Act now, not later: Reduce risk regardless of potential HIPAA updates.
Act now, not later: Reduce risk regardless of potential HIPAA updates.
AI raises the stakes: Strong governance, vendor oversight and BAAs are now essential.
Privacy extends beyond HIPAA: State laws are expanding consent and data control requirements.
The future of healthcare privacy is arriving before the compliance rules are finalized. Although proposed changes to the HIPAA Rule remain pending, regulators are already emphasizing many of the capabilities the updates would require. For organizations, that means compliance planning can no longer be tied solely to final rulemaking—it must begin now.
Privacy updates extend beyond HIPAA. The 2024 reproductive health privacy rule has been vacated. State consumer health data laws are expanding into new industries. Artificial intelligence is rewriting workflows faster than guidance can address it. Privacy officers cannot afford to wait for the rules to settle. The operational changes needed will take months to implement. Organizations should act now to address expected changes.
Over five years ago, the U.S. Department of Health and Human Services’ Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) to overhaul the HIPAA Privacy Rule. To date, that rule has not been enacted; however, with the administration’s 2026 Unified Agenda, the updates have moved one step closer to finalization. The specifics below should be treated as a forward-looking roadmap, not as current law.
The NPRM aims to, if finalized as drafted:
OCR is already evaluating healthcare organizations against expectations aligned with the NPRM, especially around patient access and the ability for patients to integrate third-party apps with their medical record.
In April 2024, HHS finalized a Privacy Rule extending special protections to reproductive health information, including a required attestation form for certain disclosures. In Purl v. HHS, the U.S. District Court for the Northern District of Texas vacated nearly all of the rule nationwide on June 18, 2025, and HHS declined to appeal. The Fifth Circuit closed the matter in September 2025. As of May 2026, the rule is not in effect.
For covered entities right now:
Many compliance teams put significant effort into the 2024 rule. Some organizations have not yet rolled back the related operational changes. That creates a potential, low-hanging operational risk that may be easy to overlook. Revisit it now.
HIPAA was built on assumptions that AI does not follow. For instance, the rule assumes data lives in identifiable systems, that access can be logged and explained, and that records can be deleted or controlled in predictable ways. AI, however, complicates each of these. Data flows through prompts, APIs, models and outputs. Model unlearning, the technical ability to remove a record's influence from a trained model, remains an unsolved research problem.
There is also an immediate operational risk related to the use of AI under HIPAA regulations. For example, a single prompt entered into the wrong system can constitute a reportable disclosure. Well-meaning employees may be using AI tools without fully understanding outcomes and consequences.
Regarding the use of AI, the regulatory response is fragmented:
OCR has not issued an AI-specific HIPAA rule. It has signaled that HIPAA applies to AI like any other technology, with particular concern for data leakage, data poisoning and the absence of BAAs with AI vendors.
The Office of the National Coordinator (ONC) for Health Information Technology HTI 1 Final Rule introduces transparency requirements for predictive decision support tools.
OCR's section 1557 guidance addresses AI-driven nondiscrimination and imposes additional obligations effective May 1, 2025.
In addition, telehealth can further compound complexity. When AI is embedded into telehealth workflows, each feature becomes another point of exposure. Organizations that establish AI governance processes now, including tool inventories, vendor oversight and data flow analysis, will be better positioned to comply with future privacy requirements and current enforcement expectations. In many cases, the controls needed to manage AI risk overlap with the capabilities regulators are increasingly focusing on across the healthcare industry. AI does not sit outside HIPAA. It can multiply the number of ways organizations can fail within it.
HIPAA protects health information only within covered entities and business associates. It does not extend to the same information when it is obtained from consumers and lives in apps, devices or platforms. States are actively closing this gap, however.
Washington's My Health My Data Act applies broadly, defines health data expansively, requires opt-in consent, grants deletion rights and allows for private lawsuits. The first class action under the law was filed against Amazon in February 2025 and is now testing what qualifies as consumer health data. Nevada's SB 370 and Connecticut's SB 3 amendments are also in effect. New York's Health Information Privacy Act passed both chambers in January 2025 but was vetoed later that year, then reintroduced in 2026. These laws are not incremental. They pull companies into health privacy regulations even if they do not operate in traditional healthcare delivery.
Retailers, app developers and ad tech companies are now subject to these requirements whether they anticipated it or not. Vendors serving healthcare clients often lift their highest control standards across their customer base, extending HIPAA-inspired expectations outward and becoming the baseline for "reasonable security."
HIPAA allows data use for treatment, payment and operations without explicit permission each time. Consumer health laws require affirmative, purpose-specific consent. These models do not align. Organizations now operate under both simultaneously, however. Clinical systems follow HIPAA. Apps and digital platforms require opt-in consent. The legal distinction is clear. The systems are not, which is where compliance breaks down in practice.
Consent must be tracked at a level most systems were never designed to support:
In theory, this is manageable, but in practice, most environments cannot support this level of tracking with confidence. AI can compound the problem. When data influences a model, removing the record is straightforward. Removing its effect is not.
Now through the end of 2026 (before a final Privacy Rule), organizations should consider the following:
When the Privacy Rule updates are published:
Ongoing:
HIPAA remains important and is becoming stricter. It no longer defines the full privacy landscape. A single incident can now trigger action from federal regulators, state attorneys general and private plaintiffs simultaneously. Privacy is no longer about meeting one framework. It is about managing risk across overlapping systems that continue to evolve.
Healthcare organizations should use this period to strengthen patient access capabilities, evaluate AI-related risks and align privacy programs with emerging enforcement priorities. Those that act now will be better positioned regardless of rule updates and, more importantly, to navigate the evolving intersection of healthcare privacy, technology and patient trust.
RSM US MMBI