Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Zero Trust Architecture

Remember when your mom said “don’t talk to strangers”? This goes way beyond that.

Zero Trust Architecture is a security framework based on “never trust, always verify.” Not like the old days when users and devices inside the network were considered safe. Zero Trust assumes no implicit trust based on network location, focusing on protecting individual resources rather than network segments.

Some of the best practices for Zero Trust implementation include:

  • Identifying critical assets: systems and applications containing ePHI and sensitive data.
  • Map data flows: understand how patient data moves through the network in your organization (between EMRs, billing and third-party systems).
  • Micro-segmentation: divide networks into small zones to maintain separate access for separate parts of the network.

Examples of Zero Trust Solutions:

  • Multi-Factor Authentication (MFA): utilizing multiple layers of authentication for users adds more layers of security.
  • Endpoint Detection and Response (EDR): a cybersecurity solution that continuously monitors end-user devices in real-time to detect, investigate and mitigate advanced threats.
  • Identity and Access Management (IAM): technology tools for verifying user identity (either human or machine) and allowing only the appropriate access to resources at the right time.

NIST Special Publication 800-207 explains the components of a Zero Trust Architecture (ZTA), threats associated with the ZTA and steps that can be taken to further secure an organization’s environment.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.