The federal government has pushed the finish line again. According to Reginfo.gov, the final version of the updated HIPAA Security Rule is now projected for July 2027, a year later than many compliance teams expected. The proposed requirements have not changed, so healthcare organizations that keep faxing patient records still need encryption, access controls and audit trails in place.
What Happened
The Office of Management and Budget updated its regulatory agenda in early July 2026. The new final action date for the HIPAA Security Rule amendments moved to July 2027, as first flagged by the Holland & Knight healthcare team on July 6.
The backstory is worth a quick recap. In January 2025, the Office for Civil Rights published a proposed rule to strengthen the Security Rule. It responded to a sharp rise in large data breaches, the kind affecting 500 or more patients, reported between 2018 and 2023. Provider groups pushed back hard on the cost and scope of the proposal. That criticism, plus a change in administration priorities, is why the final text keeps sliding.

What the Proposed Rule Still Asks For
Nothing in the delay softens the proposal itself. The draft rule would require:
- Encryption of electronic PHI both at rest and in transit
- Multi factor authentication on systems that touch patient data
- Incident reporting within 72 hours
- Annual penetration testing
- Tighter oversight of business associates, including fax service vendors
Enforcement of the current rule has not paused either. After the 2026 inflation adjustment, penalties run from $145 to over $73,000 per violation, with an annual cap above $2.1 million per category. A breach investigation today is judged against the rule that exists today.
Why Fax Teams Should Not Wait
Fax is still everywhere in healthcare, and it sits right in the middle of these requirements. An analog fax machine printing lab results into an open tray fails the spirit of every bullet above. A HIPAA compliant fax setup, by contrast, already checks most of the proposed boxes: transmissions travel over TLS, every user logs in with their own account, and each sent or received document leaves an audit record.
Here is the practical read. The delay buys you planning time, not a pass. Everything in the proposal also reduces your breach risk right now, which means the work pays off whether the final rule lands in July 2027 or slips again.

A Sensible To-Do List for the Next Year
You don’t need a compliance consultant to start. Move analog fax lines onto a fax server platform that encrypts traffic and stores documents behind authentication. Turn on role based access so a billing clerk and a physician don’t share one inbox. Sign business associate agreements with every vendor in your fax path. Then walk through your breach response plan once, on paper, and time how long notification would take. If 72 hours sounds tight, fix that now.
Self hosting helps here too. When the fax server runs on your own infrastructure, patient documents never sit with a third party cloud fax provider, which shrinks your business associate exposure and keeps the audit trail fully in your hands. You can see how that works in practice on our live demo.
FAQ
Did the HIPAA Security Rule update get cancelled?
No. The proposed rule from January 2025 is still active. The Office of Management and Budget simply moved the projected publication date for the final version to July 2027.
Does the delay change what I must do today?
No. The current Security Rule remains fully enforceable, and penalties were adjusted upward for inflation in 2026. Breaches are judged against today’s requirements, not tomorrow’s draft.
Is faxing patient records still allowed under HIPAA?
Yes. HIPAA permits faxing PHI when reasonable safeguards are in place. Secure fax server software with encryption, per user access and audit logging meets that bar far better than a standalone fax machine.
Will the final rule require encryption for fax?
The proposal requires encryption of electronic PHI at rest and in transit. Fax traffic that moves as email or through a fax API falls under that, so encrypted transport is the safe assumption.
What should small clinics do first?
Replace shared analog fax machines with a fax server or secure cloud fax that gives each user a login. That single change improves access control, encryption and audit coverage at once.
Related Resources
Questions about moving your fax workflow onto a secure, self hosted platform before the 2027 deadline? Open a support ticket and our team will walk you through it.
