On January 6, 2025, HHS proposed the most significant overhaul of the HIPAA Security Rule since 2013, a change that would eliminate the long-standing distinction between “required” and “addressable” safeguards and make encryption, multi-factor authentication, and detailed technology asset inventories mandatory…