Healthcare Compliance updates

Nate, CIT’s director of cybersecurity discusses proposed HIPAA Security Rule overhauls aimed at strengthening healthcare cybersecurity after major breaches and downtime incidents. Nate explains that the vote on the proposed changes was pushed back by one year (to 2027), but organizations should still start planning because implementation is typically required within 180 days of the final rule.

Heatlhcare compliance updates

Watch the Episode

Healthcare Compliance: What HIPAA Updates Mean for Your Practice

HIPAA was written to protect healthcare data 27 years ago. Not to secure it — to move it. The shift feels subtle until you realize what it means: the rules that govern how your patient records flow between providers were never designed to stop a ransomware attack or prevent a breach.

That gap is closing. And it’s going to reshape how you run your practice.

Summary

  • HIPAA’s proposed security rule overhaul, delayed a year to 2027, marks the first major shift in healthcare cybersecurity standards in decades — turning “nice to have” controls into mandatory requirements.
  • Multi-factor authentication, encryption at rest, formal incident response plans, and comprehensive asset inventories are no longer optional. They’re the floor.
  • The real challenge isn’t the technology — it’s cultural. Solutions like Imprivata and YubiKeys make compliance operationally seamless. The work is educating staff, budgeting time, and planning ahead.

The 27-Year Lag

HIPAA’s original intent was pure: ensure citizens could access their healthcare information anywhere, anytime. Enable the flow. That worked fine through the early 2000s, when computing was centralized and threats were different.

Then healthcare breaches exploded. Change Healthcare. Other giants. Millions of patient records leaked. Government watched the breach count climb and finally acted.

Nate, CIT’s Director of Cybersecurity, puts it bluntly: “Healthcare today is one of the least regulated, regulated industries because it’s so far behind on cybersecurity.” Financial services, manufacturing — they were locked down years ago. Healthcare, the industry entrusted with people’s lives and intimate data, was playing catch-up.

The proposed HIPAA Security Rule is the corrective. It’s not gentle. And it’s not optional anymore.

From “Addressable” to “Required”

Here’s how the shift lands in practice.

Today, HIPAA controls fall into two buckets: required (mandatory) and addressable (risk-dependent). That’s changing. Controls that were addressable are flipping to required. The choice disappears.

Multi-factor authentication is the loudest example. For years, healthcare providers could skip it for patient-facing staff. Not anymore. Every access to electronic protected health information (ePHI) or an electronic medical record (EMR) system requires it. No exceptions. Encryption is similar — it was possible to document why you weren’t encrypting data in certain cases. The new rule strips that out entirely. Encrypt in transit. Encrypt at rest. Done.

The same logic applies to incident response. Right now, many organizations have a rough plan, maybe it’s in a Word doc, maybe it’s verbal. The new rule demands a formal, written incident response plan with a specific requirement: restore services within 72 hours of a ransomware attack or other incident. No two-week recovery window. That’s existential for a hospital.

Nate sees this as actually good news for patients: “When the hospital is down for two weeks, that’s a direct contrast to [providing quality care]. And so that’s actually something that we should be excited about — if you are a care provider and your company or organization hasn’t had that, and you’re deeply passionate about saving lives or improving health, they now have to do it.”

The Cost Question

This is where smaller practices tense up. Implementation costs vary wildly.

Multi-factor? Could be free if you’re using Microsoft (it’s included). Could be $10–$15 per user if you need third-party integration. Solutions like Imprivata or YubiKeys handle this elegantly for hospitals without slowing doctors down — a badge swipe replaces passwords — but they’re enterprise-grade in price.

Encryption can be a configuration change on cloud infrastructure (basically free beyond subscription costs) or require new software licenses. Risk analysis, formal incident response planning, vulnerability scanning — all of these depend on what you already have.

Here’s the real cost: consultant hours. If you need help building a formal risk register, documenting your data flows, or running vulnerability assessments regularly, you’re looking at budget. If you have the internal resources, you can do it yourself. But in healthcare, where time literally is money, internal hours often cost more than outsourcing.

The Hidden Sticking Point: Multi-Factor Friction

Every healthcare organization Nate talks to has the same concern: multi-factor will slow down doctors.

It’s a real problem. A physician juggling five patients can’t stop to type a code every time they log into the EMR. So the industry solved it. Imprivata is the standard — a keychain badge that logs clinicians in instantly, no password required. It’s multi-factor authentication that feels like a door key.

For smaller practices, there are alternatives. YubiKeys are hardware security keys that work on web and desktop systems. Some include biometric verification. None of them require hunting for your phone or typing codes.

The cultural shift is just as important as the technology. Multi-factor is already normal for banking, email, retail. It’s becoming normal in healthcare. Once it’s routine, it stops feeling like friction.

Timeline: A Year to Prepare, Not a Year to Delay

The proposed rule was due for a vote in May 2026. It got pushed. As of the time of this recording, it’s been pushed another year — into 2027.

That’s a gift, not a reprieve.

“This does not mean ignore this for a year,” Nate says. “It means evaluating, start having discussions.” Most organizations, when a rule becomes final, have 180 days to implement. For a large healthcare provider, that’s millions of dollars in rushed spending. For any provider, it’s scrambling.

The smart move is to start now. Budget for it. Inventory your systems and data flows. Run a risk assessment. Find out where the gaps are before you’re under a deadline.

One Question Before You Close

The people listening to this either run healthcare organizations or support them: vendors, consultants, IT teams. Either way, Nate has one ask: don’t just bolt on tools.

“I can slap tools into any network and call it good, but if no one does anything with the results off of that, you didn’t actually drive change at the end of the day.” A vulnerability scan without a remediation plan is theater. An incident response playbook that nobody knows about is worse than useless.

Healthcare compliance isn’t about checking boxes. It’s about building operational resilience so your team can do what they signed up for — care for people.

Ready to Get Ahead?

Want to dive deeper into what these changes mean for your practice? Listen to the full conversation with Nate, Director of Cybersecurity at CIT, where he walks through the specific requirements, cost models for different organization sizes, and the roadmap for implementation.

Enjoyed This Episode?

Subscribe to Tech for Business and get practical IT insights for SMB leaders every week. Or reach out — we’d love to hear what topics you want us to tackle next.