Legislation Detail

Health-AI Legislation Registry

← Back to Legislation Registry

HIPAA Security Rule Update — Proposed Rule with AI Provisions

United States (Federal) | HIPAA Security Rule NPRM (RIN 0945-AA22)

Year Enacted
2025
Date Signed
N/A
Proposed rule only; comment period closed
Effective Date
N/A
Final rule timeline uncertain
Status
Pending
Proposed rule published January 6, 2025; final rule status uncertain under current administration

Categories

Other

Key Requirements

Establishes that ePHI in AI training data, algorithm data, and prediction models maintained by covered entities is protected under HIPAA. Requires entities using AI tools to include them in risk analysis and risk management activities. Would mandate multi-factor authentication, encryption, regular security testing, and 72-hour recovery capability.

Regulated Parties

HIPAA covered entities and business associates using AI to process electronic protected health information (ePHI)

Enforcement

HHS Office for Civil Rights (OCR)

Sources

Notes

First significant HIPAA update in over 10 years since the 2013 Omnibus Rule. Status uncertain under deregulatory posture.

Want full access to all legislation details?

Upgrade to a Subscriber plan for unlimited law detail views, the state map, and upcoming effective date tracking.

View Plans