Healthcare institutions and the organizations that support them are required to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This federal law prevents protected health information (PHI) from being disclosed without a patient's consent or knowledge.
Healthcare data breaches hit a record high in 2025, 772 large breaches, exposing the information of roughly 138 million people. Hacking and IT incidents drove more than 80% of those breaches. This surge resulted in 21 settlements and civil penalties in 2025, the second highest annual total on record.
The Intricacies of HIPAA Compliance
The U.S. Department of Health and Human Services (HHS) provides the HIPAA Privacy Rule as a tool to implement HIPAA requirements. The HIPAA Privacy Rule protects patients' health information while still allowing the necessary use of protected health information (PHI) to provide healthcare.
Which Organizations Need to Be HIPAA Compliant
HIPAA compliance applies broadly. Healthcare providers of every size, health plans and health insurance providers, healthcare clearinghouses, and business associates that handle patients' PHI all fall under its requirements.
The HIPAA Security Rule
The HIPAA Security Rule protects e-PHI, the subset of PHI that's created, received, stored, or transmitted electronically. Covered entities must protect their integrity, availability, and confidentiality, defend against cybersecurity threats, and train their workforce.
This part of HIPAA is overdue for a refresh. In January 2025, OCR proposed its first overhaul of the Security Rule since 2013. It would turn many addressable safeguards into firm requirements and add mandates like MFA, encryption of e-PHI at rest and in transit, vulnerability scanning, annual penetration testing, network segmentation, and an asset inventory.
The rule is still proposed, not final. More than 100 healthcare organizations have pushed back, and OCR's timeline has slipped to no earlier than July 2027. It's not law yet, but it reads like a preview of where the industry is headed, so getting ahead of it now beats scrambling later.
How Your IT Security Partner Can Help You Meet OCR's HIPAA Audit Requirements
Any CIO knows that preparing for a HIPAA audit takes a lot of work. Your IT security partner should be part of that preparation process, and they can help your organization meet these requirements with far less stress.
1. Emphasize HIPAA Training
HIPAA compliance training for your management and staff is a critical part of audit prep. Your IT partner can help you run these training sessions and document them properly.
An MSP can help you build and publish HR policies that prioritize training, and during an audit, OCR can question any member of your organization to confirm they understand the compliance requirements. At Net Friends, we have in-house Privacy Compliance and Risk Management Experts who can guide teams through annual HIPAA compliance training.
2. Perform a Risk Analysis
We recommend a thorough risk analysis to identify security gaps. Keep these documents current and easy to retrieve, since OCR investigators increasingly expect to see risk analyses that were updated within the past year, in line with the added rigor proposed in the pending Security Rule update.
3. Design a Risk Management Plan
The findings from your risk analysis will shape the best risk management plan for your organization. Your IT security partner or MSP will also help develop and document your policies to meet the Privacy and Security Rule requirements. Your risk management plan should cover incident response, breach notification, IT security and firewalls, and physical security. This documentation helps you pass a HIPAA audit and gives your organization a clear roadmap for day-to-day operations.
4. Assign a HIPAA Privacy Officer
One HIPAA requirement is assigning a privacy officer to manage compliance for each covered entity. You do not need to hire someone new for this. An existing staff member, or your MSP, can take on the role. This person ensures the security and privacy of your clients' PHI and confirms your organization meets HIPAA regulations. They are also responsible for reviewing your Business Associate Agreements (BAAs), since OCR examines your organization's third-party relationships involving e-PHI closely.
Net Friends Pro Tip: Your MSP can help you build a list of vendors and suppliers and document their security measures as outlined in each Business Associate Agreement.
5. Review HIPAA Compliance Policies
Documenting your policies is only half the job. OCR also wants to see how those policies show up in your operations. Talk with your management and staff regularly to see how well your policies are working in practice, and adjust when something is not landing. It also helps to keep a running implementation schedule, since auditors like to see how quickly and consistently you put policy changes into action.
6. Perform an Internal Audit
How about a dress rehearsal before the real thing? Your IT security partner can run an internal HIPAA audit, which surfaces problems in advance and keeps your team comfortable with the review process. Reviewing your own policies the way an OCR auditor would, asking whether they meet the regulatory intent and genuinely improve patient privacy and security. That outside perspective tends to uncover gaps you might miss.
7. Design and Execute an Internal Remediation Plan
This plan should address any vulnerabilities you found and shrink your organization's overall risk profile, and yes, it needs to be documented too. Include a schedule that outlines the core elements of your remediation plan and be ready to walk an auditor through it.
Net Friends Pro Tip: Treat HIPAA as a continual process rather than an annual fire drill.
8. HIPAA Compliance and Cybersecurity
Your organization's HIPAA compliance and cybersecurity efforts are two sides of the same coin. Preventing network security breaches protects your clients' PHI, especially now that hacking is behind many healthcare breaches. An effective IT security partner helps you meet your regulatory requirements while building a strong cybersecurity culture that outlasts any single audit cycle.
Net Friends Is Home to Your Top HIPAA Partners
Net Friends is committed to helping every organization we serve build a strong and sustainable cybersecurity culture. We have a long history of HIPAA expertise, and our internal operations are SOC 2 Type II certified. We will help you safeguard your clients' PHI, generate timely security reports, and meet HIPAA compliance standards through real world cybersecurity practices, not just paperwork. Contact Net Friends today and let's simplify your HIPAA audit prep together.
What to read next:
How We Became HIPAA Experts
Why Cybersecurity Training Is Important for Compliance
Mastering MSP Selection: Online Resources to Help You Evaluate & Choose
Take IT Off Your To-Do List.
Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.
At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.
