RealCyberNews

Free self-assessment

HIPAA Security Rule 2027 Readiness Checklist

Share

This rule is not final yet. HHS's Office for Civil Rights proposed these changes in January 2025. As of this writing, the final rule is targeted for around July 2027 on HHS's own regulatory agenda, with roughly 240 days to comply after that — and the timeline has already slipped once. Nothing here is legal advice; treat this as a directional self-check, not a compliance certification, and confirm current status atHHS.gov. Citations reference the standard each proposal amends — exact subparagraph numbering may shift before the rule is finalized.

35 questions across 14 HIPAA Security Rule categories, each citing the specific standard it maps to. Answer honestly; nothing here is saved or sent anywhere until you choose to download a report.

Security Management Process

45 CFR §164.308(a)(1)

Assigned Security Responsibility

45 CFR §164.308(a)(2)

Workforce & Access Management

45 CFR §164.308(a)(3)–(a)(4)

Security Awareness & Training

45 CFR §164.308(a)(5)

Security Incident Procedures

45 CFR §164.308(a)(6)

Contingency Planning

45 CFR §164.308(a)(7)

Evaluation & Compliance Audits

45 CFR §164.308(a)(8)

Physical Safeguards

45 CFR §164.310

Access Control

45 CFR §164.312(a)

Audit Controls & Integrity

45 CFR §164.312(b)–(c)

Encryption

45 CFR §164.312(e) — proposed standalone encryption standard

Vulnerability & Patch Management

Proposed new technical safeguard requirement

Organizational Requirements & Business Associates

45 CFR §164.314

Policies, Procedures & Documentation

45 CFR §164.316

Report attribution (optional)

Printed on your downloaded report only. Stays in your browser — never sent or stored anywhere.

Sources