
What are the most recent HIPAA changes?
Key Facts
- Records impermissibly disclosed jumped from 51.9 million in 2022 to 168 million in 2023 according to breach data
- Average breach size nearly doubled to 400,000 records in 2024 per Duo analysis
- The proposed Security Rule would eliminate the "addressable" vs. "required" distinction, making nearly all technical safeguards mandatory per HHS fact sheet
- Willful neglect uncorrected within 30 days carries penalties up to $68,928 per violation with annual caps exceeding $2 million per HIPAA Journal
- The Privacy Rule final rule expected August 2026 would shorten PHI access timeframe from 30 days to 15 days per regulatory timeline
- Proposed vulnerability scanning every 6 months and annual penetration testing would become required under the Security Rule NPRM
- A Texas court vacated the 2024 reproductive health privacy rule nationwide in 2025 removing additional protections
HIPAA Is Changing Fast — And Call Centers Are Exposed
Healthcare organizations handling patient data face mounting pressure as HIPAA regulations evolve rapidly. Pending rulemakings, including the Security Rule NPRM from December 27, 2024 and a Privacy Rule final rule expected in August 2026, signal significant changes ahead—even as the current Security Rule remains in effect during this transition period.
The stakes are rising sharply. Records impermissibly disclosed jumped from 51.9 million in 2022 to 168 million in 2023, and the average breach size in 2024 reached nearly 400,000 records. For any clinic or healthcare caller managing ePHI in call recordings, transcripts, or SMS, these trends underscore why proactive compliance attention is essential now.
The proposed Security Rule would eliminate the distinction between "required" and "addressable" safeguards, making nearly all technical controls mandatory—including encryption, multi-factor authentication, and annual compliance audits. This shift directly impacts business associates like My AI Call Center, which handles ePHI through AI-powered outbound campaigns for clinics and healthcare providers.
- Encryption of ePHI at rest and in transit would become mandatory under the proposed rule
- Vulnerability scanning would be required at least every six months
- Incident response timelines tighten to 24 hours for access change notifications and 72 hours for system restoration
While My AI Call Center already adheres to HIPAA-compliant communication standards—including signed Business Associate Agreements, consent-verified calling lists, and optional recording with disclosure—the evolving regulatory landscape demands ongoing vigilance. Preparing for mandatory safeguards today helps ensure continued adherence as rulemakings finalize, protecting both patient data and operational integrity.
The Four Biggest Recent and Pending HIPAA Changes
HIPAA hasn't seen a shakeup like this in nearly a decade. Four regulatory changes — two pending, two already in effect — are reshaping how healthcare organizations and their vendors handle protected health information.
1. The proposed Security Rule overhaul. Published December 27, 2024, HHS's proposed rulemaking eliminates the long-standing distinction between "addressable" and "required" safeguards, making nearly every specification mandatory. Encryption of ePHI, multi-factor authentication, annual compliance audits, and penetration testing become required rather than optional. The proposed timelines are aggressive:
- Vulnerability scans at least every 6 months
- Notification within 24 hours when workforce access changes or terminates
- System and data restoration within 72 hours
- Annual asset inventory and network map updates
A final rule is delayed until 2027, and a coalition led by CHIME has petitioned HHS to withdraw it — but the current Security Rule remains in effect while rulemaking proceeds. The urgency is real: breach data shows impermissibly disclosed records jumped from 51.9 million in 2022 to 168 million in 2023.
2. The Privacy Rule final rule, expected August 2026. This rulemaking shortens the PHI access timeframe from 30 days to 15 days, with a maximum of 30 days total including extensions. It also broadens the "healthcare operations" definition to cover care coordination and case management, giving providers more flexibility to share information for patient care.
3. The 2024 alignment of 42 CFR Part 2 with HIPAA. Substance use disorder records, previously governed by stricter separate rules, now follow a more unified compliance framework, simplifying how treatment-related communications are handled.
4. The 2025 vacating of the reproductive health privacy rule. A Texas court vacated the 2024 rule nationwide, removing additional protections that had been placed around reproductive health information.
The stakes are substantial. Willful neglect that goes uncorrected within 30 days carries penalties up to $68,928 per violation with annual caps exceeding $2 million, according to the HIPAA Journal's penalty breakdown. Even violations due to lack of oversight can reach $68,928 per violation.
For organizations that outsource patient outreach, these changes matter at the vendor level. Call recordings and transcripts often contain PHI and must be treated as protected records — which is why My AI Call Center reviews list sources, consent records, and disclosure handling before any campaign launches, and treats every outbound campaign against regulated contacts with documented care. As these rules finalize, the vendors who already operate with this discipline will have the shortest path to compliance.
What These Changes Mean for Outbound Calling and AI Voices
Regulation on paper becomes real the moment a phone rings. For call centers handling health information, HIPAA's recent changes land squarely on everyday operations: recordings, transcripts, identity checks, and the vendors behind the voice on the line.
Start with the recordings themselves. As HIPAA Journal notes, call recordings and transcripts often contain PHI, which means they must be treated as protected records — not marketing assets or disposable files. A reminder call that captures a name, appointment type, or clinic reference is a regulated record the moment it exists. That's why recording should be optional, disclosed, and consent-based, with data never shared, sold, or used to train shared models.
Identity verification matters even more. Steve Alder, Editor-in-Chief of The HIPAA Journal, explains that identity verification is one of the most important HIPAA controls in call centers because most disclosures are made to someone who is not physically present. Outbound calls invert the usual risk: you are disclosing information to a voice on a line, so consent records, list provenance, and escalation paths carry the compliance weight.
The AI layer adds new obligations. Training should address modern risks such as AI tools, transcription services, and translation platforms that may not be approved for PHI. A multi-language campaign or an AI voice reading a clinic reminder still touches protected data, and the tooling behind it must be vetted accordingly.
Business associates face the sharpest accountability shift. The proposed Security Rule would require:
- Annual verification by subject matter experts that required technical safeguards are deployed
- Technology asset inventories and network maps of ePHI movement, updated at least every 12 months
- Subcontractors handling ePHI held to the same security requirements
- 24-hour notification when workforce access to ePHI is changed or terminated
The stakes justify the rigor. Records impermissibly disclosed jumped from 51.9 million in 2022 to 168 million in 2023, and average breach size climbed from 225,000 to nearly 400,000 records in 2024. Willful neglect left uncorrected for 30 days carries penalties up to $68,928 per violation, with an annual cap exceeding $2 million.
This is why a managed calling provider operating as a business associate must treat these as its own obligations, not the client's problem alone. My AI Call Center reviews list source and consent records before any campaign launches, treats AI voices as artificial voices requiring disclosure, and honors opt-outs immediately. When a covered entity signs a BAA, the safeguards — encryption, access controls, verification — belong to the provider running the calls, every campaign, every time.
How My AI Call Center Stays Ahead of HIPAA Requirements
When the rules change faster than most teams can track, the safest position is already meeting the stricter standard. That is the philosophy behind how My AI Call Center runs clinic and healthcare calling campaigns — built on HIPAA-compliant communication standards before a single call goes out.
Every campaign begins with a signed Business Associate Agreement, which compliance guidance identifies as one of three core requirements for any call center handling PHI. Before launch, list source and consent records are reviewed as a formal step — only approved, permissioned, or reviewed lists are accepted. Bought lists without clear permission records are flagged, and in most cases declined. We tell you plainly if the list will not support the campaign, before you spend anything.
Once live, the controls mirror the direction regulators are heading. The proposed Security Rule published December 27, 2024 would eliminate the "addressable" versus "required" distinction, making nearly all technical safeguards mandatory. The operational answer is to treat those safeguards as already required:
- AI disclosure on every call, with human handoff available and keyword opt-outs (STOP, REVOKE) honored immediately.
- Recording is optional and only happens with clear disclosure and consent — recordings and transcripts are treated as protected records, since call recordings often contain PHI.
- Data is never shared, sold, or used to train shared models.
- DNC requests are honored immediately and carried into client DNC records across all campaigns.
- Structured scripts, defined escalation paths, and named outcome reports with disposition codes document what actually happened on every call.
This documentation discipline matters more each year. Records impermissibly disclosed jumped from 51.9 million in 2022 to 168 million in 2023, and average breach size grew from roughly 225,000 to nearly 400,000 in 2024. With proposed timelines like 24-hour access-change notifications and 72-hour system restoration on the horizon, having written procedures and audit-ready records is not extra work — it is the standard the industry is moving toward.
The same logic applies to transparency. Since further HIPAA guidance is expected in 2026 to clear up misconceptions and false interpretations, campaigns that already disclose, document, and honor opt-outs cleanly will not need to scramble when clarity arrives.
If you run clinic campaigns and want calls that confirm, remind, or retain patients without adding compliance risk, start with a free campaign review — managed outbound calling from 9¢ per connected minute, with the full number known before you approve launch.
Your Practical HIPAA Readiness Checklist Before Your Next Campaign
Preparing your outbound campaigns for evolving HIPAA requirements starts with foundational safeguards that protect protected health information at every touchpoint. A signed Business Associate Agreement with any calling or communications vendor is non-negotiable when ePHI is involved, as it legally binds the vendor to HIPAA’s Privacy and Security Rules. Verifying consent records and list provenance before dialing ensures you’re only contacting individuals who have authorized the specific type of outreach, reducing risk of impermissible disclosure.
Ask your vendor how recordings, transcripts, and texts containing ePHI are encrypted both at rest and in transit, and what retention policies apply—especially as the proposed Security Rule NPRM from December 27, 2024 seeks to make encryption and multi-factor authentication mandatory rather than addressable. This shift would eliminate current flexibility, requiring robust technical safeguards like vulnerability scanning every six months and annual compliance audits. Confirming these details now helps avoid costly rework when final rules take effect.
Build identity verification and clear escalation workflows directly into your call scripts to prevent unauthorized disclosures, a control emphasized as critical in phone-based operations where most PHI is shared with someone not physically present. Calendar the August 2026 Privacy Rule final rule and the 2027 Security Rule timeline to review and update procedures well before compliance deadlines, particularly as proposed changes include shortening the PHI access timeframe from 30 days to 15 days and broadening healthcare operations to include care coordination.
Campaign requirements vary by location, industry, and consent status, so clients should obtain appropriate legal guidance before launch. To ensure your next campaign aligns with current and upcoming HIPAA standards, schedule a free campaign review with My AI Call Center today.
Frequently Asked Questions
What are the biggest HIPAA changes happening right now?
When do the new HIPAA Security Rule requirements actually take effect?
What would the proposed Security Rule require that isn't required today?
Why is HIPAA suddenly such a big deal for call centers?
How much can a HIPAA violation actually cost my organization?
What should I check before running outbound calls that involve patient information?
Staying Ahead: Turning HIPAA Shifts into Operational Strength
As HIPAA evolves with pending Security Rule changes and a Privacy Rule update expected in 2026, the pressure on healthcare organizations and their vendors to protect ePHI has never been greater. From mandatory encryption and multi-factor authentication to tightened 24-hour incident response timelines, the proposed rules eliminate flexibility and raise the bar for compliance—especially for business associates handling call recordings, transcripts, and AI-powered outreach. My AI Call Center builds its managed outbound calling service around these realities, treating every campaign as an opportunity to uphold HIPAA standards through signed BAAs, consent-verified lists, optional recording with disclosure, and immediate opt-out honoring. With breach costs rising and penalties for willful neglect reaching up to $68,928 per violation, proactive alignment isn’t just about avoiding risk—it’s about preserving trust and ensuring every patient interaction remains secure and respectful. To confirm your next campaign meets today’s standards and tomorrow’s expectations, schedule a free campaign review and launch with confidence.