
In July 2025, UnitedHealth Group sent state attorneys general its final tally for the Change Healthcare breach: 192.7 million people, nearly double the initial estimate and the largest healthcare data breach ever reported to federal regulators [R2]. Five months later, Washington withdrew a stack of health IT regulations and proposed cutting 34 more certification criteria [R11]. If you own healthcare software compliance — and if you run engineering at a healthcare company, you now do — only one of those two numbers should change how you build.
Key takeaways
One definition before the argument, because the term is about to change meaning:
Healthcare software compliance is the work of making sure software that handles patient health information meets the federal and state security and privacy rules that govern how that data is stored, accessed, and shared.
On paper, federal healthcare IT regulation spent late 2025 moving in one direction: backward. On December 22, ASTP/ONC withdrew the remaining non-finalized HTI-2 proposals (USCDI v4 adoption, encryption standard updates, public health data exchange) and proposed a deregulatory HTI-5 rule that would remove 34 certification criteria while adding "autonomous artificial intelligence" to the definitions of access, use, and exchange [R11]. Meanwhile the HIPAA Security Rule update stalled. As of mid-2026, no final rule has been issued [R10]. OMB's Unified Agenda now targets July 2027 for final action, pushed back from spring 2026 [R10]. That's a target on a regulatory agenda, not a commitment.
The comfortable read is that you've been handed two extra years. Compliance budgets can wait, the MFA rollout can slip a quarter, the encryption-at-rest project can stay in the backlog. That read confuses the pace of rulemaking with the pace of risk. Nothing in the HTI-2 withdrawal changed what a breach costs you, what OCR enforces today, or what state laws already demand. The regulatory bar paused. The actual bar — the one your incident-response retainer and cyber-insurance renewal are priced against — kept climbing. The rest of this post is about the gap between the two.
The proposed HIPAA Security Rule update would mandate encryption of ePHI at rest and in transit, multi-factor authentication, penetration testing, and vulnerability scanning, and it would eliminate the "addressable vs. required" distinction that has defined HIPAA security since the standards were written [R9]. The NPRM, published in the Federal Register on January 6, 2025, would be the first major update to the Security Rule in more than two decades [R9]. Read it closely: it tells you where the floor is going, even if the final rule is a year or two out.
That "addressable" item is the structural one. For two decades, "addressable" gave covered entities and business associates a documented off-ramp: assess the safeguard, decide it isn't reasonable for your environment, write down why, implement an alternative or nothing. Whole compliance programs were built on the quality of that paperwork. The NPRM would replace the off-ramp with a spec sheet.
The timeline compounds it. The proposal contemplates 60 days to effective date and 180 days to full compliance once the rule is finalized [R10]. Eight months, roughly, to retrofit encryption, MFA, and a testing regime across estates that in some cases predate the 2003 standards they'd be replacing. Teams that treat July 2027 as a start date will be doing archaeology under deadline. Teams that treat the NPRM as a published spec for work they should be doing anyway lose nothing if the date slips again — which, given the track record, it may.
Here's the honest version of the numbers, including the ones that cut against my argument. IBM's 2025 Cost of a Data Breach study has healthcare as the costliest industry for the fourteenth consecutive year [R1]. The US healthcare average actually fell year-over-year, down $2.35M to $7.42M [R1]. And healthcare breaches still take 279 days to identify and contain, against a 241-day global average [R1]. Nine months, on average, between compromise and containment. That's longer than the compliance window the NPRM contemplates.
The 2025 breach ledger looks similar. 710 large breaches were reported to HHS OCR in 2025, down 4.3% year-over-year [R3]. At least 61.56 million people were affected, a 78.7% drop from 2024's 289.2 million [R3]. A skeptic could call that improvement. But 2024's figure was inflated by a single event: Change Healthcare, whose final count reached 192.7 million individuals after a February 2024 attack, up from an initial estimate of 100 million [R2]. Strip out the anomaly and the baseline is stark on its own. Even in a "good" year, that 61.56 million works out to nearly one in five Americans with health data exposed in a large breach, and the biggest single incident (Aflac, attributed to Scattered Spider) touched 13.9 million people in the US [R3].
None of these numbers consulted the Federal Register before landing. Attackers don't read the Unified Agenda, and the cost curve doesn't pause because a final rule slipped. That's the core problem with the "relax, deregulation" read: it treats the federal rulemaking calendar as the risk calendar. They're different documents.
Follow the thread from section two and something structural falls out. Under the addressable regime, compliance was fundamentally a documents problem: risk assessments, policies, justification memos. That's work a legal or compliance team can own, because the deliverable is prose. When the safeguards become hard technical requirements — encrypt this, MFA that, pen-test on this cadence, scan on that one [R9] — the deliverable becomes architecture. Encryption at rest is a database and key-management decision. MFA is an identity-provider integration. Vulnerability scanning that actually runs lives in a CI pipeline, not a binder. Legal can tell you what the rule says. It cannot ship the control.
The FDA is converging on the same posture for AI-enabled software. Its January 2025 draft guidance on AI-enabled device software functions takes a total product lifecycle approach — bias mitigation, transparency, cybersecurity, and post-market performance monitoring with updates, mitigations, and corrective actions [R6]. Read that list again. It describes engineering process, not paperwork. Regulators on both tracks are asking the same question: show me the system, not the policy.
State law adds a constraint that lands directly on team design. HIPAA itself doesn't prohibit PHI being accessed or stored offshore, but several states do, in blunt terms: Florida requires certified-EHR patient data to be physically maintained in the continental US, its territories, or Canada; Texas requires MCO data stored in the US; Wisconsin bars contractors from offshore work involving PHI access [R18]. Even where offshore is legal, the recourse is thin. As McDermott Will & Schulte partners Spencer Green and Stephen L. Page put it: "If a foreign vendor violates HIPAA or experiences a data breach, there is limited recourse unless there are strong, binding, international arbitration provisions, or the foreign vendor maintains a substantial US-based presence." [R18] The standard cost-arbitrage playbook — ship the backlog to the cheapest offshore team — now runs into statutes that constrain who can even touch the code. Which raises the practical question: where do you get the people?
The talent market is tightest exactly where this bites. In one industry roundup, 66% of health IT professionals reported persistent staffing shortages over the past two years, and 61% of healthcare IT leaders called the IT talent gap urgent [R19]. You're not just hiring engineers into a shortage; you're hiring for a profile the shortage makes rarest.
So what does the profile look like? Not a "compliance officer who codes." You want senior engineers for whom the NPRM's requirements are already defaults: encryption at rest as the boring standard configuration, MFA and least-privilege as day-one identity design, audit logging built into the service template rather than bolted on for an assessment, dependency and vulnerability scanning wired into CI so pen-testers find less. In interviews, this is easy to probe. Ask a candidate how they'd handle key rotation, or what their last team logged and why. Engineers who've internalized this answer in specifics. Engineers who haven't answer in adjectives.
The build-vs-rent math matters too. If you can't hire this profile full-time (and per the shortage numbers, many can't [R19]), one option is renting HIPAA-compliant software development in a form that respects the constraints above. Yousource's Dev on Demand embeds dedicated AI-augmented engineers on a monthly subscription (Single Stream at $3,495/month for one dedicated engineer working 3-day task cycles; Dual Stream at $6,795/month for two parallel streams), with NDA and repo access at onboarding, engineers operating inside your environment under your access controls — including SOC 2 and GDPR frameworks when required — and an explicit commitment that code and data don't leave your environment without your approval [R21]. That last commitment is the one that matters when state residency laws are in play. Whether you use them or anyone else, apply the same test to every vendor: where does the code live, who can see the data, and can they show you controls rather than describe them?
The deregulation headlines will keep coming, and the final rule may well slip past July 2027. Build to the spec anyway. The breach ledger, not the Federal Register, is the compliance document that gets priced.
No. The proposed rule (NPRM) was published in the Federal Register on January 6, 2025, but as of mid-2026 no final rule has been issued [R9] [R10]. OMB's Unified Agenda targets July 2027 for final action; that's a target on a regulatory agenda, not a commitment [R10].
The proposed update would mandate encryption of ePHI at rest and in transit, multi-factor authentication, penetration testing, and vulnerability scanning, and would eliminate the "addressable vs. required" distinction that let organizations document alternatives to technical safeguards [R9]. Once finalized, the proposal contemplates roughly 180 days to reach full compliance [R10].
The average US healthcare data breach costs $7.42 million, according to IBM's 2025 Cost of a Data Breach study — the fourteenth consecutive year healthcare has been the costliest industry for breaches [R1]. Healthcare breaches also take 279 days on average to identify and contain, against a 241-day global average [R1].
HIPAA itself does not prohibit PHI being accessed or stored offshore, but several US states do: Florida requires certified-EHR patient data to be physically maintained in the continental US, its territories, or Canada; Texas requires MCO data stored in the US; and Wisconsin bars contractors from offshore work involving PHI access [R18]. Legal recourse against a foreign vendor after a breach is also limited without strong international arbitration provisions or a substantial US-based vendor presence [R18].
Increasingly, engineering. Under the current "addressable" regime, compliance is largely a documentation exercise a legal or compliance team can own; the proposed Security Rule update would replace those documented judgment calls with hard technical requirements — encryption, MFA, penetration testing, vulnerability scanning — that only engineering teams can implement [R9].