Healthcare combines the most sensitive category of personal data with an environment where downtime has clinical consequences. That combination makes it unlike other regulated sectors: you cannot simply take a system offline to remediate it, and the data you hold is both highly regulated and highly targeted.
The frameworks that apply
- HIPAA Security Rule - the baseline for organisations handling protected health information in the US, covering administrative, physical and technical safeguards.
- HITRUST CSF - a certifiable framework that harmonises HIPAA with other standards; widely requested by US health systems from their vendors.
- ISO 27001 - the international baseline, expected outside the US and by many suppliers.
- Privacy law - the GDPR, the Saudi PDPL and equivalents, all of which treat health data as a special or sensitive category with stricter conditions.
- Medical device standards - IEC 62304 for device software and FDA expectations where devices are in scope.
- National frameworks - in Saudi Arabia the NCA ECC applies to health entities within its scope, alongside sector requirements.
What makes healthcare different
Availability is a safety control
In most sectors an outage costs money. In clinical environments it can affect care. That inverts some standard security assumptions - aggressive patching windows, automatic lockouts and hard session timeouts all need clinical review rather than blanket application.
Access is broad by necessity
Clinical staff need rapid access to records, often across departments and in emergencies. Least privilege still applies, but it has to accommodate break-glass access - which then requires strong logging and after-the-fact review rather than prevention.
Legacy and medical devices
Imaging systems and connected devices frequently run unsupported operating systems that cannot be patched without vendor recertification. Compensating controls - segmentation, strict network policy, monitoring - carry the weight here, and must be documented as deliberate decisions rather than accepted silently.
Third parties everywhere
Billing, imaging, transcription, telehealth, cloud EHR - health data flows through many suppliers. Third-party risk is disproportionately important, and business associate style agreements are a formal requirement in several regimes.
Map healthcare frameworks once
GRC Copilot assesses you against HIPAA, HITRUST, ISO 27001 and applicable privacy law from a single control set - so overlapping health-sector obligations are evidenced once, not repeatedly.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Where healthcare programmes fail
- Access reviews that never happen across a large, high-turnover clinical workforce.
- Break-glass access unmonitored - the control exists, the review of its use does not.
- Unsegmented medical devices sitting on the same network as everything else.
- Untested recovery. Backups exist; nobody has restored the clinical system under time pressure.
- Incomplete data flow mapping - health data in transcription services, research datasets or analytics platforms nobody inventoried.
- Vendor agreements missing for suppliers that clearly process patient data.
A sensible priority order
- Map where patient data actually lives and flows, including third parties.
- Segment medical devices and legacy clinical systems.
- Fix identity - joiner-mover-leaver across clinical staff, plus break-glass logging and review.
- Test recovery of the systems that matter clinically, not just the ones that are easy to restore.
- Complete vendor agreements and due diligence for anyone touching health data.
- Build the evidence base so audits and customer reviews stop being projects.
Compensating controls are legitimate and often unavoidable in clinical environments - but only when documented as a decision with the risk accepted by someone with authority. Undocumented workarounds are what auditors find.
Frequently asked questions
Is HIPAA compliance certifiable?
No. HIPAA is a regulatory requirement with no official certification. HITRUST CSF is the certifiable framework most commonly used to demonstrate HIPAA alignment to partners.
Does ISO 27001 cover HIPAA?
It covers much of the underlying security substance, but HIPAA has specific requirements that must be addressed directly. Map both to one control set.
How should we handle unpatchable medical devices?
Segment them, restrict network access tightly, monitor closely, and document the compensating controls and accepted risk. Track vendor support timelines as a lifecycle risk.
Do research datasets fall in scope?
If they contain identifiable health data, generally yes - and they are frequently missed. De-identification standards vary by regime, so confirm the applicable one.
Key takeaways
- Availability is a safety control, not just an operational one.
- Break-glass access needs logging and review, not prevention.
- Segment unpatchable devices and document the compensating controls.
- Map health data across third parties - that is where scope is usually lost.