

 

The big picture

The agenda reveals where HHS is spending its regulatory energy, and for now that means patient access and interoperability ahead of new security mandates, as Fierce Healthcare reported. The risk in reading the Security Rule delay as breathing room is that the threats the proposal was written to address have not paused alongside it. Attackers do not wait for final rules, and the gaps the rewrite targeted remain widespread, with Paubox's 2026 Healthcare Email Security Report finding that 74% of breached healthcare organizations lacked proper DMARC enforcement, an email authentication standard that helps stop attackers from sending messages that impersonate an organization's domain. Organizations that use the extra time to close encryption, authentication, and email security gaps will be better positioned whether the final rule lands in July 2027, later, or in narrower form, and better protected in the meantime regardless of what regulators eventually require.

 

FAQs

Is the Unified Agenda legally binding on HHS?

No. The agenda states each agency's planning intentions, and the dates carry no legal force. Agencies routinely miss their own targets, finalize rules early, or drop planned actions entirely, which is why the twice-yearly updates are watched closely for priority shifts rather than treated as deadlines.

 

What are the current rules on responding to patient records requests?

Covered entities must act on an access request within 30 days, with one 30-day extension available if the individual is given a written explanation for the delay. OCR has made access violations an enforcement priority, resolving dozens of cases under its Right of Access Initiative since 2019, mostly through settlements with providers who ignored or slow-walked requests.

 

Do the health IT rules apply to organizations that are not HIPAA covered entities?

Yes, in part. Information blocking rules reach health IT developers and health information exchanges alongside providers, and developers of certified health IT face their own conditions of certification. Penalties differ by actor, with developers and exchanges subject to civil monetary penalties of up to $1 million per violation while providers face disincentives set through other programs.

 

Why do the electronic transaction standards matter to a practice or health plan?

The X12 standards define the exact format of claims, remittance advice, eligibility checks, and other routine transactions, so a version change touches billing systems, clearinghouse connections, and payer interfaces all at once. The last major transition, from Version 4010 to 5010 in 2012, required months of testing, and organizations that waited experienced payment disruptions.

 

Could a new administration or court ruling change these timelines further?

Yes. Rulemaking priorities shift with administrations, and finalized rules can face legal challenges, as happened when a federal court vacated the reproductive health privacy rule in 2025. Compliance teams generally treat agenda dates as signals for planning purposes and wait for publication in the Federal Register before committing to implementation work.