The proposed 2025 update to the HIPAA Security Rule does something the original rule never had to: it names artificial intelligence explicitly, alongside quantum computing and augmented reality, as an emerging technology requiring formal risk analysis. For health systems that have been treating AI governance as a general best-practice exercise rather than a specific compliance obligation, this proposal is the signal that the distinction is about to matter less — AI risk analysis is moving from advisable to expected.
The change that affects the most organizations: required versus addressable
The most consequential part of the proposal isn’t the AI mention itself — it’s a structural change to how the Security Rule works. Currently, many Security Rule provisions are “addressable,” meaning an organization can implement an alternative measure or document why a given control isn’t reasonable for their situation. The proposed update would eliminate that required-versus-addressable distinction for several core controls, including asset inventories, encryption, and multi-factor authentication — making them mandatory rather than a risk-based judgment call.
Applied to AI specifically, this raises the bar on the “Map” component of AI governance discussed elsewhere: a maintained inventory of AI systems touching PHI moves from a governance best practice toward something closer to a compliance requirement. An organization that has been treating its AI tool inventory as informal or partial — which describes most health systems today — has a specific, dated reason to formalize it now rather than after the rule finalizes.
What HHS’s broader AI strategy signals
Alongside the Security Rule proposal, HHS’s AI strategy, released in December 2025, sets an expectation that organizations understand the technology touching PHI and manage its risk intentionally — language that applies directly to the shadow AI problem many health systems are only now starting to inventory. The direction of travel across both documents is consistent: less tolerance for informal, undocumented AI use, more expectation of a specific, demonstrable governance process.
What this means concretely, before the rule finalizes
Organizations don’t need to wait for the rule to finalize to start closing the gap it points to, and there’s a practical reason not to wait: the inventory and risk analysis work takes real time to do properly, and starting once a rule is final rather than while it’s proposed means starting from the same place, just under more time pressure. Three things are worth doing now, ahead of finalization. Build or complete the AI systems inventory — every tool touching PHI, its BAA status, and its vendor’s data-handling practices — since this is the artifact regulators will expect regardless of the rule’s exact final language. Conduct AI-specific risk analysis for the highest-exposure systems first, treating this the same way existing Security Rule risk analysis already works, just extended explicitly to AI. And review whether Security Rule controls currently treated as “addressable” and skipped would become mandatory under the proposed language, so there’s no scramble if and when that shift finalizes.
Why acting ahead of finalization is the lower-risk path
Proposed rules sometimes change before finalizing, but the direction — more explicit AI risk analysis, fewer optional controls — is unlikely to reverse, and the underlying exposure (unmanaged AI tools touching PHI) is real today regardless of what the final rule says. Building the inventory and risk analysis now is protective either way: if the rule finalizes largely as proposed, the work is already done; if it changes, the organization is still better positioned than it was.
SPAR helps health systems build AI governance structured around where HIPAA compliance is heading, not just where it currently sits, because the gap between the two is closing faster than most governance programs are moving. If your AI inventory and risk analysis process isn’t where the proposed rule is heading, that’s worth addressing before finalization forces the timeline.
Zev is a Branding Manager who specializing in content writing at SPAR, he is passionate about crafting compelling narratives that bring brands to life. With a background in both marketing strategy and creative writing, he bridge the gap between data-driven insights and imaginative storytelling to create impactful, consistent brand experiences.
The proposed 2025 update to the HIPAA Security Rule does something the original rule never had to: it names artificial intelligence explicitly, alongside quantum computing and augmented reality, as an emerging technology requiring formal risk analysis. For health systems that have been treating AI governance as a general best-practice exercise rather than a specific compliance obligation, this proposal is the signal that the distinction is about to matter less — AI risk analysis is moving from advisable to expected.
The change that affects the most organizations: required versus addressable
The most consequential part of the proposal isn’t the AI mention itself — it’s a structural change to how the Security Rule works. Currently, many Security Rule provisions are “addressable,” meaning an organization can implement an alternative measure or document why a given control isn’t reasonable for their situation. The proposed update would eliminate that required-versus-addressable distinction for several core controls, including asset inventories, encryption, and multi-factor authentication — making them mandatory rather than a risk-based judgment call.
Applied to AI specifically, this raises the bar on the “Map” component of AI governance discussed elsewhere: a maintained inventory of AI systems touching PHI moves from a governance best practice toward something closer to a compliance requirement. An organization that has been treating its AI tool inventory as informal or partial — which describes most health systems today — has a specific, dated reason to formalize it now rather than after the rule finalizes.
What HHS’s broader AI strategy signals
Alongside the Security Rule proposal, HHS’s AI strategy, released in December 2025, sets an expectation that organizations understand the technology touching PHI and manage its risk intentionally — language that applies directly to the shadow AI problem many health systems are only now starting to inventory. The direction of travel across both documents is consistent: less tolerance for informal, undocumented AI use, more expectation of a specific, demonstrable governance process.
What this means concretely, before the rule finalizes
Organizations don’t need to wait for the rule to finalize to start closing the gap it points to, and there’s a practical reason not to wait: the inventory and risk analysis work takes real time to do properly, and starting once a rule is final rather than while it’s proposed means starting from the same place, just under more time pressure. Three things are worth doing now, ahead of finalization. Build or complete the AI systems inventory — every tool touching PHI, its BAA status, and its vendor’s data-handling practices — since this is the artifact regulators will expect regardless of the rule’s exact final language. Conduct AI-specific risk analysis for the highest-exposure systems first, treating this the same way existing Security Rule risk analysis already works, just extended explicitly to AI. And review whether Security Rule controls currently treated as “addressable” and skipped would become mandatory under the proposed language, so there’s no scramble if and when that shift finalizes.
Why acting ahead of finalization is the lower-risk path
Proposed rules sometimes change before finalizing, but the direction — more explicit AI risk analysis, fewer optional controls — is unlikely to reverse, and the underlying exposure (unmanaged AI tools touching PHI) is real today regardless of what the final rule says. Building the inventory and risk analysis now is protective either way: if the rule finalizes largely as proposed, the work is already done; if it changes, the organization is still better positioned than it was.
SPAR helps health systems build AI governance structured around where HIPAA compliance is heading, not just where it currently sits, because the gap between the two is closing faster than most governance programs are moving. If your AI inventory and risk analysis process isn’t where the proposed rule is heading, that’s worth addressing before finalization forces the timeline.
Recent Posts
Recent Comments
About Me
Zev Gomes
Zev is a Branding Manager who specializing in content writing at SPAR, he is passionate about crafting compelling narratives that bring brands to life. With a background in both marketing strategy and creative writing, he bridge the gap between data-driven insights and imaginative storytelling to create impactful, consistent brand experiences.
Popular Categories
Popular Tags
Archives