Takeaways
- The Health Insurance Portability and Accountability Act (HIPAA) sets privacy and security standards for certain health care organizations, but it does not automatically cover every health, fitness, or AI app.
- Federal regulators have proposed stronger security requirements, including multi-factor authentication, encryption, testing, and monitoring, but those changes are not in effect yet.
- The proposed update is delayed, with final action projected for July 2027. Compliance could extend into 2028, depending on the final rule’s timeline.
- Older adults and caregivers can protect their information now by turning on multi-factor authentication, asking providers how they use AI, reviewing app privacy policies, and verifying unexpected health care or Medicare messages.
If you’ve logged into a MyChart account or a bank app recently, you’ve probably had to confirm your identity with a text message or an authentication app. That kind of extra security step, known as multi-factor authentication (MFA), has become routine for everyday accounts. But the federal rule that protects electronic health information doesn’t currently require it.
The discrepancy between what has become common practice and what’s required by law is what regulators have spent more than a year trying to fix. The big question hanging over that effort is whether any update to the more-than-two-decade-old federal rule can keep pace with how quickly artificial intelligence (AI) is moving into hospitals, clinics, and health insurance systems.
The Rule We’ve Been Waiting On
The Health Insurance Portability and Accountability Act, or HIPAA, includes a Security Rule that sets minimum standards for keeping electronic protected health information secure, including information in electronic medical records. That rule dates to 2003 and hasn’t been substantially updated since 2013, long before cloud-based records, telehealth, ransomware attacks, and AI diagnostic tools became part of everyday health care.
In 2025, federal regulators proposed the first major overhaul of that rule in over a decade. The proposal would require, rather than merely suggest, protections like:
- Multi-factor authentication for people accessing electronic protected health information
- Encryption of patient data, both in storage and in transit
- Regular testing of security systems and a 72-hour recovery capability after an attack
- Ongoing monitoring for unusual or suspicious activity on health systems
Right now, many of those protections are only “addressable,” meaning an organization must consider them but may use an alternative approach. The update would make them mandatory across the board.
Delayed Changes
The new rule was previously expected in spring 2026, but that deadline has passed. The latest federal regulatory agenda lists July 2027 as the projected date for final action. That date is a target, not a guarantee, and would put finalization more than a year later than the previously projected May 2026 date.
A few things are driving the delay:
- Pushback from industry. A coalition of more than 100 hospital and provider groups has formally asked the Department of Health and Human Services (HHS) to withdraw the proposal, arguing the mandatory requirements are too costly and rigid for smaller providers.
- Sheer volume of feedback. The proposal drew more than 4,000 public comments before the comment period closed in March 2025.
- A separate track moving faster. While the Security Rule overhaul stalls, HHS has a separate HIPAA Privacy Rule update in the final-rule stage, with final action projected for August 2026. Unlike the Security Rule, which addresses how health information is secured, the Privacy Rule addresses who may access and share it.
After a final Security Rule is published, affected organizations would likely receive a separate compliance period. The length of that period could change in the final rule. Finalizing the update is now a 2027-or-later story, and compliance could extend into 2028, depending on when a final rule is published and what compliance period it provides.
Where AI Fits In and Why Regulators Are Behind
AI raises additional questions that the current Security Rule and the proposed update do not fully answer.
HIPAA generally applies to health plans, doctors, hospitals, and the companies that handle health information for them. It does not automatically cover every health, fitness, or AI app that collects health-related information.
The Security Rule was not originally written with AI in mind, and the current proposal does not resolve every question AI raises about health information:
- If a hospital or insurer uses an outside AI vendor, what requires that company to protect your information?
- Who’s accountable if an AI-generated note in your medical record is wrong?
- Can health data really be made anonymous before it’s used to train an AI model?
- Will you be told when AI meaningfully affects a decision about your care?
Those questions remain unresolved. In the meantime, some states aren’t waiting. Utah, for example, has adopted AI-disclosure requirements that apply in certain circumstances to regulated professionals, including health care professionals.
Those requirements add state-level obligations to a federal framework that hasn’t caught up with AI. The result is that hospitals and AI vendors increasingly have to comply with a patchwork of state rules rather than one consistent federal standard.
What This Means for Older Adults
This issue lands with particular weight for older adults, who are heavy users of the health system, frequent targets of scams, and increasingly encountering AI in both contexts.
A national AARP survey released in June 2026 found that 41 percent of adults age 50 and older who use AI have already asked an AI tool a health-related question, and 62 percent said they’re likely to do so in the coming year. But trust hasn’t kept pace with use.
Among respondents who were not completely comfortable sharing health information with AI tools, 58 percent cited privacy and security concerns, while 57 percent cited a lack of regulation or oversight. The doctor remained the more trusted source. In the AARP survey, preferring to have a doctor explain health information rather than an AI tool was the most frequently cited reason for discomfort with using an AI tool.
Separately, Federal Internet Crime Complaint Center data show people over 60 reported more than $7.7 billion in losses to internet crime in 2025. AI-generated voices and video may make health- and Medicare-related scams harder to detect, giving consumers another reason to verify unexpected calls and messages independently.
Older adults managing multiple conditions, caregivers, and medical appointments may have even more opportunities to encounter AI tools, health apps, and scam messages. A few practical steps can help:
- Ask a provider’s office if they use an AI tool to transcribe visits or draft after-visit summaries. It’s reasonable to ask how that data are stored and whether they’re shared with outside companies.
- Turn on multi-factor authentication. Even though it isn’t federally required yet, most patient portals offer it as an option. Turning it on adds protection now, rather than waiting for a rule that may not arrive until 2027.
- Be skeptical of unsolicited AI-sounding calls or messages about Medicare, billing, or prescriptions, especially ones creating urgency. Verify by calling the provider or insurer back using a number from an official statement, not one provided by the caller.
- Avoid entering Social Security numbers, Medicare numbers, or complete medical records into a consumer AI tool unless you understand how the service uses, stores, and deletes the information.
- Ask a trusted family member or caregiver to help review privacy policies from telehealth or health apps.
The Bottom Line
The federal government has acknowledged that health data protection needs an overhaul for the AI era. But acknowledging the problem and finalizing a rule are two different things and the timeline has now widened by more than a year. Until a final Security Rule is enacted, patients and the organizations handling their health information are left navigating a rapidly changing AI landscape under outdated federal security standards and an uneven patchwork of state requirements.
