Changes are (probably) coming for the Health Insurance Portability and Accountability Act (HIPAA) compliance. On January 6, 2025, the Department of Health and Human Services (HHS) published a notice of proposed rulemaking entitled HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information. The notice details several significant potential changes to the HIPAA Security Rule intended to bring the law, which was passed in 1996, up to date with the current threat environment. Interested parties have until March 7 to comment on the proposed changes.
A Very Long Proposal
Be prepared if you browse over to check out the proposal. It’s long. Very long. Nearly one thousand pages long. The kind of long that means you’ll have to trust a law firm to go over it and explain what it means for your organization. Law firm Foley Lardner published a high-level summary of the proposed changes on their healthcare law insights page. Some of their takeaways suggest that, if passed, the updates would require:
- The creation and maintenance of a written inventory of technology assets and a network map.
- Annual risk analyses with more specificity.
- Establishment of change management controls.
- Patch management policies and procedures.
- Robust risk management planning.
- Stringent requirements for monitoring and incident response policies and procedures.
Foley Lardner also points out that the proposed rules changes seek to “expand the Security Rule’s technical safeguards,” including:
- Encrypt ePHI at rest and in motion, subject to limited exceptions.
- Use multi-factor authentication, subject to limited exceptions.
- Establish and deploy technical controls for configuring relevant IT systems in a consistent manner.
- Implement required configuration management controls, including deploying anti-malware protection, removing extraneous software, and disabling ports in accordance with the risk analysis.
- Conduct vulnerability scanning at least every six months and penetration testing at least once every 12 months.
- Use network segmentation.
- Deploy technical controls to create and maintain backups of relevant IT systems and to review and test the effectiveness of such controls once every six months.
But Wait… There’s More!
We wanted to make sure not to overlook any relevant potential changes than what Foley included in their summary, so we skimmed the document to see how it might affect the use of managed file transfer in maintaining HIPAA compliant file transfers of things like electronic health records (EHRs) and protected health information (PHI). There are a few things that stood out beyond the two items (encryption and MFA) we bolded in the list above. For example, the proposal makes reference to improving supply chain security, including a recommendation to follow National Institute for Standards and Technology (NIST) guidance for “vendor management and identification of risks in a supply chain are essential to controlling the introduction of new threats and risks to a regulated entity.”
There is also a suggestion that organizations begin “planning for migration to post-quantum cryptographic standards by developing a Quantum-Readiness Road map,” and to “prepare a cryptographic inventory, discuss post-quantum roadmaps with technology vendors, consider their supply chain’s readiness for quantum computing, and consider the responsibilities of their technology vendors with respect to preparing for quantum readiness.”
Ready for Whatever
Coviant Software counts many hospitals, healthcare networks, and other medical and healthcare services organizations among our customers. It is important to us that they can count on Diplomat MFT to support their efforts at maintaining the security and integrity of EHR, PHI, personally identifiable information (PII), and other information that might fall under HIPAA or any of the many data security and privacy mandates out there. That’s why we’ve published a Guide to HIPAA Updates and HIPAA Changes in 2025. It’s also why we invest in making sure Diplomat MFT keeps pace with our customers’ needs, including features like:
- Automated PGP encryption management to secure files at rest and in motion
- Robust scheduler with virtually unlimited concurrent job management
- Automatic file transfer process data capture to ensure auditability
- Role-based privileging for appropriate user access
- Authorized recipient and destination confirmation
- Automatic trouble/failure notification, and
- Support for
- Improved Elliptical Curve cryptography for “quantum resistant” encryption
- Time-based One-Time Passwords (TOTP)
- Two-factor authentication (2FA) and multi-factor authentication (MFA)
- Authenticator applications like Microsoft Authenticator, Google Authenticator, Okta Verify, Duo Mobile, and more.
Later this year Diplomat MFT will also include support for the new NIST standards for post-quantum cryptography.
Get Expert Advice and Expert Tech
Regulatory compliance is a serious undertaking, and we recommend that you seek expert legal guidance to ensure your practices are HIPAA compliant. The penalties for non-compliance leading to a data breach can be severe, and that is why we strive to build the best managed file transfer solution available. In more than twenty years Diplomat MFT has never been the source of a breach. We are proud of that record, and proud that so many organizations rely on us to make their file transfers easy, efficient, secure, and part of their HIPAA compliance programs.

