EPISODE · Jul 15, 2026 · 26 MIN
Healthcare Compliance Updates
from Tech for Business
In this episode, Nate, CIT’s director of cybersecurity discusses proposed HIPAA Security Rule overhauls aimed at strengthening healthcare cybersecurity after major breaches and downtime incidents. Nate explains that the vote on the proposed changes was pushed back by one year (to 2027), but organizations should still start planning because implementation is typically required within 180 days of the final rule. Key shifts include moving many controls from “addressable” to “required,” enforcing multi-factor authentication for access to ePHI/EMR systems, requiring encryption in transit and at rest with no exceptions, and strengthening risk analysis and governance with formal documentation, asset inventories, network/data flow mapping, and executive engagement. The proposal also emphasizes incident response with a 72-hour service restoration plan, more frequent vulnerability scanning, annual penetration testing, and third-party assessments.00:00 HIPAA Rule Update00:22 Why HIPAA Is Outdated01:58 Breaches Drive Reform02:46 Timeline And Delay04:14 Addressable To Required04:57 MFA And Encryption Mandates06:50 Risk Analysis And IR Plan09:27 Cost And Budget Impact13:08 Biggest Hurdle MFA16:33 How It Compares To Others18:15 What Might Change21:58 Vendors And Education23:23 Action Items And Wrap UpResource: https://www.hipaajournal.com/hipaa-security-rule-update-postponed/
Embed this episode
NOW PLAYING
Healthcare Compliance Updates
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.