In early September, the HHS Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) hosted their annual HIPAA Security Conference at the NIST campus in Gaithersburg, Maryland. A healthcare compliance attorney's account of those two days, published by The HIPAA Journal, confirms what those of us working incident response in the healthcare sector have been telling clients for months: OCR is done accepting paper compliance. The regulators' message was consistent and pointed — risk analyses are still failing, the HIPAA Security Rule modernization is coming, and enforcement is increasingly focused on whether technical safeguards actually work, not whether they are documented.
For covered entities and business associates, this is not abstract policy chatter. Healthcare remains the most-breached and most-expensive sector for data incidents year over year, and ransomware crews continue to treat hospitals, specialty clinics, and their billing vendors as priority targets because operational pressure reliably converts to payment. When OCR investigates after a breach — and it investigates virtually every breach affecting 500 or more individuals — the deficiencies it cites are remarkably consistent: no enterprise-wide risk analysis, unencrypted ePHI, missing multi-factor authentication, flat networks, and audit logs that were never reviewed. The Gaithersburg conference reinforced that these are the exact areas regulators will scrutinize.
This post distills the defensive implications of what OCR and NIST communicated and translates them into an action plan your security and compliance teams can execute now.
Why This Matters Right Now
Three converging pressures make the conference takeaways urgent rather than informational:
-
The HIPAA Security Rule Notice of Proposed Rulemaking (NPRM). HHS issued its proposed overhaul of the Security Rule in early 2025 — the first major update since the rule was originally finalized. The proposal would eliminate the distinction between "addressable" and "required" implementation specifications, effectively making encryption, MFA, network segmentation, asset inventories, vulnerability scanning, and annual technical control testing mandatory rather than negotiable. OCR's presence and messaging at the NIST conference indicates the agency is preparing both the final rule and the enforcement posture to match.
-
Enforcement is shifting from paperwork to proof. OCR's recent resolution agreements and civil money penalties have centered on Security Rule failures discovered after ransomware attacks. The consistent theme from Gaithersburg: investigators want to see that your risk analysis was enterprise-wide, current, and actually drove remediation — and that your technical safeguards function as documented.
-
The threat picture OCR is tracking mirrors what we see in IR. Ransomware and large-scale hacking incidents remain the dominant cause of healthcare breaches reported to OCR, and the agency has repeatedly flagged that most of these incidents exploited basic, well-known control gaps — unpatched internet-facing systems, missing MFA on remote access, and lateral movement across unsegmented networks.
What Defenders Should Take From the Conference
1. The Risk Analysis Is the Keystone — and It's Still Failing
OCR officials have stated for years, and reiterated at this conference, that the Security Rule risk analysis (45 C.F.R. § 164.308(a)(1)(ii)(A)) is the single most-cited failure in breach investigations. The agency's expectations are specific:
- Enterprise-wide scope. Every system, application, device, and data flow that creates, receives, maintains, or transmits ePHI — including cloud services, medical devices, remote workers, and business associate connections. A risk analysis scoped only to the EHR is not a risk analysis.
- Current and living. Updated at least annually and after any significant environmental change: mergers, new EHR modules, cloud migrations, new vendor relationships.
- Tied to remediation. OCR looks for a documented risk management plan showing identified risks were rated, prioritized, assigned, and actually mitigated. An unremediated high finding from three years ago is an enforcement exhibit.
Defensive action: If your last risk analysis is older than 12 months, treat that as an open critical finding. Use NIST SP 800-66 Rev. 2 (OCR's own recommended implementation guide) as the methodology baseline, and map findings into a tracked remediation plan with owners and deadlines.
2. "Addressable" Is Going Away — Build to the Proposed Standard Now
The NPRM proposes making the following effectively mandatory. Organizations that adopted them early will face minimal lift; those that treated "addressable" as "optional" face a compressed, expensive compliance window:
- Multi-factor authentication on all systems accessing ePHI — including remote access, email, EHR administrative interfaces, and privileged accounts. From an IR standpoint, this single control would have prevented or blunted a large share of the healthcare ransomware intrusions we've worked.
- Encryption of ePHI at rest and in transit, with strictly documented, technically justified exceptions.
- Network segmentation separating ePHI systems from general IT, guest networks, and — critically — from medical devices and operational technology that cannot be patched on enterprise timelines.
- A written asset inventory and network map, refreshed annually, covering all systems that touch ePHI. You cannot defend or attest to what you cannot enumerate.
- Vulnerability scanning and penetration testing on defined schedules, with remediation SLAs.
- 72-hour restoration capability for critical systems — a direct response to ransomware downtime that has forced hospitals onto diversion and paper operations for weeks.
- Business associate verification — annually confirming, in writing, that downstream vendors have actually deployed required safeguards.
Defensive action: Run a gap assessment against the NPRM's proposed requirements today, not after finalization. Prioritize MFA coverage gaps (especially VPN, remote desktop, and service accounts), segmentation of clinical networks, and backup/restore testing with measured recovery times.
3. Ransomware TTPs Haven't Changed — Your Controls Should Assume Breach
The intrusion patterns behind the healthcare breaches OCR investigates remain depressingly consistent:
- Initial access via phishing, exposed remote services (RDP/VPN) without MFA, or exploitation of unpatched internet-facing appliances.
- Credential theft and privilege escalation, frequently abusing local admin reuse and unprotected service accounts.
- Lateral movement across flat networks into EHR databases, imaging systems, and file shares.
- Exfiltration of ePHI for double extortion, followed by encryption — often including destruction of backups reachable from the production domain.
Defensive action: Assume initial access will happen and engineer for containment. Concretely:
- Tier your administrative model so workstation admin credentials never authenticate to servers or clinical systems.
- Isolate backups (immutable or offline, separate credentials) and test restoration quarterly against the 72-hour benchmark.
- Deploy EDR with network isolation capability on clinical workstations and servers, and verify medical device segments can be quarantined without taking down patient care.
- Alert on the pre-ransomware behaviors — mass file access from a single host, VSS deletion, disabling of security tooling — rather than waiting for encryption.
4. Audit Logs Are an Enforcement Expectation, Not a Nice-to-Have
OCR expects organizations to not only maintain audit logs of ePHI access but to review them regularly and investigate anomalies. In breach investigations, "we had logs but nobody looked at them" is treated as a safeguard failure. The proposed rule strengthens these expectations with explicit testing and review requirements.
Defensive action: Centralize EHR audit logs, authentication logs, VPN logs, and EDR telemetry into a SIEM with defined review cadences and alerting on anomalous ePHI access (bulk record lookups, after-hours access by terminated accounts, access from unusual geography). Retain per your state requirements and OCR guidance — six years of documentation retention applies to Security Rule records.
5. Business Associates Are Your Attack Surface
A substantial share of large healthcare breaches now originate at business associates — billing vendors, transcription services, cloud hosting providers, MSPs. OCR's messaging reinforces that covered entities cannot outsource accountability. The proposed rule's requirement for annual written verification of business associate safeguards formalizes this.
Defensive action: Inventory every business associate with ePHI access, validate BAAs are current, and add a technical verification step — questionnaire plus evidence (SOC 2, pen test summaries, MFA attestation) — to annual vendor reviews. For high-risk vendors, require notification SLAs in the BAA that support your own 60-day breach notification obligations.
Executive Takeaways
-
Commission or refresh your enterprise-wide risk analysis now. Use NIST SP 800-66 Rev. 2 as the framework, cover every ePHI touchpoint including cloud and medical devices, and stand up a tracked remediation plan. This is OCR's #1 enforcement target and the foundation everything else depends on.
-
Gap-assess against the proposed Security Rule requirements. MFA, encryption, segmentation, asset inventory, 72-hour restoration, and control testing are moving from "addressable" to mandatory. Budget and build in 2026 to avoid a compressed compliance scramble.
-
Close the MFA and remote access gaps first. In our IR casework, the absence of MFA on VPN, RDP, email, or privileged accounts remains the most common single point of failure in healthcare ransomware events.
-
Prove your backups with timed restoration tests. A backup that has never been restored is a hypothesis. Test full restoration of the EHR and critical clinical systems quarterly and measure against a 72-hour recovery objective.
-
Operationalize audit log review. Centralize EHR, authentication, and network logs; alert on anomalous ePHI access; document the review process. OCR treats unreviewed logs as a missing safeguard.
-
Verify your business associates technically, annually. Collect evidence of safeguards, tighten BAA notification timelines, and know which vendors could trigger your breach notification obligations.
Remediation and Compliance Roadmap
| Priority | Action | Timeline |
|---|---|---|
| Immediate (0–30 days) | Validate MFA coverage on all remote access, email, and privileged accounts; remediate exceptions | 30 days |
| Immediate (0–30 days) | Confirm backups are isolated/immutable and complete a timed restore test of one critical system | 30 days |
| Short (30–90 days) | Complete enterprise-wide risk analysis per NIST SP 800-66 Rev. 2; open tracked remediation items | 90 days |
| Short (30–90 days) | Build/refresh asset inventory and network map of ePHI systems | 90 days |
| Medium (90–180 days) | Implement segmentation between clinical, corporate, guest, and medical device networks | 180 days |
| Medium (90–180 days) | Centralize audit logs into SIEM with documented review cadence | 180 days |
| Ongoing | Annual business associate verification, vulnerability scanning cadence, penetration testing, and incident response plan exercises | Continuous |
Authoritative references:
- OCR/NIST HIPAA Security Conference coverage: https://www.hipaajournal.com/ocr-nist-hipaa-security-conference/
- NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: https://csrc.nist.gov/pubs/sp/800/66/r2/final
- HHS HIPAA Security Rule NPRM (Federal Register, January 2025): https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
- HHS OCR Security Rule guidance: https://www.hhs.gov/hipaa/for-professionals/security/index.html
Organizations that treat the proposed rule as a blueprint — rather than waiting for the final text — will be both harder to breach and far better positioned when OCR comes asking questions after an incident. The time to close these gaps is before the final rule and before the ransom note, not after.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.