Healthcare Providers
HIPAA, HITECH, and patient data protection
Healthcare providers handle protected health information under HIPAA's privacy and security rules. Thalorin provides comprehensive HIPAA compliance infrastructure that addresses administrative, physical, and technical safeguards while supporting the operational demands of modern healthcare delivery.
Provider organisations carry HIPAA obligations, but what makes them hard is the estate rather than the rule. Office for Civil Rights actions turn repeatedly on one deficiency â a security risk analysis that was scoped to a single system, performed years earlier, or never performed at all â and a health system is precisely where that scoping fails. The electronic health record, the imaging archive, the laboratory and pharmacy systems, the biomedical device fleet, an affiliated practice network and a workforce of rotating residents, agency staff and students are one organisation to a regulator and rarely one inventory to anybody else.
Substance use disorder records are the obligation providers most often discover late. The 42 CFR Part 2 final rule published by OCR and SAMHSA on 16 February 2024 took effect on 16 April 2024 with a compliance date of 16 February 2026, implementing the CARES Act alignment with the HIPAA Privacy Rule. A patient may now give a single consent covering future uses and disclosures for treatment, payment and health care operations, and the enforcement structure moved onto HIPAA’s. The heightened protections did not go away, which is the part that bites: a record that entered the chart from a Part 2 programme keeps its status wherever it travels, so the requirement is segmentation inside the record, not a separate system beside it.
Providers also sit under obligations HIPAA does not cover. Information blocking rules under the Cures Act govern whether electronic health information is made available, with penalties distinct from HIPAA. Medical device security on the clinical network is a patient safety issue that HIPAA addresses only obliquely, and connected devices frequently cannot be patched on a normal cadence.
Thalorin maintains the risk analysis as a living record connected to the safeguards it justifies, which is the linkage an OCR investigation looks for and most organisations cannot produce. It also holds the evidence behind a recognised security practices claim: under Public Law 116-321 the Secretary must consider whether an entity had such practices in place for not less than the previous twelve months when setting a fine, the scope and duration of an audit, and the terms of a settlement — and twelve months of continuous evidence is not something that can be assembled after the breach.
Healthcare faces mounting cybersecurity challenges
Risk analysis is the finding that recurs
OCR enforcement repeatedly cites risk analyses that were too narrow, too old, or absent. It is the single most reliable predictor of an adverse outcome after a breach.
Clinical devices resist standard controls
Connected medical devices often run unsupported software, cannot be patched on a normal cycle, and cannot be taken offline for remediation. Compensating controls must be designed and evidenced rather than assumed.
Part 2 records travel inside the chart
A substance use disorder record from a Part 2 programme keeps its protections once it reaches the general medical record, so the control has to live at the level of the record rather than the system. Providers that treated the February 2026 compliance date as an access-control change to one application generally have not segmented anything.
Information blocking is a separate regime
The Cures Act rules govern making electronic health information available and carry their own penalties. A HIPAA-compliant refusal to share can still be an information blocking violation.
How Thalorin helps
Security risk analysis across the care estate
Hold the risk analysis across the whole estate at once — record, imaging, laboratory, pharmacy, device fleet and affiliated practices — so its scope is a stated boundary rather than whichever systems the last assessment happened to reach.
42 CFR Part 2 record segmentation
Mark records originating in a Part 2 programme at the record level and carry the consent that authorised each disclosure, so protection follows the data into the general chart instead of stopping at a system edge.
Clinical and connected device controls
Model clinical and connected device risk with the compensating controls that stand in for what cannot be patched, and evidence those controls rather than asserting them.
EHR and health IT access governance
Reconcile access against the roles people actually hold, including residents, locums, agency staff and students, so an account ends when the rotation does.
Information blocking compliance
Track information blocking exceptions against the requests they were applied to, since the defensible position is the recorded exception, not the refusal.
Breach notification workflow
Run breach risk assessments and their notification clocks as workflow from the moment an incident is opened, rather than reconstructing the timeline afterwards.
Healthcare Providers: common questions
What is the most common HIPAA enforcement finding?
An inadequate or missing security risk analysis. OCR settlements describe it repeatedly — analyses covering one application rather than the enterprise, performed years before the incident, or not performed at all. Because the Security Rule makes risk analysis foundational, a deficiency there tends to undermine every downstream safeguard decision.
What did the 42 CFR Part 2 changes actually require of us?
The final rule published 16 February 2024 carried a compliance date of 16 February 2026, so it binds now. A patient can give a single consent covering future uses and disclosures for treatment, payment and health care operations rather than consenting each time care is coordinated, and enforcement now runs on the HIPAA structure. What it did not do is lower the protection: a record that came from a Part 2 programme keeps its status inside the general medical record, so the practical requirement is segmentation and consent tracking at the level of the record.
How do we handle medical devices that cannot be patched?
Through documented compensating controls rather than exceptions. Network segmentation, restricted access, enhanced monitoring, and physical controls can reduce risk where patching is not possible, and the Security Rule's risk-based structure accommodates this — provided the analysis identifies the risk, the compensating control is chosen deliberately, and both are documented. An undocumented unpatched device is simply an unaddressed risk.
Can we be HIPAA compliant and still violate information blocking rules?
Yes. HIPAA governs permitted uses and disclosures; the Cures Act information blocking rules govern whether you make electronic health information available when it should be. Declining to share information that HIPAA would permit sharing, without an applicable exception, can be an information blocking violation even where no HIPAA rule is breached.
Does following a recognised framework reduce our exposure if we are investigated?
It can, and the mechanism is statutory rather than informal. Public Law 116-321 amended the HITECH Act to require the Secretary to consider whether a covered entity or business associate had recognised security practices in place for not less than the previous twelve months when determining a fine under section 1176 of the Social Security Act, the scope and duration of an audit, and the terms of a settlement. Recognised security practices means the practices developed under section 2(c)(15) of the NIST Act or the approaches promulgated under section 405(d) of the Cybersecurity Act of 2015, which is the HICP material. It is not a safe harbour and it does not excuse a violation — and because the test is twelve months of demonstrated practice, it is decided by evidence you either already have or do not.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Healthcare Providers.
See how one evidence artifact satisfies Healthcare Providers requirements alongside every other framework you carry.