Healthcare Already Lives by This Rule. Its Networks Should Too

For two decades, HIPAA let proven security controls stay optional. The breaches that followed were not.

A colleague in healthcare shared a belief to me that is fundamental to his business: if the science exists to improve patient care, providers should use it.

He is right. And healthcare cybersecurity has spent more than two decades proving how often that simple idea gets ignored.

How "Addressable" Quietly Became "Optional"

Since 2003, the HIPAA Security Rule has sorted its safeguards into two buckets: required and addressable. Required means you do it. Addressable was meant to add flexibility, letting an organization adopt an equivalent control or document why a given one was not reasonable for its environment.

In practice, addressable became optional. Encryption was too expensive. Multi-factor authentication was too disruptive. So the control did not get implemented, and a paragraph explaining the gap got written instead. Auditors accepted it, and the distance between what the rule intended and what organizations actually did widened every year.

The Technology Was Never the Problem

MFA is not cutting-edge. Encryption is not exotic. Both have been affordable, well understood, and widely available for years. The question was never whether the science existed. It was whether anyone would use it.

Then the Bill Came Due

Change Healthcare remains the largest healthcare data breach on record, and it traces back to a single server that did not require multi-factor authentication. An attacker logged in with stolen credentials, moved through the network for days, and left with roughly six terabytes of data affecting close to 190 million people.

The control that would have stopped the initial login was a setting. It shipped with the platform. It was not turned on.

What Is Actually Required Today

There is a proposed update to the Security Rule that would end the addressable loophole and make MFA, encryption, and network segmentation flatly required. As of this writing it is still only proposed. The target finalization window has passed with nothing published, and the agency is still working through thousands of public comments. So here is the honest line between what is enforceable today and what is not: the new mandate is not law yet, and it may still change.

But you should not require a mandate. That is exactly why this is worth discussing. You should not need a federal rule to make you switch on protection that already exists and already works.

And the absence of a final rule does not mean the absence of consequences. This past April, regulators settled four separate ransomware cases for more than a million dollars combined, each one citing the same root failure: the organization never did the basic work to find and close its gaps before the breach.

So take the standard healthcare already holds for patient care and point it at the network. If the proven tool exists, use it. Not when a rule forces your hand. Now, while it is still your decision and not a finding in someone's investigation.

Where Promethos Fits

Knowing which proven controls your business actually needs, and making sure they are switched on and documented, is the work we do at Promethos Cyber Services. If your company is big enough to carry real risk but too small to justify a full-time security team, that is exactly who we serve. Reach out. We can help.

See what Promethos can do for you: Promethos Services

Sources

Chay Butler is the founder of Promethos Cyber Services and brings roughly 30 years in tech and cybersecurity, from front-line technical support to Principal Security Engineer roles, at large companies including ALLTEL, Web.com, and Verizon. He holds the CISSP, GISP, and GCIA certifications, as well as a B.S. in Leadership from the University of West Georgia.

Promethos offers fractional CISO services and security consulting to upper SMB and lower mid-market companies, carrying no product commissions and no vendor relationships. The only thing being sold is the advice itself.

Take the free Strategic Security Pulse Check now, or visit the Contact page for more options.