Stack Depth

HIPAA Technical Safeguard Evidence Gaps in Managed Security Platforms

Mandatory controls replace flexible compliance, and enforcement is accelerating.

Staff Writer · · 9 min read
Cover illustration for “HIPAA Technical Safeguard Evidence Gaps in Managed Security Platforms”
Compliance Evidence · September 26, 2026 · 9 min read · 1,923 words

HHS published a notice of proposed rulemaking on January 6, 2025 (90 FR 898), the first real rewrite of the HIPAA Security Rule since the 2013 Omnibus Final Rule. As of this writing the rule hasn't been finalized, but enforcement is expected to begin around July 2027, and organizations that wait to react are going to be behind.

The change that matters most is the removal of "addressable" as a category. It's the removal of "addressable" as a category. Under the current rule, an organization can look at a control like multi-factor authentication, decide it doesn't fit their setup, and write down why they skipped it. That option goes away. Every mandatory item applies to every covered entity and every business associate, with only a short list of narrow exceptions, and size alone no longer provides the flexibility it once did under the addressable framework.

Security no longer functions as a checklist filled out once a year; it now operates as architecture, where a system either enforces the control at all times, or it doesn't.

The specific list of things moving from "addressable, maybe" to "mandatory, prove it":

  • Multi-factor authentication on every system touching ePHI, with only narrow, specific carve-outs
  • Encryption for data at rest and in transit
  • Network segmentation
  • A current asset inventory and network map
  • Anti-malware controls, now written into the rule as a required specification for configuring information systems consistently
  • Technical safeguards extended to phones, tablets, and any portable device, which pulls BYOD programs directly into scope

OCR enforcement in 2025 and its implications for smaller organizations

2025 set a record: 22 major enforcement actions, more than $148 million in total fines. Most of that dollar figure comes from one settlement, the $126 million Change Healthcare/UnitedHealth case, the largest in HIPAA's history. But the headline number hides a fact that should worry smaller practices more.

Look at who else got fined. Plastic Surgery Associates of South Dakota paid $500,000 following a ransomware investigation that exposed multiple compliance failures. Heritage Valley Health System paid $950,000 following a NotPetya infection, with OCR pointing to failed risk analysis, weak access authorization, and no real contingency plan. Gulf Coast Pain Consultants reached a $1.19 million resolution after a former contractor continued accessing protected health information after the relationship ended, an access-termination failure that OCR identified during its investigation. Smaller practices have also faced enforcement actions for procedural failures unrelated to large-scale breaches.

None of these are large-scale organizations comparable to a major national insurer. They're the exact size of business that assumes enforcement risk belongs to somebody bigger.

The penalty ceiling is climbing too. Starting January 28, 2026, the maximum fine for the most serious violation tier rises to $2,190,294, and a single breach can trip more than one penalty category at once, which stacks fast. Inside the 22 enforcement actions from 2025, 18 involved an inadequate risk analysis, nine of those involved ransomware specifically. Risk analysis failure appears in roughly three out of four cases, based on OCR's enforcement record. It is, by a wide margin, the single thing OCR finds most often when it goes looking.

Why healthcare remains the highest-stakes environment for a breach

745 breaches got reported in 2025, a record. Average remediation cost per breach hit $10.93 million, the highest of any industry for the fourteenth year running. In 2024 alone, 168 million people had their health data exposed in some breach or another.

Zoom out further: 7,419 healthcare data breaches on record through January 31, 2026, touching 935,521,931 individuals combined. That's a sector with more than an occasional bad year. That's a sector where the breach is the baseline condition, and the cost of getting caught unprepared keeps compounding on top of an already-elevated starting point.

The meaning of "evidence gap" in a managed security platform context

Having the right tools installed is not the same thing as having proof those tools are doing what the policy says they're doing, continuously, in a form an auditor can actually check. That gap between "we have a tool for that" and "here's the log showing it worked on the day it mattered" is where compliance risk quietly builds up.

Call it the paperwork myth: the idea that HIPAA is fundamentally a binder problem, solved by having the right policy documents on file. It is not, because HIPAA is not fundamentally a binder problem solved by having the right policy documents on file. If a control can't produce evidence on demand, on any given day, it isn't mature enough to satisfy an OCR audit, no matter how well the policy describing it reads.

Three things separate a program that can defend itself from one that just looks good on paper:

  • Continuous visibility: one unified view across endpoints, network gear, identity systems, cloud platforms, and whatever application actually touches ePHI, not five different dashboards nobody cross-references
  • Control-to-evidence mapping: every single requirement tied to a specific artifact, whether that's a log entry, an alert, an access review, a change record, or a signed agreement
  • Monitoring that runs all the time: alerts on failed logins, odd data exports, privilege changes, and unusual access patterns firing continuously, not switched on the week before an audit

Now the specific places where managed platforms tend to leave gaps, even when every individual tool is doing its job:

Audit logs scattered across systems. The Security Rule's audit controls standard requires a way to record and examine activity across ePHI systems. OCR cites incomplete or missing audit logging regularly in enforcement actions. When logs live in one place on the firewall, another place in the cloud console, and a third place in a vendor's dashboard, nobody can reconstruct a single coherent timeline for a specific incident. The pieces exist. The story doesn't.

MFA applied unevenly. A fair number of small and mid-size organizations lock down email with MFA and stop there, leaving the patient records system, the billing system, or the practice management platform wide open. The proposed rule closes that door by making MFA mandatory across every system that touches ePHI, not just the ones that felt urgent at the time.

Mobile devices nobody's watching. Current rules focus technical safeguards on workstations. The new rule extends the same requirements to phones, tablets, and any portable device. An organization whose device management covers company laptops but not the tablet a nurse carries on rounds has an access path nobody's monitoring.

Breach notification as a data problem in disguise. If a team can't say who accessed what, from where, on which device, and whether anything actually left the environment, they can't scope an incident honestly, and they can't defend their reporting decision when OCR asks.

Business associate agreements that exist only on paper. A signed BAA assigns responsibility. It doesn't install a single technical control. Covered entities still have to build enforced safeguards around how a business associate actually handles PHI, because contract language doesn't stop a breach.

Risk analysis that's gone stale. OCR has said, in multiple enforcement actions, that a risk analysis performed years ago and never updated since does not satisfy the requirement. It has to move with the environment.

Breach notification timeline proof requirements

The Breach Notification Rule sounds simple until an organization tries to comply with it under pressure. In practice it demands a full reconstruction: who touched the data, from what location, on what device, and whether the data left the network. Get that wrong and the scoping is wrong, and the report to OCR is built on guesswork.

Breaches touching fewer than 500 people have to be reported to HHS through the OCR web portal no later than 60 days after the calendar year in which the breach happened ends. Separately, once CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act) takes hold, healthcare organizations will have to report cyberattacks to CISA within 72 hours and any ransomware payment within 24 hours. The clocks are getting shorter, not longer.

Presence Health's $475,000 settlement had nothing to do with how the breach happened. Its $475,000 settlement had nothing to do with how the breach happened. It was purely about missing the 60-day window, and OCR found the same lateness recurring across multiple smaller breaches, treating the recurring lateness across multiple smaller breaches as compounding violations. The breach wasn't the failure that cost them. The inability to document and report on time was.

Retention matters just as much as speed. HIPAA requires security policies and procedures kept in writing or electronic form, and the supporting documentation behind them generally has to stick around for six years under 45 CFR § 164.316.

What a HIPAA security incident response procedure must contain

The Security Rule's incident procedures requirement covers any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, plus anything that interferes with how a system operates. That's a wide net.

Under that requirement, covered entities and business associates have to do three things: identify and respond to a suspected or known security incident, limit the damage as much as is practically possible, and document what happened and how it was handled.

HHS guidance spells out what a workable plan looks like in practice, not just in theory:

  • A response team with names attached to roles

The three cases from earlier make the abstract requirement concrete. Plastic Surgery Associates of South Dakota got fined $500,000 for having no policy at all for responding to a security incident. Heritage Valley Health System got fined $950,000 after NotPetya exposed failures in risk analysis, access authorization, and contingency planning, all at once. Gulf Coast Pain Consultants faced a $1.19 million resolution because a former contractor kept ePHI access after the relationship ended, a failure OCR identified in its investigation.

Managed platforms generating policy coverage without producing the technical evidence OCR audits

Compliance programs rarely fail at the policy level. They fail in the operating layer, the gap between what the document says and what the system is actually doing day to day. The policy says access is role-based, but the directory still has accounts for people who left two years ago. The standard says logs get reviewed, but the logs are split across three different consoles that don't talk to each other. The incident response plan exists on paper, but the business associate never signed terms that line up with the same reporting duties the covered entity is bound to.

Gap one: endpoint coverage that isn't actually complete. The proposed rule includes anti-malware controls as a required specification for configuring information systems consistently. An organization where some devices are managed and some aren't has a gap that's easy for an auditor to find and hard to explain away. The same logic applies to mobile: the proposed rule extends technical safeguards to phones, tablets, and portable devices, and an MDM setup that covers laptops but skips the tablet fleet leaves an access path to ePHI that nobody's watching.

Gap two: audit logs that can't be pulled into one story. The Security Rule's audit controls standard requires a mechanism to record and examine activity across the systems that touch ePHI. When that activity is split across a firewall appliance, a cloud console, and a vendor's own dashboard, with no single place to line them up chronologically, an organization can own every individual tool the rule requires and still fail the standard, because the standard is about being able to produce the story those tools were supposed to be telling all along. It's about being able to produce the story those tools were supposed to be telling all along.

Sources

  1. HIPAA
  2. HIPAA Security Rule Resolves To Hit the Gym and Bulk Up | Davis Wright Tremaine
  3. HIPAA Security Rule Update Delayed Until 2027
  4. compliancy-group.com
  5. perkinscoie.com
  6. hhs.gov

More in Compliance Evidence