The 2027 edition of NFPA 99, the Health Care Facilities Code, carries four changes that facility directors will feel in design review long before any authority enforces them. Code experts detailed them publicly in August 2026, including Chad Beebe of the American Society for Health Care Engineering and Jim Peterkin of TLC Engineering Solutions.
Three of the four loosen constraints that engineers have been designing around for years. The fourth adds an obligation that most health systems have no established process for. Taken together they reward facility teams who start the internal conversations now rather than at adoption.
A cybersecurity chapter for building systems
The headline addition is a new chapter addressing cybersecurity for health care facility building systems — a response to the rise in attacks reaching hospitals through building automation rather than through clinical IT.
This is the change with the longest organisational tail, because it lands in a governance gap. Building automation, access control, nurse call, medical gas alarm panels, and increasingly the electrical monitoring layer are network-connected systems that are typically procured by facilities, installed by controls contractors, and maintained under service agreements — while the security policies, patch management, and vulnerability governance live with IT and information security. The chapter’s subject matter covers equipment cybersecurity provisions, network-connected systems, software updates, and evidence of compliance, along with vendor and contractor security management planning.
Every one of those clauses implies a document and an owner. “Evidence of compliance” in particular is not something a controls vendor produces on request unless it was specified in the contract.
Three things worth starting before adoption, none of which require the code to be in force:
Inventory what is connected. Most facility departments cannot produce a current list of network-connected building systems, their firmware versions, and who is responsible for patching each one. That inventory is the prerequisite for everything else and it takes months to assemble accurately.
Fix the ownership question in writing. Decide with your CISO whether building systems fall inside the enterprise security programme or run a parallel one, and write it down. Ambiguity here is where the audit finding will land.
Put security language in the next controls contract. Patch cadence, vulnerability disclosure, credential management, and remote-access terms cost nothing to specify at procurement and are expensive to retrofit into an existing service agreement.
Video monitoring in care spaces, conditionally permitted
The 2027 edition permits video monitoring in health care spaces where it does not violate HIPAA or patient rights generally.
The operative word is conditionally. The code opens a door that privacy law still governs, which means the design question is now downstream of a policy question: which spaces, what is recorded, who can view it, how long retention runs, what the patient is told, and how the system behaves during examination or treatment. Clinical leadership, compliance, and risk own those answers. Facilities owns whether the infrastructure supports them — camera placement, field-of-view masking, network segmentation, and storage.
The practical failure mode here is a well-intentioned tele-sitter or fall-prevention deployment that gets installed against a clinical business case and only later meets the privacy review. Sequence it the other way.
MRI suite suppression, eased
The new edition accepts by default certain types of fire suppression equipment in MRI suites and treatment rooms, per Peterkin’s account of the changes.
MRI suite design has long involved a negotiation between magnet safety and suppression requirements, with ferromagnetic constraints inside the five-gauss line pushing teams toward custom solutions and AHJ-specific variances. Accepting certain equipment by default removes a recurring source of design-review friction and cost on imaging projects. If you have an imaging renovation in the FY2027 or FY2028 capital plan, this is worth flagging to your engineer now — the assumptions baked into a design basis written under the current edition may be more restrictive, and more expensive, than what the new edition will allow.
The 20,000-square-foot rule, replaced
The change most likely to save money on a floor plan: the fixed requirement placing isolated power and telecommunications rooms at 20,000-square-foot intervals has been replaced with a risk- and function-informed framework.
Peterkin described the practical problem the old rule created — hospital floors that needed three telecommunications rooms with nowhere to put them. A fixed interval takes no account of what the space is used for. A 20,000-square-foot administrative floor and a 20,000-square-foot procedural floor have entirely different distribution needs, and the arbitrary interval forced program space to be surrendered on floors that did not need the rooms while offering no additional coverage where the load was genuinely dense.
A risk-informed framework means the room count follows an analysis rather than a number, which is better engineering and more work. Expect your design team to produce a documented basis for the layout, and expect AHJs to ask for it. The upside is real: on a large floor plate, recovering one telecom room is recovering usable clinical or program space in perpetuity.
Electrical systems and hazard scope
The 2027 edition also broadens the framing of electrical system requirements, calling for mitigation of risks from fire, explosion, high temperatures, and natural disasters among other hazards. Chapter 5 carries revisions to electrical requirements, piping material requirements, and inspection and testing provisions.
The natural-disaster language is worth noting for facilities in flood, seismic, or high-wind exposure. Where equipment siting decisions — generator placement, transfer switch elevation, medical gas manifold location — were previously driven by the building code and by system-specific standards, the health care facilities code is now pointing at the same questions.
What this means for the planning cycle
None of this is enforceable until your state adopts the 2027 edition and CMS references it, and for health care that adoption chain is slower than the commercial building codes — many jurisdictions remain on earlier editions, and CMS Conditions of Participation reference a specific edition that lags publication by years.
That lag is the opportunity. The three easing changes reduce cost on projects designed after adoption, which argues for checking the timing of imaging and large floor-plate projects against your state’s adoption trajectory before finalising a design basis. The cybersecurity chapter runs the other way: it adds obligations that take an organisation a year or more to build the process for, and starting that work is not contingent on adoption at all.



