top of page
Search

From Optional to Mandatory: The Exact Controls the New HIPAA Security Rule Requires You to Prove

Sep 9
5 min read

Updated: Sep 10

In the first article in this series, I made the case that the proposed HIPAA Security Rule turns compliance from a documentation exercise into an engineering discipline. This article gets specific. If "addressable" is disappearing, the obvious question every healthcare executive should be asking is: mandatory to do what, exactly? The Notice of Proposed Rulemaking that the HHS Office for Civil Rights published on January 6, 2025 answers that question in detail, and the answer is a set of controls that most organizations have partially implemented at best.


Below is the shortlist that matters most, and for each one, the harder question that separates a compliant program from an exposed one: not "do you do this," but "can you prove it to an auditor tomorrow."



Multi-Factor Authentication, Everywhere ePHI Lives


The proposed rule requires multi-factor authentication across access points to electronic protected health information. Most organizations will say they already have MFA. The gap is almost always in the exceptions. The legacy clinical application that only supports a password. The service account that scripts use to move data. The vendor remote-access pathway that was stood up years ago and never revisited. Under the current addressable regime, those exceptions were tolerated. Under the proposed rule, each one is a finding.


The evidence an auditor wants is not a policy stating that MFA is required. It is a configuration export showing MFA enforced on every system in scope, and a documented, risk-assessed plan for any technical exception that genuinely cannot support it. If you cannot produce that export today, you have work to do.



Encryption at Rest and in Transit


The rule proposes mandatory encryption of ePHI both at rest and in transit. This is the requirement that most cleanly illustrates the end of "addressable," because encryption has been the textbook example of an addressable specification for two decades. Organizations chose not to encrypt certain databases, or certain backup media, or certain internal transmissions, and documented a rationale. That option is closing.


Proof here means an inventory of every repository and transmission path that carries ePHI, mapped to the encryption applied to each. The places organizations get caught are the unglamorous ones: database backups written to unencrypted storage, internal service-to-service traffic assumed to be safe because it never leaves the data center, and data at rest on medical devices and imaging systems that were never treated as ePHI repositories in the first place.




Healthcare information security

A Written Asset Inventory and Network Map


The proposal requires a written inventory of technology assets and a network map showing how ePHI moves through the environment, kept current. This sounds administrative. It is actually the foundation the entire rule stands on, because you cannot encrypt, segment, monitor, or recover what you have not inventoried.


In my work assessing organizations as a HITRUST evaluator with DirectTrust and EHNAC, the asset inventory was often the first place a program's real maturity became visible. A current, reconciled inventory signals a program that is operated. A spreadsheet last updated two reorganizations ago signals a program that is described. The proposed rule forces the former. The evidence is a maintained inventory with a defined refresh cadence and a network diagram that a stranger could use to trace ePHI from ingestion to storage to backup.



Continuous Testing: Vulnerability Scans and Penetration Tests


The rule proposes vulnerability scanning at least every six months and penetration testing at least once a year. This is where many programs that look mature on paper fall down, because testing was never strictly required and therefore was often skipped in lean budget years. The Cybersecurity and Infrastructure Security Agency and the HHS 405(d) program have both pushed continuous testing as baseline hygiene for years; the proposed rule makes it non-negotiable.


Proof is straightforward and unforgiving: dated scan reports on the required cadence, an annual penetration test report from a qualified party, and, critically, evidence that findings were remediated and re-tested. A pen test report that sits on a shelf with its findings unaddressed is worse than no report, because it documents that you knew and did not act.



A 72-Hour Recovery Capability


The proposal requires the ability to restore critical systems and ePHI within 72 hours. Ransomware made this real. When an attacker encrypts your environment, the question is no longer whether your policy describes a recovery plan; it is whether you can actually restore operations before patient care and revenue are materially harmed. The evidence is a tested restoration, with logs showing recovery time, not a business continuity binder.



An Annual Compliance Audit


Finally, the rule proposes a formal audit of the organization's Security Rule compliance every twelve months. This is the requirement that ties all the others together, and it is the one that most closely mirrors the recurring examination cycle I run for clients. At MTC Group, we have taken multiple healthcare organizations through initial SOC 2 Type 1 and Type 2 examinations and carried several through repeat Type 2 renewals. The single most important lesson from that work applies directly here: the first audit is hard, and the recurring audit is what proves the program is real. An annual HIPAA compliance audit means the evidence has to exist not once, but continuously.



What Leaders Should Do


Do not read this list as six separate projects. Read it as one program with a single organizing principle: every control must produce evidence, and the evidence must be current. Start by mapping each mandated control to the specific artifact that proves it, then find the gaps between the artifact you should have and the one you actually have. That gap analysis is the entire game.


A fast, free way to find your biggest gaps before you invest in a formal engagement is my "Big Rocks" Information Security Risk Assessment, a 10-question, five-minute survey that maps directly to the highest-impact areas this rule puts in scope. It is linked from the MTC Group homepage and costs nothing.


The organizations that treat these controls as an evidence problem, not a policy problem, will be ready when the rule lands. The ones that update their binders will not. If you want help closing the distance between the two, that is exactly the work we do at MTC Group. Reach out at rick@mtcgroupllc.com.




Sources & Further Reading


  1. HIPAA Security Rule NPRM overview, U.S. Department of Health & Human Services, Office for Civil Rights

  1. Cybersecurity best practices, Cybersecurity and Infrastructure Security Agency

 
 
 

Comments


bottom of page