Episode notes
In this episode, Nate, CIT’s director of cybersecurity discusses proposed HIPAA Security Rule overhauls aimed at strengthening healthcare cybersecurity after major breaches and downtime incidents. Nate explains that the vote on the proposed changes was pushed back by one year (to 2027), but organizations should still start planning because implementation is typically required within 180 days of the final rule. Key shifts include moving many controls from “addressable” to “required,” enforcing multi-factor authentication for access to ePHI/EMR systems, requiring encryption in transit and at rest with no exceptions, and strengthening risk analysis and governance with formal documentation, asset inventories, network/data flow mapping, and executive engagement. The proposal also emphasizes incident response with a 72-hour service restoration plan, mo ...