← Back to home

Service

Chris Gainus · Security & Compliance

Healthcare Security & Compliance

HIPAA, TCPA, PCI DSS, and RADV audit readiness. Preparing clinics for the proposed 2026 HIPAA Security Rule update: mandatory MFA, encryption at rest and in transit, and annual security risk assessments. Entra ID Conditional Access, Elastic SIEM, and Microsoft Defender for Endpoint deployed across multi-site clinic networks.

The problem: most clinics are not ready for what is coming

I walk into healthcare organizations all the time and find the same posture. Shared admin accounts. No MFA on RDP connections. EHR data sitting on unencrypted drives. Vendor access logged nowhere. Security risk assessments that are a check-the-box PDF from three years ago, filed in a drawer nobody opens.

That was survivable before. It is not survivable now.

The proposed 2026 HIPAA Security Rule update changes the math. Mandatory MFA on all systems that access electronic protected health information. Encryption at rest and in transit is no longer an addressable implementation specification, it is required. Annual security risk assessments become enforceable, not optional. The comment period happened. The final rule is coming. When it lands, the gap between "we have a policy" and "we actually enforce it" becomes an OCR enforcement action.

Beyond HIPAA, TCPA violations from unconsented outreach are a separate exposure. PCI DSS applies to anyone taking payments. RADV audits from CMS require you to demonstrate that the data behind your risk adjustment submissions was secure from tampering throughout the reporting period. Each of these has its own requirements. Most organizations handle them reactively, after a letter arrives, which is the most expensive way to do it.

The approach: assess, prioritize, fix

I do not write a hundred-page report and hand it over. I assess the gaps, rank them by actual risk, and fix them. The work falls into three stages.

1. Security assessment

A hands-on review of the environment. Active Directory configuration, Entra ID tenant policies, network segmentation, endpoint protection status, SIEM coverage, encryption state at rest and in transit, vendor access controls, backup and recovery posture, and existing policies versus actual configuration. I check what the security risk assessment says against what the network actually does. Those two things rarely match.

The assessment produces a prioritized gap list. Not a generic "you should consider MFA" recommendation. A specific list: these 14 workstations have no MFA, these three VPN accounts use shared credentials, this NAS volume holds 2.4TB of PHI and is unencrypted, these four vendors have persistent RDP access with no session logging. Actionable. Ranked by risk and remediation effort.

2. Identity and access controls with Entra ID

Most multi-site clinics I work with are running Active Directory with basic Group Policies, if that. Entra ID Conditional Access is the next layer. I deploy conditional access policies that enforce MFA, restrict access by location and device state, block legacy authentication protocols, and require compliant devices for PHI access.

The goal is to make it structurally difficult to do the wrong thing. A user on an unmanaged device from an unrecognized IP cannot reach the EHR even if their credentials are valid. A vendor account cannot RDP into a clinic server at 2am from an IP in a country the organization has never operated in. These are not theoretical policies. These are real attacks I have seen in SIEM logs.

3. Visibility and detection with Elastic SIEM

You cannot protect what you cannot see. Elastic SIEM gives me centralized visibility across the environment. Windows Event logs, firewall traffic, VPN connections, file access events, DNS queries, authentication failures. I build detection rules for the attack patterns that matter in healthcare: credential stuffing against VPN portals, lateral movement between clinic subnets, mass file access from compromised accounts, vendor accounts accessing data outside their contracted scope.

The SIEM integration is not a shelfware deployment. I configure alerts that go to people who respond to them. I tune out the noise so that what fires is actually worth investigating. And I build the dashboards that make audit evidence retrievable in minutes instead of days.

4. Endpoint protection with Microsoft Defender for Endpoint

Defender for Endpoint deploys across the workstation fleet and provides real-time threat detection, automated investigation, and response. I configure it for the healthcare context: EHR processes get sensitivity tags so any anomalous behavior around clinical data is escalated. USB device control policies prevent unauthorized data exfiltration. Network protection blocks communication with known malicious infrastructure.

Across a multi-site clinic network, this means every workstation reports into a single console. An incident at one site is visible across all sites. If a ransomware sample hits a workstation in clinic B, Defender for Endpoint contains it and the SIEM captures the full chain for the incident report.

Deliverables

At the end of an engagement, the client has:

The documentation package exists because I have been through audits. I know what the auditor asks for, in what format, and how far back they want to see evidence. I build the documentation as I deploy the controls, not after, so there is no reconstruction effort when the audit letter arrives.

Proof points

I have worked through HIPAA, TCPA, PCI DSS, and RADV requirements for healthcare organizations. Specifically:

These are not theoretical engagements. I deploy the tools, I write the policies, I build the documentation, and I stand behind the work when the auditor shows up.

Book a 15-minute scoping call to talk about your security posture and what the 2026 HIPAA update means for your organization.

Book a call