HIPAA Security Rule (proposed)
Published September 18, 2026
What changed
Fact. Named instrument, date, jurisdiction. Cited.
On January 6, 2025, HHS Office for Civil Rights published a Notice of Proposed Rulemaking in the Federal Register (90 FR 898) to revise the HIPAA Security Rule. OCR issued the NPRM on December 27, 2024. It is proposed. The current Security Rule remains in effect until a final rule exists.
Among other changes, the NPRM would remove the distinction between required and addressable implementation specifications, require encryption of electronic protected health information at rest and in transit, and require multi-factor authentication, with limited exceptions.
Why it matters for veterans
Stakes in plain language. If we interpret, we say so.
The proposed rule would raise the federal floor for how electronic health information is protected. Veterans' records are what that floor is meant to protect. Until a final rule exists, the current Security Rule is what applies.
LastVet's position
The stance.
The proposed rewrite of the HIPAA Security Rule raises the federal floor for protecting health data, turning protections that were once optional, like multi-factor authentication and encryption everywhere, into requirements. For a lot of the industry this is a scramble. For LastVet it is not, because we did not build to a floor. We built from the individual.
When you start by asking what a veteran is owed over their own record, strong protection is not a compliance line you rise to meet later. It is the premise. So the protections the proposed rule would require are ones we treat as baseline, not aspiration.
Our position is that the real work of this rule is not technical. It is a change of posture. For years, too much of the industry treated data security as a way to protect the institution, its liability, its reputation, its exposure, rather than to protect the person whose data it is. The rising floor forces a reckoning that should never have been optional: individual privacy and individual control come first. Institutions that took that seriously from the start have little to adjust. Those that did not now have to catch up to a standard they should have held all along.
What we're doing
Dated actions only.
- 2026-09-15. Database-level access controls are enforced on sensitive record data. Those controls are real and in use, and do not yet apply uniformly to every class of stored data.
- 2026-08. Sensitive data is encrypted at rest and in transit using strong, standard encryption. Encryption covers specific classes of data, not yet every table.
- Production runs on dedicated, single-tenant infrastructure we control, with secrets held in a managed secrets vault. The Security Rule NPRM stays labeled proposed. Current HIPAA posture is the
/compliancestatement, not a claim that the proposed rule is already met.