Cybersecurity & IT Risk

Healthcare Organizations May Need to Rethink HIPAA Security Compliance

Proposed changes to the HIPAA Security Rule would introduce more specific cybersecurity requirements and raise expectations for how organizations protect electronic protected health information.

ealthcare Orgs Rethink HIPAA Security Compliance

The U.S. Department of Health and Human Services has proposed the most significant update to the HIPAA Security Rule in years. While many healthcare leaders are focused on specific requirements such as penetration testing, vulnerability scanning, multi-factor authentication, and enhanced recovery planning, the proposal signals something broader: a move toward a more prescriptive and auditable cybersecurity framework for organizations that create, receive, maintain, or transmit electronic protected health information.

Why the Proposed Rule Matters

Healthcare organizations have long operated under a HIPAA Security Rule designed to provide flexibility in how security safeguards are implemented. That flexibility has allowed organizations to tailor cybersecurity programs to their size, complexity, and risk profile. The healthcare threat landscape, however, has changed dramatically since the Security Rule was originally introduced. Ransomware attacks, third-party breaches, cloud computing, remote access, and increasingly sophisticated threat actors have elevated cybersecurity from an IT concern to a patient safety, operational resilience, and compliance issue.

The proposed updates appear intended to create greater consistency across the healthcare sector by establishing clearer expectations for how organizations protect electronic protected health information (ePHI). Regulators are placing greater emphasis not only on whether safeguards exist, but also on whether organizations can demonstrate that those safeguards are operating effectively and supported by appropriate documentation.

One of the most consequential aspects of the proposal is the practical elimination of the longstanding distinction between ‘required’ and ‘addressable’ implementation specifications. Historically, healthcare organizations could determine whether certain safeguards were reasonable and appropriate for their environment. Under the proposed rule, many of those safeguards would become mandatory requirements, significantly narrowing the discretion organizations have traditionally exercised when designing compliance programs.

The result is a framework that is more prescriptive, more measurable, and likely to require stronger evidence that security controls have been implemented, tested, and maintained. For healthcare leaders, the proposal is less about any single new requirement and more about a broader shift in regulatory expectations.

What Healthcare Organizations Should Be Doing Now

Although the proposed rule has not been finalized, it provides a useful framework for evaluating the maturity of existing cybersecurity and compliance programs. Many of the safeguards receiving the greatest attention including vulnerability management, penetration testing, multi-factor authentication, encryption, asset inventories, and incident recovery planning are already recognized as important security practices. The proposal signals that regulators may soon expect more organizations to implement them consistently and demonstrate that they are operating effectively.

For many healthcare organizations, the first step is gaining a clear understanding of current capabilities. Leadership teams should assess whether they have visibility into the systems, devices, applications, and data flows that support electronic protected health information. Without a reliable inventory of assets and an understanding of where sensitive data resides, it becomes difficult to evaluate risk, prioritize remediation efforts, or demonstrate compliance. The proposed rule places particular emphasis on these foundational activities because they support nearly every other aspect of a cybersecurity program.

Organizations should also evaluate how they identify and address vulnerabilities. Under the proposal, vulnerability scanning and penetration testing would become more formal compliance expectations. That shift reflects growing recognition that security programs must do more than document risks; they must continuously identify weaknesses, prioritize remediation, and verify that corrective actions are effective. Healthcare organizations that already perform these activities may need to focus on consistency, documentation, and evidence retention. Others may need to establish more structured testing and vulnerability management processes.

The proposal also reinforces the importance of resilience. Cybersecurity incidents are no longer viewed solely as technology events. They can disrupt patient care, interrupt operations, delay revenue cycles, and affect an organization’s reputation. As a result, organizations should review incident response procedures, recovery capabilities, and the extent to which critical systems and data can be restored following a disruption. Regulators appear increasingly focused on whether organizations can continue operating during and after a cyber event, not simply whether they have policies in place.

Finally, healthcare organizations should not overlook the role of third parties. Business associates, vendors, and service providers often create, receive, maintain, or transmit electronic protected health information on behalf of covered entities. The proposed rule suggests greater scrutiny of vendor safeguards and stronger expectations for validating that security controls are operating as intended. Organizations that rely heavily on external providers may want to revisit vendor risk management practices and determine whether sufficient oversight and documentation exist today.

Putting This Into Practice: Healthcare IT Risk Advisory

AAFCPAs’ IT Risk Advisory practice helps healthcare organizations evaluate their readiness for the proposed HIPAA Security Rule changes and the broader shift toward more prescriptive cybersecurity expectations. Our specialists work with organizations to assess current safeguards against proposed requirements, identify gaps in areas such as vulnerability management, penetration testing, multi-factor authentication, encryption, asset inventories, network mapping, incident response, and recovery planning, and strengthen the documentation needed to support compliance efforts. We also help organizations evaluate third-party risk management practices and determine whether vendor oversight aligns with evolving regulatory expectations. Whether you’re assessing the potential impact of the proposed rule or prioritizing next steps, we provide practical guidance that helps organizations make informed decisions, reduce risk, and strengthen operational resilience.

These insights were contributed by Michael Anderson, CISSP, CEH, CCNP, Consulting CISO & Certified Ethical Hacker.

Questions? Reach out to our author directly or your AAFCPAs partner.

AAFCPAs offers a wealth of resources on cybersecurity and IT risk. Subscribe to get alerts and insights in your inbox.

Author Bio

About The Author.

More Articles

Related Insights.

Stay up-to-date on trending topics, fresh perspectives, in-depth analysis, and regulatory alerts that affect your business.
See All Trending Topics