HHS OCR’s Jan. 6, 2025 proposed rule would significantly amend the HIPAA Security Rule, expanding mandates for risk analysis, technical safeguards, and business associate oversight. For healthcare AI, the proposal raises the bar on protections for training and operational data, stricter deidentification and re-identification safeguards, enhanced audit logging and access controls, and closer scrutiny of cloud and AI vendors and breach reporting.
Organizations should inventory AI data flows, update security risk analyses, and strengthen BAAs and vendor assessments. Implement encryption, MFA, least-privilege access, comprehensive logging, and formal model governance — including testing, monitoring, deidentification or synthetic data, and incident response. Prioritize remediation, tabletop exercises, workforce training, and privacy impact assessments to align AI development and procurement with the proposed rule as it moves toward finalization.





