The HIPAA Privacy Rule update that has been sitting unfinished since January 2021 is finally moving. HHS sent the final text to the Office of Management and Budget on 4 April 2026, and it is expected to publish in August. What it contains is not the thing most compliance teams have been bracing for.
The change everyone talks about, cutting the record request response deadline from 30 days to 15, is not in it. That piece was pulled out into a separate proposed rule, which means a comment period first and a compliance date somewhere after that. If your plan was to spend this month rebuilding a records workflow around a 15-day clock, you have bought yourself time.
You have not bought yourself a pass. Read on for what is actually in the August rule and why a fax queue is where it will bite.
Three rules, three dates, and a lot of confusion

Three separate rulemakings, and only one of them lands this month.
Most of the confusion comes from treating this as one big HIPAA update. It is three.
The Privacy Rule final is the August item. It comes out of the January 2021 notice of proposed rulemaking and covers individual access rights, disclosures for care coordination and case management, exceptions for emergencies and threats to health or safety, and required changes to the notice of privacy practices. It sat at proposal stage for five years, which is a long time even by rulemaking standards, and the text has been locked since it went to OMB. There is no public preview, so nobody outside the process knows exactly what survived from the proposal.
The access timing piece was carved off into its own proposed rule, expected around November 2026. Proposed means comment period, then a final rule, then a compliance date. That is not this year’s problem.
The Security Rule overhaul, the one with the encryption and multi-factor authentication mandates, slipped a second time and now sits in July 2027 on the long-term actions list. It is the rule with the most operational weight and the least urgency right now.
So the practical read is this. One rule is arriving with notice and disclosure changes. One is coming later with a deadline you cannot yet plan against precisely. One is far enough out that anything you build for it now will be built against a guess.
Why a fax queue is the exposed surface
Fax should have died a decade ago and did not. US healthcare still moves somewhere around nine billion fax pages a year, and by most estimates roughly nine in ten medical record requests travel that way at some point in their journey. Referrals, prior authorisations, discharge summaries, and the record requests themselves all ride on it.
That makes the fax queue the physical location of your access compliance, whatever your policy document says. When somebody asks for their records, the clock that matters starts when the request arrives and stops when the records go back out. Both of those events, for most organisations, happen on a fax server.
Here is the uncomfortable part. Nearly every access enforcement action OCR has brought, and there have been more than fifty under the Right of Access Initiative, comes down to the same fact pattern. Somebody asked, and the records did not arrive within the window. Not a breach, not a hacker, not a ransomware event. A request that went slowly.
Slowness is not usually a policy failure. It is a queue nobody watches, a failed transmission at 2am that nobody retried, or a request that landed in a shared inbox during someone’s annual leave.
The notice of privacy practices is the sleeper item
Of everything in the August rule, the notice of privacy practices changes are the ones most likely to be missed, because the notice is a document that usually has no owner.
Ask around your organisation who is responsible for the current text of the NPP and when it was last revised. In a lot of places the honest answer is that a consultant wrote it, somebody put it on the website, and it has not been touched since. That is exactly how a rule change arrives and nothing happens.
The disclosure provisions matter for fax too. If the rule changes what you must tell people about how their information gets shared for care coordination, and your care coordination happens over fax, then your outbound fax practice is part of what the notice describes. A notice that describes a process you do not actually follow is worse than no notice at all, because it documents the gap for you.
Five numbers to pull this month

None of these need the final rule text to be published first.
You do not need to see the August text to do useful work right now. Every one of these is measurable today and none of them takes more than an afternoon.
Median and worst-case turnaround on inbound record requests. Not the send time, the whole clock. Most teams quote a median and have never looked at the tail. The tail is the only part a regulator would ever ask about, because the complaint that reaches OCR is always from the person who waited longest, not the average requester.
Failed transmissions per week, and what happens to them. A fax that failed overnight and never got retried is a record request still sitting in your queue with nobody aware of it. The question is not how many fail. It is whether a failure raises anything a human sees, or whether it only writes a line to a log nobody reads.
Whether your log proves delivery or just proves you tried. There is a genuine difference between a record saying you sent it and a record saying the receiving machine confirmed the page count. If you only have the first, you cannot evidence a disclosure that somebody later says never arrived. That distinction becomes the whole argument in a dispute.
How long fax images sit on disk, and who can read them. Spool directories collect years of patient records quietly, because deleting them was never anybody’s job. Find the oldest file on the box and list which accounts can open it. That answer is usually uncomfortable, and it is a minimum necessary problem sitting in plain sight.
Who is named on the notice of privacy practices, and when it was last touched. If nobody owns it, the rule change will arrive and nothing will happen.
What the answers tell you
If your median turnaround is a couple of days and your tail is under a week, the eventual 15-day rule is a non-event for you and you can stop worrying about it. Go and spend the attention on the notice instead.
If you cannot produce the number at all, that is the actual finding, and it is a bigger one than any specific deadline. An organisation that cannot measure its own response time cannot tell whether it is compliant with the current 30-day rule either.
Where the number is uncomfortable, the fix is almost never more staff. It is visibility. Most fax queues have no dashboard, no ageing view, and no alert when something has been sitting too long. Add those three things and the turnaround usually improves on its own, because people fix what they can see.
This is one of the arguments for running your fax infrastructure somewhere you can query it. When the server is yours, the delivery confirmations, retry history and spool contents are all in a database you can point a report at. On a hosted service you get whatever report the vendor decided to build, and if ageing by request date is not one of them, you cannot add it. If you are weighing that tradeoff, our notes on self-hosting PHI over T.38 go through the practical differences.
What not to do before August
Two temptations worth resisting.
Do not rebuild your workflow around a 15-day deadline that has not been finalised. The proposal has not even been published for comment yet. Building to a number that may move wastes the work twice, once building it and once unpicking it.
Do not buy anything on the strength of a vendor email about the August rule. Nobody has seen the text. Any product being sold this month as ready for the new Privacy Rule is being sold on a guess about a document that is still inside OMB. Wait for the text, read the notice and disclosure sections, and then decide whether you need anything at all.
The measurement work above is useful regardless of what the rule says, which is what makes it the right thing to do now.
Frequently asked questions
Is the HIPAA record request deadline changing to 15 days in August 2026?
No. The access timing change was split out of the Privacy Rule final and into a separate proposed rule expected around November 2026. A proposal has to go through a comment period and a final rule before any compliance date applies, so the current 30-day standard still governs.
What is actually in the August 2026 Privacy Rule final?
It comes from the January 2021 proposal and covers individual access rights, disclosures for care coordination and case management, exceptions for emergencies and serious threats to health or safety, and changes to the notice of privacy practices. The exact final text is not public until it publishes.
What happened to the HIPAA Security Rule update?
It slipped again and now sits around July 2027 on the long-term actions list. That is the rulemaking carrying the encryption and multi-factor authentication requirements, so it has the most operational weight of the three, but the least immediate urgency.
Does a fax confirmation page count as proof of delivery?
It depends what your system records. A confirmation that the receiving machine acknowledged the transmission and matched the page count is meaningfully stronger evidence than a log line saying a send was attempted. Check which one you actually store before you need it.
How long should fax images stay on the server?
Only as long as you have a documented reason to keep them. The common failure is a spool directory holding years of patient records because deletion was never assigned to anyone. Set a retention period, automate it, and restrict who can read the directory in the meantime.
Do we need to update our notice of privacy practices?
Very likely, since NPP content is one of the areas the 2021 proposal addressed. The first step is naming an owner for the document, because a notice with no owner does not get updated when a rule changes.
Related resources
- HIPAA Compliant Fax Server
- Self-Hosting PHI: T.38 and FoIP in 2026
- Self-Hosting Fax, Open Source PHI and the BAA Question
- Open Source Fax Server and Healthcare Standardization
Where to go next
If the five numbers above turned up something you could not answer, the gap is usually visibility rather than capacity. ICTFax is an open source fax server you run yourself, which means the delivery confirmations, retry history and queue ageing all live in a database you can report on. Tell us how record requests reach your fax queue today and we will help you work out where the measurement should sit. Open a ticket at service.ictinnovations.com.