Resources Articles HIPAA and Cybersecurity: From Compliance Checklist to Continuous Protection

HIPAA and Cybersecurity: From Compliance Checklist to Continuous Protection

Top view of laptop with stethoscope in the background with Sedara branded elements and color.

Protecting patient information has always been central to HIPAA. Today, however, healthcare organizations must secure that information across a much larger and more complicated technology environment.

Electronic health records, cloud platforms, remote access, mobile devices, connected medical equipment, third-party vendors, and legacy systems can all create potential paths to electronic protected health information (ePHI). At the same time, ransomware and other cyberattacks can do more than expose sensitive data. They can interrupt appointments, delay treatment, disrupt billing, and affect an organization’s ability to deliver care.

That is why HIPAA cybersecurity cannot be treated as a policy exercise or an annual checklist. It requires an ongoing process for identifying risk, strengthening safeguards, monitoring the environment, responding to incidents, and documenting what has been done.

What Does the HIPAA Security Rule Require Today?

The HIPAA Security Rule applies to covered entities and their business associates. It requires regulated organizations to use reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI.

According to the U.S. Department of Health and Human Services, regulated organizations must:

  • Protect all ePHI they create, receive, maintain, or transmit
  • Protect against reasonably anticipated threats and hazards
  • Protect against impermissible uses or disclosures
  • Ensure workforce compliance with security requirements

The Security Rule is designed to be flexible and scalable. The controls appropriate for a large hospital system may differ from those needed by a smaller medical practice or healthcare business associate. That flexibility, however, does not remove the obligation to understand risk and implement appropriate safeguards.

Risk Analysis Is the Foundation

A HIPAA risk analysis is not simply a vulnerability scan, policy review, or questionnaire. It should identify where ePHI is created, received, maintained, and transmitted, along with the threats and vulnerabilities that could affect it.

The analysis should consider:

  • Systems, applications, devices, and cloud platforms that handle ePHI
  • Users and third parties with access to ePHI
  • Technical vulnerabilities and unsupported systems
  • Security controls already in place
  • The likelihood and potential impact of identified threats
  • Operational dependencies that could affect access to patient information
  • Gaps in monitoring, response, backup, and recovery capabilities

Risk analysis continues to be a significant enforcement priority. The HHS Office for Civil Rights has established a Risk Analysis Initiative focused on investigations involving potential failures to conduct an accurate and thorough assessment of risks to ePHI.

Completing the assessment is only the beginning. Organizations must use the findings to create a risk management plan, prioritize remediation, assign responsibility, establish timelines, and document progress.

The HIPAA Security Rule May Become More Specific

In January 2025, HHS published proposed changes intended to strengthen the HIPAA Security Rule. As of August 2026, these changes have not been finalized, and the existing Security Rule remains in effect.

The proposed HIPAA Security Rule changes would create more specific cybersecurity requirements, including:

  • Maintaining a technology asset inventory and network map
  • Reviewing and updating the inventory and network map at least annually
  • Requiring multi-factor authentication, with limited exceptions
  • Encrypting ePHI at rest and in transit, with limited exceptions
  • Conducting vulnerability scanning at least every six months
  • Conducting penetration testing at least annually
  • Using network segmentation
  • Establishing separate technical controls for backup and recovery
  • Restoring certain critical systems and data within 72 hours
  • Conducting an annual Security Rule compliance audit
  • Requiring greater documentation and verification from business associates

These are proposed requirements, not current mandates. Still, they provide a clear indication of where federal expectations are heading. Organizations that begin strengthening these areas now can improve their security posture while reducing the amount of work required if the changes are finalized.

Seven Priorities for Stronger HIPAA Cybersecurity

1. Know Where Your ePHI Lives

You cannot protect information if you do not know where it is stored, processed, or transmitted.

Maintain an accurate inventory of relevant devices, applications, servers, cloud platforms, databases, identities, and vendors. Document how ePHI moves between internal systems and outside organizations.

Asset inventories must also be maintained over time. New systems are added, devices are replaced, integrations change, and old accounts or applications may remain active long after they are needed.

2. Control Access to Patient Information

Access should be based on an individual’s role and limited to what that person needs to perform their job.

Organizations should regularly review:

  • Privileged and administrative accounts
  • Inactive and former employee accounts
  • Shared accounts
  • Remote access
  • Vendor access
  • Accounts with passwords that do not expire
  • Systems that do not support multi-factor authentication

Multi-factor authentication should be used wherever it is technically feasible and appropriate, particularly for remote access, email, administrative accounts, and systems containing ePHI.

3. Manage Vulnerabilities and Unsupported Technology

Healthcare organizations often rely on systems that cannot be patched or replaced without affecting clinical operations. That makes it important to understand which vulnerabilities present the greatest risk and where compensating safeguards may be needed.

HHS guidance emphasizes that patching is not a one-time activity. Organizations should maintain an ongoing process for identifying missing patches, obsolete software, insecure configurations, and newly discovered vulnerabilities.

The January 2026 OCR Cybersecurity Newsletter specifically highlights asset inventory, vulnerability scanning, patching, system hardening, and the removal or disabling of unnecessary software and services.

4. Monitor for Suspicious Activity

Preventive controls cannot stop every attack. Healthcare organizations also need the ability to identify unusual activity and respond before it becomes a larger incident.

Effective monitoring may include:

  • Endpoint detection and response
  • Network detection and response
  • Centralized collection and analysis of relevant security logs
  • Monitoring for changes to privileged access
  • Detection of missing or disabled security tools
  • Alerts for suspicious authentication activity
  • Defined escalation and response procedures

Collecting logs is not enough. The organization must know which events matter, who will review them, and what should happen when suspicious activity is detected.

5. Prepare for Ransomware and Operational Disruption

HIPAA cybersecurity is not only about confidentiality. The Security Rule also requires organizations to protect the integrity and availability of ePHI.

Organizations should maintain tested plans for:

  • Responding to a cybersecurity incident
  • Continuing critical operations during an outage
  • Backing up ePHI and important system configurations
  • Isolating affected systems
  • Restoring data and services
  • Communicating with leadership, legal counsel, vendors, insurers, and other stakeholders
  • Evaluating whether an incident requires notification

Backups should be protected from the same credentials and systems that an attacker could compromise. Restoration procedures should be tested so the organization knows whether recovery objectives can actually be met.

Tabletop exercises can help leadership, IT, security, legal, communications, and clinical teams understand their responsibilities before a real incident occurs.

6. Validate That Security Controls Work

Policies and purchased tools do not automatically reduce risk. Controls must be configured, monitored, maintained, and tested.

Vulnerability assessments can identify known weaknesses and missing safeguards. Penetration testing goes further by determining whether weaknesses can be combined or exploited to gain unauthorized access.

After remediation, retesting helps confirm that the changes were effective and that the original path to compromise has been closed.

7. Document Decisions and Progress

HIPAA compliance requires evidence.

Organizations should be able to demonstrate:

  • When the risk analysis was performed
  • What systems and ePHI were included
  • Which risks were identified
  • How remediation priorities were established
  • Who is responsible for each action
  • Which safeguards have been implemented
  • Why alternative safeguards were selected
  • How incidents, assessments, training, and testing were documented
  • Whether remediation activities were validated

This documentation should reflect the organization’s actual environment. Policies that have not been implemented or evidence that has not been updated can create a misleading picture of readiness.

Do Not Forget Business Associates

Cloud providers, billing services, software vendors, consultants, managed service providers, and other third parties may create, receive, maintain, or transmit ePHI on behalf of a covered entity.

A signed Business Associate Agreement is important, but it is not a substitute for understanding how the vendor protects ePHI.

Organizations should evaluate:

  • What information the vendor can access
  • Where that information is stored
  • How access is authenticated and monitored
  • Whether subcontractors are involved
  • How security incidents are reported
  • What happens to the data when the relationship ends
  • Whether the vendor can support the organization’s continuity and recovery requirements

Third-party risk should be incorporated into the organization’s broader risk analysis and risk management process.

HIPAA Compliance Is an Ongoing Cybersecurity Program

There is no single product that makes an organization HIPAA compliant. Compliance is built through coordinated policies, technology, people, oversight, testing, and evidence.

The most effective programs create a repeatable cycle:

  • Identify assets, ePHI, threats, and vulnerabilities.
  • Prioritize risk based on potential business and patient impact.
  • Implement reasonable and appropriate safeguards.
  • Monitor for threats and control failures.
  • Respond to incidents and remediate findings.
  • Validate that improvements are working.
  • Document results and repeat the process as the environment changes.

This approach does more than prepare an organization for an audit. It helps protect patient trust, support uninterrupted care, and reduce the operational impact of a cybersecurity incident.

How Sedara Can Help

Sedara helps healthcare organizations turn HIPAA cybersecurity requirements into a practical, sustainable security program.

Our services can support organizations through:

Whether your organization needs to complete a risk analysis, address known gaps, improve monitoring, or build a more mature cybersecurity program, Sedara can help you determine where to begin and what to prioritize next.

Contact Sedara to discuss your HIPAA cybersecurity needs.

This article is provided for general informational purposes and does not constitute legal advice. Organizations should consult qualified legal or compliance professionals regarding their specific HIPAA obligations.

Accomplish your security & compliance goals.
Easier.

Get a Demo