The federal government has pushed the HIPAA Security Rule overhaul, including its mandatory encryption requirement for electronic protected health information, from a targeted May 2026 final rule to July 2027, with the rulemaking reclassified as a long-term action while regulators work through more than 4,700 public comments. That delay changes your compliance deadline. It changes nothing about your exposure. IBM's 2025 Cost of a Data Breach research puts the average healthcare breach at $7.42 million, the highest of any industry, and the PHI moving through your email, collaboration tools, and AI workflows today is governed by the rule as it exists now, not the rule as proposed.

The temptation across healthcare IT is obvious. A deadline that moves out eighteen months looks like permission to shelve the project. That reading gets the situation backwards, for a reason buried in the rule's own history. The "addressable" encryption standard that the proposal would eliminate was never optional in the first place. Organizations treating the delay as a reprieve are deferring work that current enforcement already expects of them.

Key Takeaways

  • The HHS Office for Civil Rights moved its HIPAA Security Rule update, which would make encryption of ePHI mandatory in transit and at rest, from a targeted May 2026 final rule to July 2027, reclassifying it as a long-term action.
  • The current rule's "addressable" encryption standard was never optional. It requires covered entities to implement encryption, implement an equivalent alternative, or document in writing why neither is reasonable, and OCR enforces that today.
  • Healthcare remains the most expensive industry for data breaches, at an average of $7.42 million per incident according to IBM's 2025 research, and PHI now moves through AI tools and agent workflows the original rule never contemplated.
  • Organizations that build toward the proposed standard now, covering encryption, access governance, audit trails, and AI-aware content controls, will be secure regardless of when or in what form the final rule lands.

A patient record sealed inside an encryption shell, with its deadline far in the distance.

What Changed, and What Only Looks Like It Changed

The January 2025 proposed rule is the most significant rewrite of the HIPAA Security Rule in more than two decades. It eliminates the distinction between "required" and "addressable" implementation specifications, making encryption of ePHI at rest and in transit mandatory for every covered entity and business associate. It adds multi-factor authentication requirements, asset inventories, and tighter business associate oversight. The updated federal regulatory agenda now shows a July 2027 timeline, and the rulemaking has been downgraded from final rule stage to long-term action.

So the mandate is delayed. Here is what is not delayed. The existing Security Rule still requires every covered entity to address encryption. "Addressable" has a precise regulatory meaning that most organizations have never internalized. You must implement the safeguard, implement a documented equivalent, or produce a written analysis of why neither is reasonable for your environment. Few organizations have that documentation in defensible shape, and OCR's enforcement authority over it did not move to 2027. Kiteworks maintains a thorough breakdown of the Security Rule's current requirements and the pending updates for teams that need the baseline.

The practical translation is that the delay buys time to do the work properly. It does not buy time to not do the work.

The Breach Data Is Not Waiting for the Rule

Regulatory timelines and attacker timelines have nothing to do with each other. Healthcare has held the top position for breach costs for over a decade, and email remains one of the most reliable attack paths into a healthcare organization. Every month of deferred encryption work is another month in which a single misdirected message or compromised mailbox can turn into a seven-figure incident and a public breach notification.

Encryption also carries a benefit that too few compliance teams price in. Under the HITECH breach notification framework, properly encrypted ePHI that is lost or stolen generally does not trigger notification obligations, because the data is unusable to whoever took it. That safe harbor exists today, under the current rule, regardless of what happens in 2027. Kiteworks covers the mechanics in its guide to AES-256 encryption and the HIPAA breach safe harbor, and the broader requirements in its overview of HIPAA encryption for ePHI.

The arithmetic favors acting early. The cost of encrypting PHI channels is a project budget. The cost of not encrypting them is a probability-weighted $7.42 million, plus the notification, the OCR investigation, and the plaintiffs' bar.

The Rule Was Written for Email. Your PHI Now Moves Through AI.

Here is the part of this story that the compliance calendar misses entirely. The Security Rule update was drafted for a world where PHI moves through email, file transfers, and electronic health record systems. By the time the final rule lands in 2027, a meaningful share of PHI will also be moving through generative AI tools, Microsoft 365 Copilot sessions, and autonomous agents retrieving records from clinical and administrative data stores.

That shift creates exposure the proposed rule barely begins to address. An AI assistant summarizing a patient complaint, an agent drafting a prior authorization appeal, a Copilot query that pulls a care plan into a document, all of these move PHI in and out of systems that were never mapped in a risk analysis. Worse, AI can create new PHI by inference, generating diagnostic conclusions that never existed in any source record. We examined this dynamic in The Executive Guide to HIPAA Compliance in the GenAI Era, and the agent-specific version in HIPAA Has a Term for What AI Agents Do by Default. It's Called Overexposure.

The core issue is the minimum necessary standard. HIPAA requires that uses and disclosures of PHI be limited to the minimum necessary for the purpose. Humans violate it occasionally. AI agents violate it by default, because retrieval systems are built to be generous. Ask an agent about one patient's billing dispute and it may retrieve the full account history, adjacent records, and whatever else scored well in the search. Most tools ask what an agent is configured to do. Bonfy asks what data is actually flowing through it. For PHI, that question is the difference between a compliant workflow and a reportable incident, which is why we built enforcement that applies minimum necessary logic inside AI workflows, as described in Teaching AI 'Minimum Necessary'.

A healthcare organization planning its 2027 compliance program around email encryption alone is preparing for the last war. The defensible posture covers the channels the rule names and the AI channels it does not, under one policy model.

What a No-Regrets PHI Program Looks Like

The useful property of the proposed rule is that nothing in it is wasted effort even if the final version softens. Four workstreams qualify as no-regrets moves, meaning they satisfy current obligations, anticipate the mandate, and reduce breach exposure on their own merits.

Inventory where PHI actually moves. Not where policy says it moves. That means email, managed file transfer, patient forms, SFTP feeds to payers, Slack and Teams conversations, and every AI tool with access to clinical or administrative content. Healthcare trust boundaries are more complicated than PHI labels suggest, a point we developed in Trust Boundaries Look Different in Every Industry.

Encrypt the channels that carry it, with governance attached. Encryption without access control and audit logging satisfies neither the current rule nor the proposed one. The standard to build toward is encrypted, policy-governed exchange with immutable audit trails, the model Kiteworks describes for HIPAA-compliant email carrying PHI and HIPAA-compliant file sharing and collaboration.

Close the documentation gap now. If your organization relies on the addressable standard, the written analysis defending your encryption decisions should exist today, because an OCR investigator can ask for it today. Audit trail discipline is part of the same posture, covered in Kiteworks' guide to HIPAA audit trail requirements.

Extend minimum necessary enforcement to AI. Classify content contextually as it moves through outbound email, collaboration tools, and AI retrieval paths, and block or remediate PHI flows that exceed the purpose at hand. The risks of generative AI drafting outbound messages are concrete and current, as we outlined in the hidden dangers of using GenAI for outbound emails.

On that last workstream, the division of labor between Bonfy and Kiteworks is deliberate. Bonfy provides inline, context-aware classification and enforcement on PHI in motion, including what AI clients and agents retrieve and generate mid-task. Kiteworks provides the governed exchange layer, the encrypted channels, access controls, and unified audit evidence that OCR investigations and the proposed rule both demand. One policy model for data in motion, at rest, and in use, applied to clinicians, administrators, and AI agents alike.

Use the Runway. Don't Waste It.

The July 2027 date will arrive faster than any healthcare IT roadmap wants it to, and the final rule may yet change shape. What will not change is the direction. Encryption moves from addressable to expected. AI moves from pilot to infrastructure. And PHI keeps flowing through more channels than any point solution can see.

The organizations in the strongest position next year will be the ones that treated the delay as runway, not reprieve. They will have their PHI inventory done, their channels encrypted and governed, their documentation defensible, and their AI workflows under the same minimum necessary discipline as their humans. None of that work waits well. All of it compounds.

FAQs

1. When does the new HIPAA Security Rule take effect?

The HHS Office for Civil Rights had targeted May 2026 for a final rule. The updated federal regulatory agenda now shows July 2027, with the rulemaking reclassified from final rule stage to long-term action while OCR works through more than 4,700 public comments on the January 2025 proposal. The timeline could move again, in either direction.

2. Is encryption of ePHI optional until the new rule is final?

No. The current Security Rule classifies encryption as an addressable implementation specification, which requires covered entities to implement it, implement a documented equivalent alternative, or document in writing why neither is reasonable. Organizations without encryption and without that written analysis are out of compliance under the rule as it stands today. Kiteworks' overview of HIPAA encryption requirements covers what the current standard expects.

3. Does encrypted PHI still trigger breach notification if it is stolen?

Generally no. Properly encrypted ePHI falls under the breach notification safe harbor, because the data is considered unusable, unreadable, and indecipherable to unauthorized persons. This is one of the strongest practical arguments for encrypting now rather than waiting for the mandate.

4. How do Bonfy and Kiteworks divide the work for HIPAA compliance?

Kiteworks supplies the governed exchange layer, encrypted email and file sharing, access controls, and the immutable audit trails that demonstrate compliance to OCR. Bonfy supplies the content intelligence layer, contextually classifying PHI as it moves through email, Microsoft 365, Slack, and AI workflows, and enforcing minimum necessary limits on what humans and AI agents send, retrieve, and generate. Together they give a healthcare organization one policy model across traditional channels and AI channels, as described in Teaching AI 'Minimum Necessary'.

5. Do you need both, or does one replace the other?

They solve different halves of the same problem. Encrypted, governed channels without content-aware inspection cannot catch PHI that is overexposed inside an approved workflow, and content inspection without governed channels leaves the exchange layer itself unprotected and unauditable. Healthcare organizations facing both the encryption mandate and AI adoption generally need the combined model.

6. Does the proposed rule say anything about AI?

Not meaningfully. The proposal focuses on encryption, multi-factor authentication, asset inventories, and business associate oversight. The minimum necessary standard, however, applies to PHI regardless of what technology moves it, which means AI tools and agents handling PHI are already inside HIPAA's scope today, even though the Security Rule text barely mentions them.

Get Ahead of the Mandate

If your PHI flows are not inventoried, encrypted, and governed across both traditional and AI channels, the 2027 delay is the best gift your compliance program will get this decade. Use it. Schedule a Bonfy demo to see contextual PHI enforcement inside your email, Microsoft 365, and AI workflows, and explore how Bonfy protects healthcare organizations, before OCR or an attacker finds the gaps first.

Gidi Cohen, VP Product, Kiteworks

Gidi Cohen is the co-founder of Bonfy.AI, now part of Kiteworks, where he leads product for AI-native content security. He has spent two decades building security analytics and risk management platforms, including as founder of Skybox Security.