HIPAA Security Rule changes: what HHS proposed for NEMT companies and what applies today
Overview
HHS proposed a stricter HIPAA Security Rule on January 6, 2025, but it is not law. No final rule has been published, and HHS lists final action for July 2027. Until then the 2013 rule governs. The proposal would require encryption, multifactor sign-in, an asset inventory and network map, 72-hour restore plans, and yearly audits.
On this page
Is the proposed HIPAA Security Rule update in effect?
No. HHS published its proposal, “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” on January 6, 2025 (90 FR 898), and comments closed on March 7, 2025. As of October 6, 2026 the Federal Register still lists only that proposal under the rule’s tracking number, RIN 0945-AA22, and no final rule has been published. HHS’s regulatory agenda files the rule under “Long-Term Actions” and gives July 2027 as the date for final action.
Until a final rule is published, the Security Rule you must meet is the 2003 text as last amended in 2013. HIPAA for NEMT providers explains what that rule asks of a transportation company, starting with the risk analysis. This page covers the proposal: what it would add, which parts touch a small fleet’s phones, dispatch logins and vendors, and what to do while it is pending.
If a final rule is published, the proposal says it would take effect 60 days later, and companies would have 180 days after that to comply, about eight months from publication. Existing business associate agreements that meet today’s rules and are not changed after day 60 would get longer: they would stay valid until the earlier of a renewal on or after day 240 or one year and 60 days after publication. The final text can differ from the proposal, so read what follows as a preview, not a checklist.
Does the Security Rule apply to a NEMT company?
It applies to covered entities and business associates, whatever their size. Under 45 CFR 160.102 a health care provider is a covered entity when it sends health information electronically in a standard transaction, and a company that handles protected health information for a covered entity is a business associate. Which one a NEMT company is depends on how it is paid and who sends it trips, and the table in HIPAA for NEMT providers walks through it. The rest of this page assumes your company is covered or is a business associate.
The proposal keeps the flexibility factors in the current rule: the company’s size, complexity and capabilities, its technical setup, the cost of a measure, and the likelihood and seriousness of the risk. What it removes is the option to skip a safeguard because it is labeled “addressable.” HHS wrote that the flexibility is in how a company meets a standard, not whether it meets it.
What would change, compared with the rule today?
The grid compares ten points between the current text and the proposed text.
| Topic | Rule today | Proposed |
|---|---|---|
| Encryption | Addressable: adopt it or document why not | Required at rest and in transit, with a few documented exceptions |
| Multifactor sign-in | Not named; a procedure must confirm who is signing in | Required on every technology asset in systems that touch rider data |
| Ending a departed worker’s access | Addressable procedures | Required, within one hour after the person’s employment or arrangement ends |
| Risk analysis | Required, no schedule | In writing, reviewed and updated at least every 12 months |
| Asset inventory and network map | Not named | In writing, reviewed at least every 12 months |
| Restoring after an outage | Disaster recovery plan, no deadline | Written procedures to restore critical systems and data within 72 hours |
| Backups | Retrievable copies, no schedule | Copies no more than 48 hours old, with a test restore at least monthly |
| Compliance audit | Periodic evaluation | Written audit of every standard at least every 12 months |
| Vendor oversight | A business associate agreement | The agreement plus the vendor’s written security verification every 12 months |
| Scans and testing | Not named | Vulnerability scans every six months and a penetration test every 12 months |
HHS says in the proposal that it would mostly write existing expectations into the text, such as the asset inventory that a thorough risk analysis already involves. It also says encryption is built into most software today and that most companies “should already have” encrypted their health information.
What would it mean for phones, tablets and laptops?
Every device that holds rider details would have to be listed, encrypted and kept patched. The proposal defines a workstation to include a server, desktop, laptop, virtual device and mobile device such as a smart phone or tablet, so a driver’s phone counts.
- Inventory. The written list would show each technology asset’s identification, version, the person accountable for it, and its location. It would be reviewed at least every 12 months and after changes such as new software, a merger or a security incident.
- Network map. A written map would show how rider information enters and leaves the company’s systems and how it is reached from outside. For a fleet, that is the path from the broker portal into dispatch, onto the driver’s phone, and out to billing.
- Encryption. All electronic rider information would be encrypted at rest and in transit. The exceptions include a device that cannot support encryption, where the company needs a written plan to move off it, a rider’s request to receive their own records unencrypted, and an emergency in which encryption is not feasible.
- Patching. Critical fixes would have to be installed within 15 calendar days of identifying the need, and high-risk fixes within 30, when a fix is available.
- Backups. Copies of rider information could be no more than 48 hours older than the live data, and the company would test a restore from a sample at least monthly and keep the results.
What would it mean for dispatch logins and former employees?
Most sign-ins would need a second factor, and a worker’s access would have to end within one hour. The proposal defines multifactor authentication as proof from at least two of three categories: something the user knows, something the user has, or a personal characteristic. It also calls for unique passwords that follow the current advice of authoritative sources.
- Departures. Access to systems and facilities where rider information is reachable must end as soon as possible and no later than one hour after the person’s employment or other arrangement ends.
- Logins at other companies. A company whose workers hold logins to another regulated company’s systems, such as a broker portal, would have to tell that company within 24 hours after a worker’s access changes or ends.
- Training. Each worker would complete security training by the compliance date and at least every 12 months, and each new hire within 30 days after first getting access. A material change to the policies triggers training within 30 days.
- Incidents. The company would keep a written incident response plan and test it at least once every 12 months.
What would it mean for vendors and broker agreements?
A company would have to collect a written security check from each vendor every year, and the vendor agreement would have to require a 24-hour warning when the vendor activates its recovery plan. For each business associate that handles rider information, the covered entity would need the agreement plus a written analysis of the vendor’s systems by a qualified person and a written certification, signed by someone with authority at the vendor, that the analysis was done and is accurate. The agreement itself would have to require the vendor to report any security incident it learns of, and to report within 24 hours if it activates its contingency plan.
A covered entity would not need that verification from a business associate that is a subcontractor. A business associate would need it from its own subcontractors. A NEMT company that works for a broker and also uses dispatch software may therefore hold both roles: it answers to the broker and expects the same from its software vendor. The business associate agreement template lists what an agreement should cover now, and HIPAA-compliant NEMT software lists what to ask a vendor.
What already changed for everyone in 2026?
Two compliance dates arrived on February 16, 2026, and both bear on a company that touches substance use treatment records. The Part 2 final rule (89 FR 12472) took effect April 16, 2024, and organizations had to comply by February 16, 2026. It applies HIPAA’s breach notification to Part 2 records and ties violations to HIPAA’s civil and criminal penalties. Rehab center transportation explains the agreement a treatment center asks a ride company to sign.
The second date covered the notice of privacy practices. The April 2024 reproductive health privacy rule (89 FR 32976) set February 16, 2026 for new notice content. On June 18, 2025 a federal court in Texas, in Purl v. HHS, vacated that rule except its changes to 45 CFR 164.520, and then vacated three of the notice paragraphs. The substance use disorder statements stay. The notice of privacy practices template shows what a notice carries today.
What should a small company do now?
Do the steps the current rule already requires, because each one also moves a company toward the proposal.
- Complete a written risk analysis. The current rule requires an accurate and thorough one, and HHS says in the proposal that doing it properly means inventorying technology assets and tracing how rider information moves. The HIPAA risk analysis template is a place to start.
- List every device and tool that holds rider details, with one named owner for each.
- Turn on a second sign-in step for email, the dispatch system, broker portals and the bank. Cybersecurity for NEMT companies covers the setup.
- Remove access the day someone leaves, including shared passwords the person knew.
- Ask each vendor for its security terms in writing, and keep the business associate agreement with them.
- Restore one backup as a test, and write down how long it took.
Insurers already ask about several of these. The cyber insurance guide lists the questions on a typical application.
Security habits in HealthRide
HealthRide is HIPAA compliant, and patient information is encrypted and protected. In the provider portal, each person sees only what their role allows, and sign-ins can use passkeys or two-step codes. Every change is recorded, and the driver app keeps rider details off the phone’s lock screen.
Frequently asked questions
- Is the proposed HIPAA Security Rule update final?
- No. HHS published the proposal on January 6, 2025, and comments closed March 7, 2025. As of October 6, 2026 the Federal Register shows no final rule under its tracking number, RIN 0945-AA22. HHS's regulatory agenda lists the rule under long-term actions with final action in July 2027. The current rule stays in force until a final one is published and its compliance date passes.
- Would the new Security Rule require multifactor authentication?
- The proposal would, with narrow exceptions. It would require multifactor authentication on every technology asset in the systems that handle electronic health information, and for any change to a user's privileges. Today the rule only requires procedures to confirm that a person signing in is who they claim to be. Final wording could differ from the proposal.
- How long would a company have to comply once a final rule is published?
- The proposal sets an effective date 60 days after publication and a compliance date 180 days after that, about 240 days in all. Existing business associate agreements that meet today's rules and are not changed after day 60 would get more time: they stay valid until the earlier of a renewal on or after day 240 or one year and 60 days after publication.
- Does the proposed rule exempt small companies?
- The proposed text does not. It applies to every covered entity and business associate, and it keeps the rule's flexibility factors: the size, complexity and capabilities of the company, its technical setup, the cost of the measure, and the likelihood and seriousness of the risk. What it removes is the choice of skipping a safeguard because it is labeled addressable.
- What HIPAA changes already took effect in 2026?
- Two with a February 16, 2026 compliance date. The Part 2 rule for substance use treatment records now applies, with HIPAA-style breach notification and penalties. Covered entities also had to update their notice of privacy practices, which a federal court left in place when it vacated the reproductive health privacy rule on June 18, 2025, except for three reproductive health items.
- What should a small NEMT company do before a final rule arrives?
- Finish the written risk analysis the rule already requires, list every device and tool that holds rider details, turn on a second sign-in step, remove former workers the same day, and ask each vendor for its security terms in writing. Each step is required or expected today and would also meet most of what the proposal asks.