
Patch management is the process of identifying, prioritizing, acquiring, installing, evaluating, and verifying software and system updates. It helps correct security weaknesses while reducing the risk that an update will disrupt operations or affect electronic protected health information (ePHI).
How do covered entities and business associates know what needs patching? Common sources include:
- Vendor notifications and security advisories
- Automated vulnerability scans
- Penetration-testing results
- Government resources, such as CISA’s Known Exploited Vulnerabilities Catalog
- IT or managed service provider reports
- Internal risk analyses and system reviews
The U.S. Department of Health and Human Services (HHS) proposed significant HIPAA Security Rule changes in December 2024. As of today, the proposal has not been finalized. The federal regulatory agenda identifies July 2027 as an estimated final-action date, but that date is not binding and may change.
If finalized as proposed, covered entities and business associates would need written procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying patches, updates, and upgrades across relevant electronic information systems. These procedures would need to be reviewed and tested at least annually.
Critical risks generally would need remediation within 15 calendar days after the need is identified when a patch, update, or upgrade is available. High risks generally would need remediation within 30 calendar days. If remediation is unavailable, the applicable period would begin when it becomes available. Organizations would set and document timelines for other risks.
Limited exceptions would apply when remediation is unavailable or would adversely affect the confidentiality, integrity, or availability of ePHI. The organization would have to document the exception in real time and implement appropriate compensating controls.
Organizations should not wait. The HHS Office for Civil Rights has confirmed that the current HIPAA risk-analysis requirement includes risks and vulnerabilities to ePHI from unpatched software.

Leave a Reply