The HIPAA Security Rule, 45 CFR part 164 subpart C, requires covered entities and their business associates to protect electronic protected health information through administrative, physical and technical safeguards. It applies to an AI system that creates, receives, maintains or transmits ePHI exactly as it applies to any other system, because nothing in it turns on the technology involved.
The 2025 proposal is still a proposal
A notice of proposed rulemaking to strengthen the Security Rule was issued in December 2024 and published on 6 January 2025 at 90 FR 898. It would have removed the addressable category, mandated encryption and multi-factor authentication, and required asset inventories and network maps.
It has not been finalized. As of September 2026 the operative regulatory text is unchanged since 2013, and the federal regulatory agenda classifies the rulemaking as a long-term action with final action projected no earlier than July 2027 — a slip from the earlier projection of May 2026. Any compliance plan built on the proposal as though it were in force is planning against a rule that does not exist. HHS has said plainly that the current Security Rule remains in effect while the rulemaking proceeds.
Addressable does not mean optional
This is the most misstated item in HIPAA summaries, and it matters more once AI is in the picture.
Each implementation specification is labelled in the regulation as required or addressable. A required specification must be implemented. An addressable one must be assessed to determine whether it is a reasonable and appropriate safeguard in that environment; if it is, implement it, and if it is not, document why and implement an equivalent alternative where reasonable and appropriate. Every addressable specification therefore produces a mandatory documented decision. The flexibility is in the control chosen, not in whether to decide.
Section 164.306(b) sets what that assessment weighs: the entity's size and complexity, its technical infrastructure, the cost of the measure, and the probability and criticality of the risk. Introducing a system that ingests clinical free text changes the second half of that calculation, which is what obliges a fresh assessment rather than a reference to the last one.
What applies to AI today
HHS has issued no guidance specifically addressing artificial intelligence under the Security Rule. The consequence is not that AI is unregulated but that it is governed by the existing rule with no AI-specific interpretation to lean on, so the institution's own risk analysis carries more weight rather than less.
Three practical consequences. A vendor processing ePHI is a business associate under section 164.314 whether or not the processing is AI-based. The audit controls requirement at 164.312(b) applies to AI interactions, which means a record of what was sent and returned, not only that a request occurred. And the risk analysis under 164.308(a)(1) has to cover the new path — a clinician pasting a patient note into a general-purpose assistant is a disclosure, and the control that prevents it is inline detection and redaction rather than a policy reminder. Keeping ePHI inside the perimeter removes the business associate question entirely, which is the approach set out on the healthcare page, with egress control and tamper-evident audit logs documented separately. Counsel should bless the phrasing of any compliance claim built on this.
Related terms
DLP for AI · AI sovereignty · Tamper-evident audit log · GLBA · Full glossary
Verified against the Federal Register, the eCFR and the federal regulatory agenda in September 2026. This rulemaking is live and the status above is the item most likely to change. If something here is out of date, tell us and we will correct it.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs