<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1611884&amp;fmt=gif">
Marita Scarfi 04/15/2026
3 Minutes

The HIPAA Security Rule overhaul, which strengthens electronic protected health information (ePHI) through multi-factor authentication (MFA), has slipped its expected finalization date - originally targeted for spring 2026 - to July 2027 at the earliest, according to HHS’s latest regulatory agenda.

These updates to the HIPAA Security Rule are meant to strengthen identity verification requirements under 45 CFR § 164.312 (Authentication) to better protect against credential-based attacks and unauthorized access.

Organizations (covered entities and business associates) would be required to implement MFA to better protect the confidentiality, integrity, and availability of ePHI. MFA uses at least two of the following:

  • Something you know (password)
  • Something you have (device, token)
  • Something you are (biometric)

Are you confident your onboarding flow will meet the tightened HIPAA Security Rule requirements?

The Real Timeline: Why Your Compliance Design Starts Now

Even with final action now pushed to July 2027 — and realistic full compliance likely landing in 2028 — the mechanics still favor early movers. Once the rule is finalized, the Department of Health and Human Services (HHS) is likely to give organizations only 60 days after approval to reach the effective date, then 180 days after that to the compliance deadline. This means compliance and security teams should treat this as design work that starts now — asset mapping, workflow review, and vendor exception planning gives you room instead of a scramble.

The proposal drew more than 4,000 public comments, with pushback on implementation costs, operational feasibility, and the burden on smaller and rural providers — much of which helps explain the delay. Right now, it’s still a proposed rule, and current HIPAA Security Rule requirements stay in effect.

Today’s HIPAA Security Rule already requires organizations to verify that a person or entity seeking access to ePHI is who it claims to be, but the updates would make that expectation much more explicit.

Regulated entities would be required to deploy MFA across all technology assets in relevant electronic information systems and for any action that changes user privileges in a way that could affect the confidentiality, integrity, or availability of ePHI.

In multi-factor authentication, the two factors must come from different categories. A password and a security question both count as 'something you know,' so pairing them doesn't meet the requirement.

Preparation: Proactive Steps and Key Exemptions

What are proactive healthcare security teams doing now to prepare?

  • Mapping how ePHI moves through their environment
  • Identifying patient-facing workflows
  • Noting where privileged access exists
  • Reviewing MFA steps to ensure they meet the definition

HHS’s proposed MFA definition is also broader than many teams assume: It includes knowledge, possession, and physical or behavioral characteristics, which means healthcare teams should evaluate workflow-friendly options beyond basic text codes and phone prompts.

HHS is allowing exceptions for those with a plan in place, proposing:

  • Limited exceptions when a technology asset does not support MFA, but only if the organization has a written migration plan to move ePHI to a technology asset that does.
  • Exceptions for emergencies or other occurrences where MFA is infeasible, as long as reasonable compensating controls are in place under emergency access and contingency procedures.

Additionally, HHS proposes annual written verification of technical safeguards from business associates, making these requirements an issue of governance, architecture, and vendor-management.

Solving the Identity-Proofing Problem at Enrollment

MFA is only as strong as the identity behind the credential enrollment, account recovery, or other high-risk access event. Vouched’s Identity Verification platform is built to address this potential weakness.

Our workflows combine government ID verification, biometric selfie comparison, liveness checks, and real-time fraud detection to confirm that the person on the other end is present and matches the credential. The platform can return results in seconds behind the scenes, integrating into digital onboarding flows.

For healthcare organizations, the fit is especially strong in patient onboarding, portal enrollment, and account recovery – exactly where weak identity proofing can quietly undermine an otherwise solid MFA program.

Additionally, Vouched is now available in the Epic Toolbox for identity verification. This gives health systems standards-based, consumer-grade identity proofing alternative for MyChart account creation and recovery.'

Because the proposed rule covers privileged and staff access changes as well as patient enrollment, that maps directly to where MFA programs most need verified identity.

Already stretched support teams can achieve stronger identity assurance without adding friction for patients.

The identity-proofing solutions provided by Vouched close gaps left open by many MFA rollouts, which may only be discovered downstream: Proving who the person really is at enrollment. Effective identity-proofing is becoming a legitimate compliance advantage as HIPAA moves toward explicit MFA requirements.

Stay ahead of the HIPAA MFA changes

The rule isn’t final yet, but the design work starts now. Get updates as the timeline moves, and talk to our team about closing the identity gap in your MFA program.

Connect with sales to see how Vouched fits your onboarding, portal enrollment, and account recovery workflows.

Request a demo

 


Tag: