
Many compliance teams still treat "HIPAA compliant" and "cyber secure" as interchangeable. They're not. HIPAA sets the legal floor. Real security is what you build on top of it, every single day.
This guide breaks down how HIPAA and cybersecurity actually intersect, what the Security Rule requires, the safeguards you need in place, real breach examples, and where the NIST Cybersecurity Framework fits into the picture.
Key Takeaways
- The HIPAA Security Rule mandates administrative, physical, and technical safeguards for ePHI as the baseline for compliance.
- HHS's proposed 2025 rule drops "addressable vs. required," mandating MFA and encryption for every covered entity.
- Annual risk analysis, ongoing training, and continuous monitoring reduce breach risk more than any single security tool.
- Organizations treating HIPAA as continuous governance recover faster and see fewer OCR findings than checklist-only compliance.
How HIPAA Relates to Cybersecurity: Understanding the Security Rule
HIPAA is a federal law. The HIPAA Security Rule (45 CFR Parts 160 and 164, Subpart C) is the specific regulation that turns "protect patient data" into enforceable technical and operational requirements for electronic protected health information, or ePHI.
It's easy to confuse this with the Privacy Rule, but they cover different ground:
| Rule | Scope |
|---|---|
| Privacy Rule | Protects all protected health information, paper and electronic |
| Security Rule | Protects only ePHI created, received, maintained, or transmitted electronically |
The Security Rule codifies what's known as the CIA triad: confidentiality, integrity, and availability. Confidentiality keeps records out of unauthorized hands, while integrity ensures data isn't altered improperly.
Availability means the system is actually up when a nurse needs to pull a chart at 2 a.m. During a ransomware event, availability failures can matter just as much as data theft.
Who has to comply? Covered entities (health plans, clearinghouses, and providers who transmit standard electronic transactions) along with their business associates and subcontractors must meet these requirements.
The 2025 Proposal to Strengthen the Rule
In January 2025, HHS issued a Notice of Proposed Rulemaking aimed at closing long-standing gaps. Proposed (not yet final) changes include:
- Mandatory multi-factor authentication, with limited exceptions
- Mandatory encryption of ePHI at rest and in transit
- Required network segmentation
- A compliance audit at least once every 12 months
- Elimination of the "addressable vs. required" distinction entirely

Organizations with MFA, encryption, and audit logging already built into their systems, such as those using ComplyGovern's HIPAA-aligned platform, are already positioned to meet these proposed requirements without a scramble.
According to the HHS factsheet on the proposed rule, the current Security Rule stays in effect until this rulemaking is finalized. Don't wait for the final version to start closing these gaps.
Why HIPAA Cybersecurity Compliance Matters
The financial stakes climbed sharply. Under 2026 statutory adjustments, civil penalties now range from $145 per violation at the lowest culpability tier to $2,190,294 per violation for uncorrected willful neglect, with a matching $2,190,294 annual cap for identical violations.
| Culpability Tier | Per-Violation Range | Annual Cap |
|---|---|---|
| No knowledge, reasonable diligence exercised | $145 – $73,011 | $2,190,294 |
| Reasonable cause, no willful neglect | $1,461 – $73,011 | $2,190,294 |
| Willful neglect, corrected in time | $14,602 – $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 – $2,190,294 | $2,190,294 |
Recent OCR resolution agreements show a pattern. Regional Women's Health Group settled for $320,000 after a ransomware breach exposed the absence of an accurate risk analysis. Assured Imaging paid $375,000 for the same core failure, plus late breach notification affecting more than 244,000 people. Missing or incomplete risk analysis is the recurring thread.
Beyond fines, healthcare breaches cost more than breaches anywhere else. IBM's research shows the average healthcare breach hit $7.42 million in 2025, compared to a $4.44 million global average across all industries — the highest of any sector for the 14th consecutive year.
There's a human cost too:
- Delayed treatments when systems lock up mid-shift
- Ambulance diversions when hospital networks go dark
- Forced reversion to paper charting, slowing every workflow
- Lasting reputational damage among patients and referring providers
Key HIPAA Security Requirements: Administrative, Physical & Technical Safeguards
The Security Rule organizes requirements into three buckets. All three rest on one foundation: a documented, ongoing risk analysis, not a one-time PDF filed away after an audit.
Administrative Safeguards
These govern people and process, not hardware. Requirements include:
- Designating a security official accountable for policies and procedures
- Workforce security clearance procedures to determine appropriate access
- A formal risk management program and sanction policy for noncompliance (sanctions are required, not optional)
- Regular security awareness training for all staff who touch ePHI
- Documented incident response procedures
Physical Safeguards
Physical safeguards stop unauthorized hands from reaching the machines that store or display ePHI:
- Facility access controls limiting who can physically enter server rooms and clinical areas
- Workstation use and security policies (think auto-locking screens in shared nursing stations)
- Device and media disposal procedures so decommissioned laptops or drives don't leak data years later
Technical Safeguards
This is where most cybersecurity tooling lives:
- Access controls: unique user IDs and automatic logoff after inactivity
- Audit controls: mechanisms that record and examine system activity
- Encryption for ePHI at rest and in transit
Platforms built with HIPAA-aligned architecture, such as ComplyGovern's audit logging and encryption at rest and in transit, bake these technical safeguards into daily workflows rather than leaving them to a patchwork of point tools.
Here's the catch most compliance teams miss: under the current rule, encryption and workforce clearance are technically "addressable," not required. That doesn't mean optional — you must document why you didn't implement them and what equivalent measure you used instead. The proposed 2025 rule would remove this ambiguity entirely, making MFA and encryption flatly required for nearly everyone.

HIPAA Cybersecurity Best Practices for Healthcare Organizations
Meeting the letter of the Security Rule and actually reducing breach risk are related but different jobs. Here's what separates organizations that stay ahead of OCR findings:
- Run risk analysis continuously, not annually. Treat every new system, vendor, or facility change as a trigger for reassessment, not just the calendar.
- Layer technical controls. Encryption, MFA, and network segmentation together close far more gaps than any single control alone. These layered controls also align directly with where HHS's proposed rule is heading.
- Train year-round, not once a year. Phishing simulations, social engineering scenarios, and password hygiene refreshers beat a single annual click-through module every time.
- Test your incident response plan at least annually. Ransomware recovery time is consistently one of the biggest drivers of total breach cost, and an untested plan rarely holds up once a real incident hits.
- Move off spreadsheets for risk tracking. Static trackers go stale the moment someone forgets to update a tab. Continuous compliance platforms, including ComplyGovern's automated evidence collection, policy lifecycle mapping, and real-time executive dashboards, replace that reactive scramble with ongoing visibility into where your safeguards actually stand.
That last point matters more than it sounds. A risk register that only gets touched before a survey functions as a documentation exercise, not an active risk management program. Platforms built around continuous monitoring connect policy updates, evidence, and findings automatically, so gaps surface in real time rather than during the post-breach investigation.
Real HIPAA Breaches & the NIST Framework Connection
Two incidents illustrate what happens when safeguards fail at scale.
Anthem, reported 2015: Nearly 79 million individuals affected. OCR's investigation found several failures common to large-scale breaches:
- No enterprise-wide risk analysis
- Insufficient review of system activity
- Inadequate access controls
These are the same categories of failure that show up in smaller OCR settlements year after year.
Change Healthcare, 2024: Roughly 192.7 million individuals affected, per the breach report filed with OCR in mid-2025. HHS describes it as an unprecedented disruption to patient care and privacy nationwide: pharmacies couldn't process claims, and providers across the country felt the impact for weeks.
The pattern isn't subtle. Both cases trace back to the same core requirement: a thorough, honest risk analysis that actually gets acted on.
HIPAA doesn't mandate a specific technical framework, but HHS and OCR routinely point to the NIST Cybersecurity Framework as an accepted structuring tool. Two resources make that connection concrete:
- A formal HHS crosswalk mapping NIST CSF functions to Security Rule standards, letting NIST-aligned organizations translate existing work into HIPAA compliance evidence
- Updated NIST implementation guidance for the Security Rule, refreshed in 2024 as a current reference point for compliance teams
This matters most when risk analysis becomes an ongoing discipline rather than an annual checkbox. Continuous monitoring tools, such as ComplyGovern's configurable risk registers, are built to close exactly that gap.

Frequently Asked Questions
How does HIPAA relate to cybersecurity?
The HIPAA Security Rule is the specific federal regulation requiring administrative, physical, and technical safeguards to protect ePHI. It's the legal foundation healthcare cybersecurity programs are built on, though genuine security requires more than the minimum it sets.
What is an example of a HIPAA breach?
The Change Healthcare ransomware incident in 2024 affected approximately 192.7 million individuals, disrupting pharmacy and claims processing nationwide. It stands as one of the largest healthcare breaches ever reported to HHS.
What is the NIST framework for HIPAA?
HHS published a crosswalk mapping the NIST Cybersecurity Framework to HIPAA Security Rule standards. It's a voluntary structuring tool for risk analysis, and following NIST alone doesn't automatically satisfy HIPAA obligations.
What are the three types of safeguards required by HIPAA?
Administrative safeguards govern policies, training, and workforce conduct. Physical safeguards protect facilities and devices from unauthorized access. Technical safeguards cover access controls, audit logs, and encryption for systems handling ePHI.
Who must comply with the HIPAA Security Rule?
Covered entities, including health plans, clearinghouses, and providers who transmit standard electronic transactions, must comply, along with their business associates and any subcontractors handling ePHI on their behalf.
What are the penalties for HIPAA violations?
Penalties range from $145 to over $2.19 million per violation depending on culpability, with an annual cap of $2,190,294 for identical violations. OCR resolution agreements consistently cite missing or inadequate risk analysis as the root failure.


