Skip to Main Content

Security Is a Process, Not a Project: A Deep Dive into Why Continuous Compliance Is the Only Compliance That Works

06/26/2026 | 6 minute read

Posted in Data Security Incident Response

Healthcare entities and their business associates (healthcare companies) have spent the better part of two decades navigating the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, and many still treat compliance as a one-time project that can be completed. These companies often start strong by conducting an initial security risk analysis, implementing policies and procedures, and training staff on HIPAA security. Then they file away the documentation, check the boxes and move on.

That approach comes at a cost – one that is too often realized only when a regulator or a plaintiffs’ attorney comes calling.

The HIPAA Security Rule was not designed with a finish line in mind but rather was meant to be an ongoing security program designed to address ever-increasing cybersecurity threats. The drafters envisioned a framework that grows and evolves in parallel with the healthcare company’s systems, vendors, workforce and threat landscape. Healthcare companies that understand their cybersecurity programs as a process consistently find themselves in the best position to defend against the ever-increasing number of cybersecurity threats and, when necessary, to respond to regulators and plaintiffs’ attorneys who seek to highlight inadequacies in their security. 

The Project Trap

Projects are given budgets, timelines and deliverables. In the context of HIPAA compliance, healthcare companies conduct a security risk analysis, draft policies and train employees all before the end of a fiscal year. They complete the process and move on to the next project.

Herein lies the problem. While these activities are a great first step, they are not sufficient to maintain compliance with the HIPAA Security Rule. There is an assumption on the part of companies that once the project is completed, security is achieved and can then be maintained simply by doing nothing. It cannot.

Healthcare IT environments are not static. Threat actor tactics are not static. Best cybersecurity practices are not static. The environment is constantly evolving, and so must healthcare companies. Upgrades to electronic health records platforms, the introduction of new vendors and the acquisition of new clinical practices using legacy systems are just some of the common changes to a company’s environment that can impact the threat landscape. Changes to the company’s environment are on top of external factors that may change the threat landscape, such as ransomware groups pivoting to new attack techniques, new vulnerabilities or new methods to circumvent existing protections, such as multifactor authentication.

These developments render stale the security risk analysis that was “completed” 12 months ago. Healthcare companies that treat HIPAA security as a one-time project incur increasing risk as more time passes. As these risks accumulate over time, they will provide more opportunities for threat actors to exploit the systems and make it increasingly difficult to defend the sufficiency of the security program in response to inquiries by regulators and plaintiffs’ attorneys.

There is also a speed problem. The 2026 BakerHostetler Data Security Incident Response Report (2026 DSIR) shows that threat actors are moving faster than in prior years from the initial compromise to the data theft and/or encryption of the systems. This information emphasizes the need to ensure there are processes and tools in place to quickly identify any unauthorized access. The increasing speed of threat actors is just one example of how an organization’s analysis of the security risk level can change as threat actors change and improve their techniques.

What the Security Rule Actually Requires

The HIPAA Security Rule binds healthcare companies to ongoing initiatives.

HIPAA requires accurate and thorough analysis of the potential risks and vulnerabilities of the confidentiality, integrity and availability of electronic protected health information (ePHI). It is not a one-and-done activity. The expectation is that a company implements and maintains appropriate security measures. This means periodic evaluations. If a healthcare company ever faces an investigation, the Office for Civil Rights (OCR) will typically ask about the organization’s HIPAA security risk analyses and risk management plans; HIPAA policies and procedures, including effective and revision dates of these policies; and the records and copies of HIPAA security trainings. These investigations often happen following a data breach or a patient complaint to OCR. Organizations that ensure compliance before such investigations are in the best position to quickly and effectively respond to OCR, usually with no penalty.

Security Risk Analyses Are Effective Only When There Is Continuous Compliance

OCR has provided general guidance on what is required for a HIPAA security risk analysis but, despite the routine focus on these analyses, has not provided specific instruction on how they should be performed. OCR did, however, point to National Institute of Standards and Technology guidance focused on risk management as a base to use when performing a HIPAA security risk analysis.

The general steps when performing this type of risk analysis are:

  • Step 1 – System Characterization
  • Step 2 – Threat Identification
  • Step 3 – Vulnerability Identification
  • Step 4 – Risk Analysis
  • Step 5 – Control Recommendations
  • Step 6 – Results Documentation

Due to the fluid nature of companies, an accurate analysis of the threats and vulnerabilities faced by healthcare companies will require periodic analysis. Therefore, the first step is for healthcare companies to set up a regular cadence for their HIPAA security risk analysis. For many healthcare entities, the analysis is performed annually. However, in addition to this regular analysis, companies should perform a new, perhaps focused, analysis whenever a material change occurs in the IT environment. Material changes are those that may impact the types or level of risk to the organization. Examples of material changes are the introduction of new technology in the IT environment, hiring new vendors that handle ePHI, restructuring the workforce or the occurrence of a security incident. Depending on whether a change is material, the healthcare company may need to reassess only a portion of the environment, but this decision should be based on the specific change to the environment. Healthcare companies should maintain policies that define a material change and assign ownership to the personnel responsible for monitoring, recording and enacting a new security analysis based on the material change.

Following the security risk analysis, healthcare entities then use the identified threats and vulnerabilities as well as the controls in place to address and mitigate the risks in the form of a risk management plan. Each identified threat or vulnerability risk may be assigned a risk rating. Some risks will likely need to be addressed quickly, whereas other risks may require additional time and/or funding to address. Additionally, an organization may decide to accept a risk.

Under the HIPAA Security Rule, the set of controls that the healthcare entities plan to implement to reduce the identified risks is referred to as a risk management plan. Risk management plans should prioritize remediation steps, assign ownership of the actions and include timelines to complete the actions. Due to the nature of creating short-, intermediate- and long-term goals, this plan is an ongoing process. In addition, areas that are considered low risk at one time may be considered higher risk at another time due to changes internally in the environment or externally such as new technology or threat actor tactics.

Continuous monitoring is essential for ongoing compliance. Effective monitoring includes log reviews, vulnerability scanning, access control auditing, vendor security monitoring and tracking of workforce compliance with security policies. For example, without continuous monitoring of the threat landscape, it is easy to miss new tactics used by threat actors. According to the 2026 DSIR, threat actors are frequently moving from initial access to exfiltration without deploying encryption. As a result, relying on ransomware-style detection is not sufficient. Healthcare companies that have performed a more recent analysis have had the opportunity to review and assess this risk and create a risk mitigation plan to address it by, for example, tuning their threat detection tools for credential-based intrusion, lateral movement and unusual data transfer rather than the presence of ransomware.

Enforcement Risk

In addition to the security benefits of ongoing security monitoring, there is an increasing amount of enforcement risk for healthcare entities that do not implement such measures. OCR’s Risk Analysis Initiative penalizes healthcare companies that have not performed HIPAA risk analyses or have not adequately managed risk. OCR’s programmatic focus on the performance of these risk analyses and implementation of risk management plans emphasizes the need for healthcare entities and business associates to ensure they are regularly assessing and responding to the cybersecurity landscape.

State attorneys general are also filling enforcement gaps left by smaller federal agencies. Multiple attorneys general launched investigations into healthcare companies in 2025, often concurrent with or even following investigations closed by OCR. These investigations often resulted in multiple regulators asking for evidence that the legally required security controls were in place at the time of an incident.

Treating HIPAA security as an ongoing and active program rather than a completed project is the foundation of a defensible compliance posture. Healthcare companies and their vendors that commit to continuous risk analysis, monitoring and remediation are far better positioned to withstand scrutiny from regulators and plaintiffs’ attorneys alike. In our next article, we tackle another complex area of the HIPAA Security Rule – what “addressable” safeguards are and why addressable does not mean optional.

This post is part of a series on practical HIPAA Security Rule compliance. It draws on themes explored in “HIPAA at 21 Years of Compliance: Why the Security Rule May Be Entering a More Prescriptive Era,” published by BakerHostetler, and data from the 2026 DSIR.