Paragon Partners Blog | April 2025
Cybersecurity is no longer just an IT issue, it’s a compliance imperative. In January 2025, the Department of Health and Human Services (HHS) proposed significant updates to the HIPAA Security Rule to strengthen protections for electronic protected health information (ePHI). For brokers, employers, and benefit administrators, these changes are a wake-up call to reassess how sensitive health data is handled, shared, and secured.
At Paragon Partners, we’re here to help our broker network and their clients stay ahead of the curve. Let’s walk through what’s changing, what it means for your clients, and how we can support smarter, safer compliance strategies.
The HHS’s proposed updates reflect a shift toward modern, proactive cybersecurity practices. While not finalized yet, the proposals signal clear expectations for how organizations should protect ePHI.
Here are the key proposed requirements:
Together, these updates aim to improve transparency, reduce vulnerability, and hold all parties handling PHI to a higher standard.
In December 2024, a separate update to the HIPAA Privacy Rule took effect, specifically addressing reproductive health information. Covered entities are now required to:
For employers offering self-insured plans or brokers managing groups in healthcare-related fields, this is a critical change that requires both attention and documentation.
These HIPAA updates may feel far removed from day-to-day benefits conversations—but they’re not.
Many employers, especially those offering self-funded plans or using benefits platforms that store health data, fall under these rules. And brokers are often the first line of communication when it comes to helping those clients understand their compliance responsibilities.
Here’s how you can help your clients stay prepared:
How Paragon Partners Supports You
Compliance shouldn’t feel overwhelming. That’s why Paragon is committed to keeping you informed and equipped to respond, not just to what’s happening now, but what’s on the horizon.
Here’s how we help:
Cybersecurity and data protection are more than regulatory checkboxes, they’re part of the trust your clients place in you. As HIPAA evolves, the brokers and partners who understand the risks and prepare early will stand out as true leaders in the field.
Have questions about how these updates might impact your clients or your business? Reach out to your Paragon rep for insights, support, or a compliance check-in.
Paragon Partners: Supporting broker success with integrity, innovation, and the human connection that makes all the difference.