Healthcare Compliance Updates

Healthcare Compliance Updates

July 15, 2026 · 26 min · Season 5 · Episode 15

About this episode

Nate discusses proposed HIPAA Security Rule overhauls aimed at strengthening healthcare cybersecurity.

In this episode, Nate, CIT’s director of cybersecurity discusses proposed HIPAA Security Rule overhauls aimed at strengthening healthcare cybersecurity after major breaches and downtime incidents. Nate explains that the vote on the proposed changes was pushed back by one year (to 2027), but organizations should still start planning because implementation is typically required within 180 days of the final rule. Key shifts include moving many controls from “addressable” to “required,” enforcing multi-factor authentication for access to ePHI/EMR systems, requiring encryption in transit and at rest with no exceptions, and strengthening risk analysis and governance with formal documentation, asset inventories, network/data flow mapping, and executive engagement. The proposal also emphasizes incident response with a 72-hour service restoration plan, more frequent vulnerability scanning, annual penetration testing, and third-party assessments. 00:00 HIPAA Rule Update 00:22 Why HIPAA Is Outdated 01:58 Breaches Drive Reform 02:46 Timeline And Delay 04:14 Addressable To Required 04:57 MFA And Encryption Mandates 06:50 Risk Analysis And IR Plan 09:27 Cost And Budget Impact 13:08 Biggest…

More episodes of Tech for Business

Explore listener stats, chart rankings, contacts and more on the Tech for Business podcast page.