HIPAA Security Rule overhaul · Final rule delayed to 2027

Five HIPAA safeguards just became mandatory. Are you covered?

A five-part bundle — GRC-as-a-Service, vCISO-as-a-Service, Vulnerability Management, Managed SIEM, and Backup/Disaster Recovery — built to cover every mandate in HHS's incoming HIPAA Security Rule overhaul, for regional health systems, payers, and health tech running lean security teams.

MFA now mandatory
Encryption at rest & in transit
2x/yr vuln scans + annual pen test
72-hr disaster recovery
Live asset & network inventory
Request Your Free Assessment
What's changing

Applies to every regulated entity — regardless of size.

HHS's Office for Civil Rights published its HIPAA Security Rule overhaul as a Notice of Proposed Rulemaking in January 2025, replacing today's flexible "addressable" standard with strict, non-negotiable controls for every provider, payer, and business associate — no exemption for smaller practices. Push-back over cost and implementation timelines led HHS to delay final action to 2027, but the direction is set. The current Security Rule remains fully enforceable in the meantime — waiting for the final rule to start preparing is starting too late.

445
Ransomware incidents against healthcare providers in 2025
69%
Of stolen patient records industry-wide, from just 11% of breaches
$7.42M
Average healthcare breach cost — highest of any industry, 14 years running
2027
Target for the finalized HIPAA Security Rule overhaul
The overhaul, in plain terms

Five safeguards move from optional to mandatory.

Once finalized, the HIPAA Security Rule overhaul enforces these five previously "addressable" safeguards for every regulated entity — provider, payer, or business associate. Here's what's coming, and which CYBREX service line covers it.

1
Multi-Factor Authentication
Mandatory across every system and platform that accesses electronic protected health information (ePHI).
Covered by: GRC-as-a-Service + vCISO
2
Data Encryption
Strict requirements for all ePHI, both at rest and in transit — no more case-by-case exceptions.
Covered by: GRC-as-a-Service (HIPAA)
3
Technical Testing
Vulnerability scanning twice yearly, plus penetration testing annually.
Covered by: Vulnerability Management-as-a-Service
4
Asset Tracking
Live inventories of every network-connected device and application, plus network maps showing data flows.
Covered by: Managed SIEM (Microsoft Sentinel)
5
Disaster Recovery
Testable procedures to restore systems and data within 72 hours.
Covered by: Backup & Disaster Recovery-as-a-Service

Source: HHS Office for Civil Rights Notice of Proposed Rulemaking (Jan. 2025, Federal Register); final-rule timeline per industry legal reporting (targeted 2027). The current HIPAA Security Rule remains fully enforceable today.

The bundle

Six services. One accountable partner.

CYBREX's Regulated Healthcare Bundle is delivered as coordinated, subscription SKUs — compliance, leadership, testing, monitoring, and recovery — so nothing falls into the gap between a consultant's report and day-to-day operations.

1
Free Intro
HIPAA Security Risk Assessment
A no-cost, scored evaluation across Identity, Device, Network, App & Data, mapped to HIPAA Security Rule safeguards.
→ scored report · 3 quick wins
2
GRC-MFA / MFR / MFM
GRC-as-a-Service (HIPAA)
Gap assessment, remediation roadmap, and continuous compliance monitoring — including the incoming MFA and encryption mandates.
→ gap matrix · remediation roadmap
3
GRC-VCISO
vCISO-as-a-Service
A named, subscription fractional CISO — monthly steering, policy program, and board-level risk reporting.
→ monthly steering · board reporting
4
CYB-VMS
Vulnerability Management-as-a-Service
Recurring scanning and executive reporting, scaled to the incoming twice-yearly-scan / annual-pentest requirement.
→ scan cadence · pen-test coordination
5
CYB-SIEM
Managed SIEM (Microsoft Sentinel)
Continuous threat detection plus the asset and network visibility the new rule requires, with a clear path to 24/7 MDR.
→ continuous detection · MDR-ready
6
DPR-BAAS / DRAAS
Backup & Disaster Recovery-as-a-Service
Managed backup with monthly restore testing and DR runbooks built to a 72-hour recovery window.
→ tested restores · 72-hr runbooks
Outcome A defensible, board-ready HIPAA compliance program — sustained, not one-time.
What you walk away with

Artifacts your board and your auditors can both use.

Assessment
HIPAA Security Risk Assessment
Scored evaluation across all five NIST-aligned pillars, with prioritized quick wins.
Documentation
Control Gap Matrix
Framework-mapped gaps against MFA, encryption, asset tracking, and disaster recovery mandates.
Remediation
POA&M to Closure
Tracked plan of action with evidence captured as each gap is closed.
Testing
Vulnerability & Pen Test Reports
Recurring scan results and annual penetration-test findings, built to the incoming cadence.
Visibility
Live Asset Inventory & Network Map
A current inventory of network-connected devices and applications, with data-flow diagrams.
Leadership
Monthly Board Reporting
vCISO-authored risk reporting your board and compliance committee can act on.
Recovery
Tested 72-Hour DR Runbook
Restore procedures tested against the incoming 72-hour recovery requirement, not just documented.
HIPAA Security Rule safeguard categories, in scope
MFA Multi-Factor Authentication ENC Encryption at Rest & Transit VM Vulnerability & Pen Testing AST Asset & Network Inventory DR Disaster Recovery (72-hr) ADM Administrative Safeguards PHY Physical Safeguards AUD Audit Controls BAA Business Associate Oversight RA Risk Analysis
Why CYBREX for healthcare

We've run the programs. We're not describing them.

Proven monitoring and vulnerability managementA live 16-source Microsoft Sentinel SIEM migration and a running Tenable Nessus vulnerability-management program with weekly executive reporting — not a theoretical capability.
Compliance methodology that transfersThe same Assess / Remediate / Sustain discipline built for CMMC Level 2 readiness, applied to HIPAA and CMS obligations.
Local, accessible, DMV-basedBethesda, MD-based with WBE/MBE certification — an in-person partner for regional health systems, not an offshore ticket queue.
Senior-led deliveryCISSP- and PMP-credentialed staff with active federal clearance-level rigor, applied to commercial healthcare programs.
Built for regulated healthcare

Credentials that clear the room.

Live Sentinel SIEM Migration
Tenable-Powered Vulnerability Management
HIPAA / CMS Scoped GRC
MBE / WBE · CAGE 197K0
CISSP · PMP · Secret Clearance
Bethesda, MD · DMV Regional
We don't just write the policy. We've run the SOC.

Advisor and practitioner, in the same firm.

Start here

Get your free HIPAA Security Risk Assessment before the rule is final.

Would you like to receive periodic updates on healthcare cybersecurity and HIPAA compliance from CYBREX? CYBREX will process your personal data in accordance with our Privacy Policy.

No cost. No obligation. Scored report delivered within 5 business days.

CYBREX
HEALTHCARE CYBERSECURITY & COMPLIANCE · GRC / VCISO / VMS / SIEM / BACKUP-DR · CYBREXAI.COM