• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

Simplifying HIPAA Compliance: How Microsegmentation Can Help

by Garrett Weber, Field CTO – Enterprise Security at Akamai Technologies 04/28/2025 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
Simplifying HIPAA Compliance: How Microsegmentation Can Help
Garrett Weber, Field CTO – Enterprise Security at Akamai Technologies

In today’s cybersecurity landscape, the stakes have never been higher especially for organizations in the healthcare industry. Data breaches and ransomware attacks are not just increasing in frequency—they’re becoming more sophisticated, leaving even the most prepared organizations vulnerable. The reality is clear: protecting electronic protected health information (ePHI) demands comprehensive, granular control.

This urgency has been underscored by the Department of Health and Human Services’ (HHS) proposed updates to the HIPAA Security Rule, which emphasize the necessity of network segmentation to help prevent lateral movement and safeguard sensitive data. However, it’s not just about compliance; it’s about survival in a world where threats evolve daily. When it comes to segmentation, not all solutions are created equal.

While traditional segmentation approaches, such as VLANs or static firewall rules, provide some level of protection, they fall short in the face of modern threats. These methods are often rigid, complex to manage, and lack the real-time adaptability needed to address today’s dynamic risk landscape. That’s where microsegmentation steps in, offering a superior alternative. Let’s first understand the new guidance and why it matters.

Why the New HIPAA Guidance Demands More

The proposed modifications to the HIPAA Security Rule, specifically 45 CFR 164.312(a)(2)(vi), call for “reasonable and appropriate” technical controls to segment networks and electronic information systems. This represents a critical step forward in addressing the lack of barriers to lateral movement within a network.

Consider the following scenario:

  • A point-of-sale (POS) system, connected to a flat network of assets, is hit by a targeted malware attack designed to exploit vulnerabilities in the system.
  • Without network segmentation, the attacker can then move laterally and gain access to an electronic health record (EHR) system.
  • The result? A catastrophic breach of sensitive ePHI, leading to financial, reputational, and regulatory fallout.

This example underscores why microsegmentation is crucial in today’s world of cybersecurity. The goal is clear: impede intruders at every turn, isolate systems to prevent widespread damage, and ensure sensitive data remains secure.

The upcoming changes to HIPAA Security Rules are set to create significant challenges for healthcare organizations, but the biggest hurdle may not be compliance itself–it’s the underlying network infrastructure. Many healthcare providers operate electronic health records (EHR) systems on flat networks where data moves freely between devices, applications, and users without strict microsegmentation. While this design is efficient it also presents major security risks in a world where data protection requirements demand a stronger approach.

The Cost of Rearchitecting vs. Microsegmentation

Traditionally, network security operations relied on next-generation firewalls (NGFWs) and VLAN segmentation, but for most organizations, rearchitecting an existing flat network using these legacy tools would be complex and expensive. Making these changes to comply with new guidelines and better protect EHRs could require a massive investment in infrastructure and result in downtime. 

This is where a microsegmentation strategy starts to make more sense as a practical and cost-effective solution. Unlike traditional network segmentation, microsegmentation applies security policies at the workload level, enabling granular control over data flows without the need for costly hardware overhauls. With microsegmentation, organizations can enforce HIPAA-mandated protections without disruption and lower costs. 

Take Action

The risks are clear, the guidance is explicit, and the solutions are available to help organizations secure their ePHI, comply with evolving regulatory standards, and protect organizations from disaster.

In today’s evolving cybersecurity landscape, staying proactive is essential. Microsegmentation provides a powerful way to enhance your organization’s security and resilience against modern threats. Taking action now can help safeguard your systems for the future.


About Garrett Weber

Garrett Weber is the Field CTO for Akamai’s Enterprise Security Group, where he works with organizations to guide them through their Zero Trust journey. In his role as Field CTO, Garrett worked very closely with organizations of all sizes to adopt and successfully implement Zero Trust solutions into their environment. Garrett brings practical, real-world experience from years working in various security roles, in the Insurance, Healthcare and Consulting industries. He also spent 12 years in the Air National Guard as part of a Cyber Warfare Squadron that worked alongside both the Air Force Computer Emergency Response Team (AFCERT) and the Defense Information Systems Agency (DISA).

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

2025 EMR Software Pricing Guide

2025 EMR Software Pricing Guide

Featured Interview

Kinetik CEO Sufian Chowdhury on Fighting NEMT Fraud & Waste

Most-Read

CureIS Healthcare Sues Epic: Alleges Anti-Competitive Practices & Trade Secret Theft

The Evolving Role of Physician Advisors: Bridging the Gap Between Clinicians and Administrators

The Evolving Physician Advisor: From UM to Value-Based Care & AI

UnitedHealth Group Names Stephen Hemsley CEO as Andrew Witty Steps Down

UnitedHealth CEO Andrew Witty Steps Down, Stephen Hemsley Returns as CEO

Omada Health Files for IPO

Omada Health Files for IPO

Blue Cross Blue Shield of Massachusetts Launches "CloseKnit" Virtual-First Primary Care Option

Blue Cross Blue Shield of Massachusetts Launches “CloseKnit” Virtual-First Primary Care Option

Osteoboost Launches First FDA-Cleared Prescription Wearable Nationwide to Combat Low Bone Density

Osteoboost Launches First FDA-Cleared Prescription Wearable Nationwide to Combat Low Bone Density

2019 MedTech Breakthrough Award Category Winners Announced

MedTech Breakthrough Announces 2025 MedTech Breakthrough Award Winners

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

'Cranky Index' Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

‘Cranky Index’ Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |