This week, Health-ISAC®’s Hacking Healthcare® examines evidence that the HIPAA Security Rule effort launched at the end of the Biden administration may be moving ahead under the Trump administration, and that the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) might miss its October deadline by more than a few months.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
PDF Version: TLP WHITE Hacking Healthcare 8.28.2025
Size : 530.9 kB Format : PDF
Text Version:
Welcome back to Hacking Healthcare®.
Evidence Suggests New Dates for HIPAA Security Rule and Cyber Incident Reporting
U.S. presidential administration transitions often begin with months of policy reviews and reversals as the new administration rushes to enact its own policy vision. The first months of the second Trump administration have been no different, but they have thrown two important cybersecurity efforts into question. While there has been very little official news on the progress of the HIPAA Security Rule Proposed Rule that the Biden administration published in early January, or the long running effort by the Cybersecurity and Infrastructure Security Agency (CISA) to complete the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Final Rule, we may now have some evidence about what to expect and when.
HIPAA Security Rule Recap
As many are aware, over the past few years, there has been significant support for updating the HIPAA Security Rule to account for changes in technology and the cyber threat landscape. That support materialized in the last weeks of the Biden administration as the Department of Health and Human Services (HHS) published a fairly substantial proposed Rule.
However, the change in presidential administration in January, which included a lengthy pause and review of Biden-era policies, cast doubt on the fate of the proposed update. HHS under the Trump administration has not been vocal about what it plans to do with the HIPAA Security Rule, leaving uncertainty over whether it might continue with the Biden era proposal with minimal modifications, heavily revise it to better align with Trump administration goals, or put it on indefinite hold since there is no legal obligation to update the Rule.
New Evidence of Ongoing Efforts
At the time of writing, HHS has not publicly commented on the status of its HIPAA Security Rule effort. However, new evidence suggests there are still plans to move forward with it.
So where does this evidence come from?
Within the Office of Management and Budget (OMB), there is the Office of Information and Regulatory Affairs (OIRA), and within the General Services Administration (GSA) is the Regulatory Information Service Center (RISC). These two offices coordinate to publish the Unified Agenda of Federal Regulatory and Deregulatory Actions (“Unified Agenda”). This agenda “provides uniform reporting of data on regulatory and deregulatory activities under development throughout the Federal Government, covering approximately 60 departments, agencies, and commissions.”[i] Generally included in the agenda are activities that are “currently planned to have an Advance Notice of Proposed Rulemaking (ANPRM), a Notice of Proposed Rulemaking (NPRM), or a Final Rule issued within the next 12 months.”[ii]
The agenda is generally compiled and published twice a year, once in the Spring and once in the Fall. While the Trump administration did not publish a Spring update, two weeks ago, an update briefly appeared on the Unified Agenda webpage that looked to be the expected Fall 2025 update. However, the update was quickly taken down, and the Unified Agenda webpage reverted to the prior Fall 2024 version. Before that reversal could be completed, Bloomberg Law reportedly noticed and took screen captures of the apparent Fall 2025 Unified Agenda.[iii] These captures included what appear to be updates to the existing HIPAA Security Rule and the CIRCIA agenda entries.
While Unified Agenda entries are fairly basic in terms of content, Bloomberg’s screen captures suggest that HHS is targeting a HIPAA Security Rule Final Rule around May of next year, and CISA will miss the October CIRCIA deadline, pushing it to mid-2026 as well.[iv]
To be absolutely clear, while this “leak” is compelling, we urge members to be prudent in assessing its veracity, and no one should confuse this with an official confirmation of policy decisions by either HHS or CISA. Under the assumption that it is accurate, let’s dig into what to make of this new evidence in the Action & Analysis portion of this week’s Hacking Healthcare.
Action & Analysis
**Included with Health-ISAC Membership**
[i] https://www.reginfo.gov/public/jsp/eAgenda/UA_About.myjsp
[ii] https://www.reginfo.gov/public/jsp/eAgenda/UA_About.myjsp
[v] https://www.regulations.gov/docket/HHS-OCR-2024-0020/comments
[vi] https://www.reginfo.gov/public/jsp/eAgenda/UA_About.myjsp
- Related Resources & News
- New critical infrastructure cybersecurity framework features government, regional council options
- Frontier AI in the Health Sector: Managing Supply Chain and Vendor Risk
- The State of Enterprise Cyber Crisis Readiness (report)
- Human Risk Management 90-Day Playbook
- Cybercriminals Flock to Healthcare Businesses as Attacks Surge
- DHS Revives Critical Infrastructure Threat Sharing, Without the Legal Shield Industry Wants
- Healthcare’s Governance Needs To Speed Up To Combat Unsanctioned AI Usage
- Monthly Newsletter – July 2026
- Healthcare Cybersecurity in an Era of Geopolitical Instability
- Health-ISAC AAMI eXhange Interview – Medical Device Security
