Skip to main content

Industry · Healthcare & HealthTech

A compromised credential here doesn't just mean a breach — it means OCR exposure.

Healthcare has recorded the highest average breach cost of any industry in every edition of IBM's Cost of a Data Breach report for over a decade — USD 6.64M in the 2026 edition. And the enforcement pattern has shifted from breach response to whether you did the risk analysis at all.

Your Regulatory Reality

Two sets of rules, one control set.

United States

  • HIPAA Security Rule

    Section 164.308(a)(4) information access management; Section 164.312(a)(1)/(d) access control and authentication. These are the standards in force today.

  • The proposed Security Rule update

    The NPRM published 6 January 2025 would make MFA and encryption mandatory rather than "addressable." It is still not finalized: comments closed 7 March 2025, OMB currently targets July 2027, and more than 100 hospital systems and provider associations have asked HHS to withdraw it. Plan for it; do not budget as though it were law.

  • OCR Risk Analysis Initiative

    Between January and August 2025 OCR announced 16 resolution agreements centred on failure to conduct an accurate and thorough risk analysis. This — not a headline breach — is the live enforcement pattern for the average covered entity and business associate.

  • HITRUST CSF

    Certification your enterprise and payer customers increasingly demand — identity controls form its largest domain.

  • OCR audit protocol

    Access reviews, termination evidence, emergency-access testing, and audit controls under Section 164.312(b).

Canada

  • PHIPA (Ontario)

    Health-sector equivalents of HIPAA access controls. A US vendor is usually an agent of a health information custodian rather than a business associate, and lockbox and consent-directive handling is an authorization problem, not a policy one.

  • PIPEDA / Law 25

    Consent and safeguard expectations for commercially handled health data, shaping consent architecture and data-subject request design directly.

  • Provincial EHR agreements

    Identity obligations flow down contractually to every vendor touching provincial systems.

What one missing control cost: the Change Healthcare intrusion began at a remote-access portal that accepted a password alone. As of 31 July 2025, 192.7 million individuals had been notified to HHS OCR — the largest healthcare breach on record. We cite it as public industry context, never as our own client work.

Where It Breaks

Healthcare-specific failure modes

Clinical workflow vs least privilege

Shared logins at nursing stations "because care can't wait" break accountability chains — the exact pattern examiners probe.

Vendor/BAA sprawl

Dozens of third parties hold standing EHR integrations far beyond contract scope, with no expiry or re-attestation.

AI/research workloads touching PHI

LLM pipelines wired in via unowned service accounts — powerful models, real patient data, zero oversight.

Break-glass with no glass to break

Emergency clinical procedures untested since implementation: no alarms, no expiry, no logs.

How We Fix It

Deliverables built for audit day

Facing an OCR inquiry or HITRUST deadline?

An Identity Risk Review maps your current gaps against exactly what OCR examiners test for — with a prioritized fix list.

Book an Identity Risk Review