08/04/2026
OCR pushed the final HIPAA Security Rule to July 2027, changing it from "final rule stage" to "long-term action." For an industry bracing for a tighter deadline, that's an easy excuse to shelve the project plan.
At LuxSci, we think that would be a mistake.
The current rule already requires you to address encryption. "Addressable" has never meant "optional" — you must implement it, implement an equivalent alternative, or document why neither is reasonable. OCR's enforcement authority applies today.
Breach costs haven't waited for the rule either. The average healthcare breach now costs $7.42M, and email remains the #1 attack vector into healthcare organizations.
OCR hasn't abandoned the encryption mandate — organizations that build toward it now will be ahead regardless of when it lands.
Get the full update on the new HIPAA Security Rule in our new Definitive Guide, and what steps you should take today to be ready for the changes coming next year.
Read it here, no email required:
LuxSci HIPAA compliant email ensures secure email encryption, data protection, secure server hosting, HIPAA compliant forms and secure communication since 1999.