By Daniel Casciato

The U.S. Department of Health and Human Services (HHS) is preparing to finalize sweeping updates to the HIPAA Security Rule, with changes expected by May 2026. The proposal reflects a broader effort to modernize healthcare cybersecurity in response to a rapidly evolving threat landscape, one increasingly defined by ransomware attacks, data breaches, and operational disruptions.

For healthcare organizations across South Florida and beyond, the proposed changes represent more than incremental adjustments. They signal a fundamental shift in how cybersecurity is defined, implemented, and governed.

John Christly, Vice President of Commercial Services at OneZero Solutions and a nationally recognized cybersecurity and compliance advisor, believes one of the most impactful changes is the elimination of the long-standing distinction between “addressable” and “required” safeguards.

“The removal of the distinction between ‘addressable’ and ‘required’ safeguards is one of the most significant structural changes ever proposed for the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” Christly says.

Historically, many organizations interpreted “addressable” controls as optional. Under the proposed rule, that interpretation will no longer hold. Instead, most safeguards, particularly those related to encryption and authentication, will become mandatory.

“By eliminating that distinction, the Department of Health and Human Services (HHS) is essentially saying that the baseline cybersecurity expectations for healthcare must be stronger and more consistent across the industry,” Christly explains.

This shift elevates cybersecurity beyond the IT department and into the boardroom.

“From a leadership perspective, this change elevates cybersecurity from a technical decision to a governance responsibility,” he says.

Mandating Core Security Controls

Among the most notable requirements are mandatory multifactor authentication (MFA) and encryption of electronic protected health information (ePHI), both at rest and in transit. While widely recognized as best practices, these controls have not always been consistently implemented across healthcare organizations.

Christly notes that implementing these safeguards is not without challenges.

“Multifactor authentication and encryption are widely recognized as foundational cybersecurity protections but implementing them effectively in healthcare environments presents unique challenges,” he says.

Legacy systems and medical devices are a major hurdle. Many were not designed with modern security controls in mind, making upgrades complex and, in some cases, risky to clinical operations.

Equally important is the human factor. Clinicians operate in fast-paced, high-pressure environments where any disruption can affect patient care.

“If security controls are implemented poorly, they can create friction that impacts patient care,” Christly says. “Successful organizations focus on implementing these controls in ways that support clinical workflows rather than hinder them.”

Despite these challenges, the benefits are clear. When properly deployed, MFA and encryption significantly reduce the risk of credential theft, ransomware attacks, and unauthorized access to sensitive data.

Visibility as a Foundation for Security

Another key requirement is the development and maintenance of a comprehensive technology asset inventory and network map, updated annually. While this may seem administrative, Christly emphasizes that it is foundational to effective cybersecurity.

“You cannot secure what you cannot see,” he says.

Healthcare environments are notoriously complex, encompassing electronic health records, imaging systems, connected medical devices, cloud platforms, and third-party integrations. Without a clear understanding of how these systems interact, organizations face blind spots that attackers can exploit.

“In my experience, many healthcare organizations have partial inventories but not a complete picture,” Christly notes.

The proposed rule aims to close that gap by requiring organizations to document where ePHI resides, how systems are connected, and which assets are most critical to patient care.

Rethinking Patch Management and Risk

The proposal also introduces stricter timelines for patch management, requiring organizations to address critical vulnerabilities within 15 days and high-risk issues within 30 days.

Christly acknowledges that these deadlines may be difficult for organizations relying on legacy infrastructure.

“Healthcare environments are unique because many systems cannot simply be patched the moment an update becomes available,” he says.

Updates often require vendor validation and clinical testing to ensure patient safety. However, the urgency behind these timelines is driven by real-world threats.

“Many of the ransomware attacks affecting healthcare organizations in recent years have exploited vulnerabilities that already had patches available,” Christly says.

To meet these expectations, organizations will need to adopt a more proactive and continuous approach to vulnerability management—one that prioritizes risks, coordinates across departments, and implements compensating controls when immediate patching is not feasible.

Addressing Regional Gaps in South Florida

South Florida’s healthcare ecosystem includes a wide range of providers, from large hospital systems to small physician practices. While larger organizations often have more mature cybersecurity programs, smaller providers frequently face resource constraints.

“The most common gaps we see involve incomplete risk analyses, limited visibility into connected systems, and inconsistent implementation of modern security controls,” Christly says.

Third-party risk is another growing concern, as providers increasingly rely on vendors and cloud-based services to support operations.

At OneZero Solutions, Christly and his team work with organizations to translate regulatory requirements into actionable strategies.

“That typically begins with a comprehensive risk assessment aligned to recognized frameworks such as the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF),” he says.

The ultimate objective extends beyond compliance.

“The goal is not simply compliance. The goal is operational resilience so that healthcare organizations can continue delivering patient care even in the face of cyber threats.”

Accelerating Incident Response Expectations

The proposed rule also requires certain security incidents to be reported within 72 hours, aligning healthcare with broader regulatory trends.

“A 72-hour window is becoming more common across multiple industries,” Christly says.

While many organizations already have incident response plans, the new requirement will demand faster detection, escalation, and decision-making.

“In many cases, the biggest challenge is not the reporting itself but the ability to detect incidents early enough to act within that timeframe,” he explains.

Meeting this expectation will require enhanced monitoring capabilities, centralized logging, and well-trained response teams.

Aligning with Industry Frameworks

Finally, the proposed updates bring HIPAA more closely in line with the National Institute of Standards and Technology Cybersecurity Framework, a widely adopted model for managing cybersecurity risk.

“Aligning the HIPAA Security Rule more closely with the National Institute of Standards and Technology Cybersecurity Framework is a very positive development for the healthcare industry,” Christly says.

This alignment provides organizations with a clearer roadmap for implementing security controls across key functions, including identifying risks, protecting systems, detecting threats, responding to incidents, and recovering from disruptions.

It also raises the bar for business associates and vendors, who will face increased scrutiny and accountability for their own cybersecurity practices.

“Ultimately, this alignment helps move the industry toward a more standardized approach to cybersecurity where organizations, vendors, and regulators are all working from a common framework,” Christly says.

Preparing for What Comes Next

As the final rule approaches, healthcare organizations should begin assessing their current security posture, identifying gaps, and developing a roadmap for compliance.

The proposed changes may be complex, but they reflect a necessary evolution in protecting patient data and ensuring the continuity of care.

In an industry where cybersecurity incidents can directly impact patient safety, the message from regulators is clear: stronger, more consistent protections are no longer optional—they are essential.

For more information, visit www.onezerollc.com.