Healthcare regulationUnited States

HIPAA / HITECH Security and Breach Readiness

Bring current HIPAA Security Rule safeguards into continuous managed operation while preparing for incidents and breaches involving ePHI.

View the control mapping

Where we contribute

A managed security layer within a broader compliance program.

The HIPAA Security Rule applies to the complete environment in which a covered entity or business associate creates, receives, maintains, or transmits electronic protected health information. Network Box can operate and document substantial technical and operational safeguards, but no product, BAA, or managed service makes an organization automatically HIPAA compliant or certified.

Current rule status

Reviewed September 2, 2026

The current HIPAA Security Rule remains in effect.

HHS proposed a substantial Security Rule modernization in December 2024, but it remains a Notice of Proposed Rulemaking. The proposal is useful for readiness planning; it is not the present enforceable compliance standard.

Read the HHS Security Rule proposal status ↗
  • This page maps Network Box services to the Security Rule currently in effect, not to proposed requirements.
  • The current rule requires reasonable and appropriate administrative, physical, and technical safeguards for ePHI.
  • Covered entities and business associates must protect the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit.
  • The rule remains scalable and technology neutral, with safeguards selected from the regulated entity's documented risks and circumstances.
  • Proposed priorities such as broader MFA, encryption, inventories, segmentation, scanning, and testing are identified only as readiness considerations.

Regulatory foundation

Understand what HIPAA protects and who remains accountable.

The current Security Rule, HITECH amendments, Breach Notification Rule, and actual service data flows determine the responsibilities of covered entities, business associates, MSPs, and other providers.

Current Security Rule

Protect electronic PHI

Regulated entities must apply reasonable and appropriate safeguards to the confidentiality, integrity, and availability of ePHI throughout their environment.

HITECH

Business associates are directly accountable

HITECH extended significant Security Rule duties and breach-notification obligations to business associates and certain downstream subcontractors.

Implementation

Addressable does not mean optional

An addressable specification requires a documented reasonableness analysis, implementation when reasonable and appropriate, or a documented equivalent alternative when appropriate.

Positioning

There is no product certification

HHS does not certify products as HIPAA compliant. Compliance depends on the regulated entity's complete program, environment, people, contracts, and operation of safeguards.

Control mapping

Current HIPAA Security Rule safeguards and Network Box support.

The matrix follows the current administrative, physical, technical, organizational, policy, and documentation requirements. Each row separates managed-security contributions from the duties retained by the covered entity or business associate.

Authoritative sourceHHS summary of the current HIPAA Security Rule ↗
Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Technical risk inputs and continuously operated controls support an organization-wide security management process.
Vulnerability ManagementThreat intelligenceSIEMNBX: MDR, EDR, XDR24/7 SOCSecurity reporting
Partial
Recurring technical assessment identifies threats and weaknesses but is not, by itself, a HIPAA risk analysis.
Vulnerability ManagementSIEMNBX: MDR, EDR, XDRThreat intelligenceSecurity reviews
Supporting
Managed safeguards and remediation guidance help reduce identified technical risks within scope.
UTM+Secure SD-WANSecure Web GatewayWAFManaged Cloud Email SecuritySIEMNBX: MDR, EDR, XDR
Partial
Centralized logging and SOC analysis support regular review of information-system activity.
SIEMNBX: MDR, EDR, XDRManaged-device logging24/7 SOCDashboardsSecurity reporting
Strong
Defined contacts, escalation paths, and operating reports support the designated security official.
Service contactsEscalation proceduresSecurity reportingService reviews
Supporting
Access restrictions, logging, and alerts can help prevent or detect inappropriate access within the managed scope.
Access controlsManaged administrative accessSIEMNBX: MDR, EDR, XDR
Supporting
Network policy, segmentation, secure connectivity, and telemetry help enforce approved access paths.
UTM+Network segmentationVPNSecure SD-WANDirectory integrationSIEM
Partial
Education, phishing simulations, and metrics build safer workforce behavior when subscribed.
Security Awareness TrainingPhishing simulationsCampaign reportsUser metrics
Strong
Continuous detection, investigation, escalation, and containment support the regulated entity's response procedures.
24/7 SOCSIEMNBX: MDR, EDR, XDRIncident investigationContainment assistanceIncident reporting
Strong
Monitoring, protected configurations, recovery procedures, and resilient options support continuity of managed security functions.
Managed-service monitoringConfiguration protectionIncident responseService restoration supportResilient service options
Supporting
Operational records and reviews help evaluate whether managed safeguards are functioning and where improvement is needed.
Service reviewsConfiguration recordsSIEM reportsVulnerability findingsIncident history
Partial
Service, data-handling, security, incident, subcontractor, and assurance information can support accurate arrangements.
Service documentationResponsibility assignmentsIncident proceduresContractual commitmentsAssurance documentation
Partial
Service and assurance information may support evaluation of facilities used to deliver managed services.
Service documentationAssurance documentationRemote monitoringNetwork segmentation
Supporting
Web, endpoint, and network controls can enforce or observe selected technical aspects of acceptable use.
Secure Web GatewayNBX: MDR, EDR, XDRNetwork controlsSecurity monitoring
Supporting
Endpoint detection and network enforcement help protect and isolate subscribed workstations.
NBX: MDR, EDR, XDRNetwork access controlsSIEMContainment assistance
Partial
Managed-service data-handling information supports oversight of security records inside the contracted scope.
Managed security-data handlingAccess controlsService documentation
Supporting
Managed enforcement, segmentation, VPN, gateway policy, and supported authentication restrict access paths.
UTM+Network segmentationVPNSecure SD-WANSecure Web GatewayWAFDirectory integration
Partial
Centralized records, correlation, searches, analyst review, and reporting support examination of ePHI-system activity.
SIEMNBX: MDR, EDR, XDRManaged-device logging24/7 SOCDashboardsSecurity reporting
Strong
Layered prevention and monitoring detect malicious alteration, exploitation, or destruction affecting systems and communications.
IDS/IPSAnti-malwareWAFManaged Cloud Email SecuritySecure Web GatewaySIEMNBX: MDR, EDR, XDR
Partial
VPN authentication, supported MFA and directories, restricted administration, and telemetry protect managed access.
VPNMFA/TOTP supportDirectory integrationManaged administrative accessSIEM
Partial
Secure connectivity, traffic policy, segmentation, and monitoring protect ePHI moving through managed paths.
VPNUTM+Secure SD-WANNetwork segmentationSecure Web GatewayManaged Cloud Email SecuritySIEM
Strong
Accurate service and responsibility information supports BAAs and other required organizational arrangements.
Service descriptionsResponsibility assignmentsIncident termsSecurity documentationSubcontractor information
Partial
Managed-service procedures, configurations, escalation paths, and reports support technical portions of written policy.
Service proceduresManaged-control documentationConfigurationsEscalation proceduresSecurity reporting
Supporting
Configuration, investigation, vulnerability, incident, and service records evidence managed activities.
Configuration recordsChange recordsSIEM reportsIncident reportsVulnerability findingsService documentation
Partial

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Encryption and scope

A secure network path does not prove complete ePHI encryption.

Encryption is addressable under the current Security Rule, which still requires a documented reasonableness-and-appropriateness decision. VPN and secure transport can protect managed paths, but the regulated entity must validate ePHI protection at rest and in every application, message, file transfer, API, device, backup, and third-party exchange. This includes the methods and key management needed for any breach safe harbor.

Incident and breach readiness

Separate detection from the legal breach determination.

Network Box can provide rapid technical facts and response support. The regulated entity must determine whether PHI was involved, apply the required breach analysis, and complete every applicable notification.

01

Security incident

Attempted or successful unauthorized access, use, disclosure, alteration, destruction, or interference must be identified, addressed, mitigated where practicable, and documented.

02

Ransomware

Ransomware affecting ePHI systems is a security incident and requires investigation of access, acquisition, modification, encryption, exfiltration, integrity, and availability.

03

Breach assessment

An impermissible use or disclosure is generally presumed to be a breach unless an exception applies or the required assessment supports a low probability of compromise.

04

Individual and HHS notice

For applicable breaches, the current rule uses outside notification limits of 60 calendar days; larger breaches have prompt HHS and potentially media-notice requirements.

05

Business-associate escalation

A business associate must notify the covered entity without unreasonable delay and within the regulatory outside limit, while a BAA may require much faster initial reporting.

06

Prepared evidence

Named contacts, event timelines, affected assets, PHI context, indicators, containment actions, preservation steps, and continuing updates should be planned before an incident.

Assessment evidence

Show that safeguards are operating.

Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.

  1. 01Service descriptions, scope documents, and responsibility assignments
  2. 02BAA-related service, subcontractor, and security information where applicable
  3. 03Managed security device, service, endpoint, and log-source inventories
  4. 04Network diagrams and descriptions of managed boundaries and segments
  5. 05Firewall, VPN, SD-WAN, segmentation, web, email, and WAF policies
  6. 06Administrative access and authentication records for managed services
  7. 07Security configurations, maintenance activity, and change records
  8. 08Centralized logs, log-source health, SIEM searches, dashboards, and reports
  9. 09Evidence of information-system activity review within the managed service
  10. 10SOC alerts, analyst investigations, escalations, and incident reports
  11. 11Incident timelines, indicators, affected-system details, and containment records
  12. 12Vulnerability findings, validation, priorities, trends, and remediation recommendations
  13. 13IDS/IPS, malware, phishing, email, web, and application-security events
  14. 14Security-awareness participation and phishing-simulation results
  15. 15Service availability, performance, continuity, and recovery information
  16. 16Available independent-assurance and managed-control documentation

Coverage key

What each label means.

Strong

Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.

Partial

Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.

Supporting

Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.

Client responsibility

This area primarily remains with the MSP and client, their assessors, or other qualified parties.

Shared responsibility

Network Box helps operate the controls. The organization owns the compliance program.

The covered entity or business associate owns applicability, its complete ePHI inventory and risk analysis, governance, workforce and physical safeguards, identity and data controls, contingency planning, documentation, business-associate oversight, breach determinations, notifications, and every system or process outside the managed-service scope.

HIPAA / HITECH FAQ

Questions about scope, evidence, and responsibility.

What is HIPAA / HITECH?

Bring current HIPAA Security Rule safeguards into continuous managed operation while preparing for incidents and breaches involving ePHI.

How can Network Box USA support HIPAA / HITECH?

Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable HIPAA / HITECH requirements.

Does using Network Box USA make an organization HIPAA / HITECH compliant?

No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.

How should the HIPAA / HITECH control mapping be used?

Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.

What evidence may be available for a HIPAA / HITECH assessment?

Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.

What remains the organization's responsibility under HIPAA / HITECH?

The covered entity or business associate owns applicability, its complete ePHI inventory and risk analysis, governance, workforce and physical safeguards, identity and data controls, contingency planning, documentation, business-associate oversight, breach determinations, notifications, and every system or process outside the managed-service scope.

Explore another frameworkReturn to the Compliance Center →

Security stack review

Map the technical foundation before the assessment starts.

Request a Security Stack Review