The first major update to the HIPAA Security Rule in more than a decade is expected to finalize this May, and it changes something fundamental about how healthcare facilities think about security. For the first time, physical safeguards that were previously “addressable,” meaning organizations could weigh cost and risk before deciding whether to implement them, will become mandatory. No exceptions, no alternative measures, no documented justifications for skipping them.
The Department of Health and Human Services estimates the first-year compliance cost at around $9 billion across the healthcare sector. That number alone tells you the scale of the gap between where most facilities are today and where they need to be.
Having spent nearly three decades working in physical security, I have seen this pattern before. A major regulatory shift arrives, and organizations scramble to address the technical requirements, encryption, multifactor authentication, network segmentation, while the physical layer gets treated as an afterthought. In healthcare, that blind spot is not just a compliance risk. It is a patient safety risk.
The Physical Security Gap Nobody is Talking About
Most of the conversation around the updated rule has focused on cybersecurity: mandatory encryption of electronic protected health information, annual penetration testing, vulnerability scans every six months, and incident response plans that require data restoration within 72 hours. These are significant and necessary changes.
But here is the part that is not getting enough attention. The rule also requires organizations to formally test and verify their physical safeguards every 12 months. That means access controls on server rooms, medication storage areas, medical device bays, and anywhere electronic health data is created, stored, or transmitted. It means proving that only authorized personnel can physically reach the systems that hold patient information.
In many hospitals today, physical and cyber security operate as entirely separate functions with separate budgets, separate teams, and separate reporting lines. The IT department handles firewalls and endpoint protection. The facilities team handles door locks and cameras. And very rarely do these two groups sit in the same room to map out where the vulnerabilities actually overlap.
That disconnect is where the real risk lives.
Where Compliance Meets Patient Safety
Think about it this way. An unsecured medication room is a compliance issue. But it is also a direct threat to patient welfare. An unmonitored access point to a server closet is a HIPAA violation waiting to happen. But it is also a potential entry point for someone who wants to tamper with critical infrastructure.
When we talk to healthcare organizations, the question I hear most often is “where do we even start?” And the answer is deceptively simple: start by mapping the physical environment against the digital one. Where does ePHI live? Who can physically walk up to those systems? What controls are in place to prevent unauthorized access, not just through a login screen, but through a door?
The updated rule makes this kind of integrated thinking non-negotiable. Organizations will need to demonstrate that their physical access controls, their visitor management processes, and their intrusion detection capabilities work alongside their digital protections as a single, testable system.
Bridging the Gap Before May
The good news is that closing this gap does not require ripping out existing infrastructure. What it requires is connecting what is already there. Most healthcare facilities already have access to control systems, camera networks, and alarm platforms. The problem is that these systems were installed in isolation and rarely communicate with one another, let alone with the IT security stack.
The organizations that will be best positioned for the new rule are the ones that take a unified approach now: conducting a joint physical-cyber gap assessment, ensuring that access events generate auditable logs, and building response protocols that treat a propped-open door to a data center with the same urgency as a suspicious login attempt.
We are driving organizations forward, helping them bridge the gap between where they are today and where the regulation is taking them. Because the reality is that the May deadline is not just a compliance exercise. It is an opportunity to finally treat physical security as what it has always been in healthcare: a patient safety function, not just a facilities line item.
The hospitals that get this right will not just be compliant. They will be safer.
The author, Kumar Sokka, is CEO of Acre Security, a global provider of access control, visitor management, intrusion detection, and secure communications solutions for healthcare, enterprise, and critical infrastructure.