HIPAA: Securing Healthcare Organizations with Zero Trust
How healthcare organizations can secure access to sensitive data in the era of hybrid work.

HIPA A CHECKLIST: SECURING HEALTHCARE ORGANIZATIONS
WITH ZERO TRUST NETWORK ACCESS
2HIPA A CHECKL IST
Embracing Zero Trust Network Access (ZTNA) is one of the most effective ways for healthcare organizations to protect sensitive electronic personal health information (ePHI). ZTNA is an approach to network security that approves access on an application-by-application basis instead of permitting broad access to the entire network.
Restricting access to ePHI with granular permissions is critical given the potential threats that organizations in the health sector face.
According to the 2023 Verizon Data Breach Investigations Report, 35% of healthcare data breaches can be attributed to internal threat actors leaking data. Add to that threats like ransomware that could destroy ePHI, or potential hacks that could leak ePHI into the darker corners of the web, and it’s clear healthcare organizations need advanced security solutions.
For healthcare organizations in the United States, the federal government removes a lot of the guesswork about what those advanced solutions need to do: The Security Rule of the Health Insurance Portability and Accountability Act (HIPAA) sets the standards for handling and protecting ePHI.
The Four Pillars of the Security Rule The HIPAA security rule includes four essential concepts that healthcare organizations must adhere to1.
1 U.S. Department of Health & Human Services. (2022, October 19). Summary of the HIPAA Security Rule. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
ENSURE Ensure the confidentiality, integrity, and availability of all ePHI that organizations create, receive, maintain, or transmit
IDENTIFY AND PROTECT Identify and protect against reasonably anticipated threats to the security or integrity of the information
STOP IMPERMISSIBLE USES Protect against reasonably anticipated, impermissible uses or disclosures
WORKFORCE COMPLIANCE Ensure compliance by your workforce
.01
.03
.02
.04
3HIPA A CHECKL IST
The HIPAA Checklist High-Level Measures
Designate a security official responsible for developing and implementing security policies and procedures
Perform a risk analysis evaluating the likelihood and impact of potential risks to ePHI
Implement security measures to address identified risks
Day-to-day Measures
Deploy access control measures for the “minimum necessary” workforce members who can access ePHI
Implement mechanisms to record and examine access to ePHI
Guard against unauthorized access to ePHI while in transit over the network
Ensure that ePHI is not improperly altered or destroyed
Train and manage workforce members handling ePHI
Document the rationale for adopting your security measures
Maintain continuous, reasonable, and appropriate security protections
4HIPA A CHECKL IST
The Checklist Explained High-Level Measures First and foremost, healthcare organizations that fall under HIPAA regulations must designate someone to oversee ePHI security policies, often called the HIPAA Security Officer. It makes sense for this to be someone within the organization that already understands the day-to-day procedures of how ePHI is handled. This doesn’t have to be someone from the IT team, but the HIPAA Security Officer will need guidance from an IT Manager to help carry out their duties.
Once a HIPAA Security Officer is in place, the next step is to perform a risk analysis. The analysis should evaluate the likelihood of your organization exposing ePHI to risks and what the impact could be. Risks to consider could include ransomware attacks, data exfiltration during a hack, leaks from an internal source, and improper data destruction.
After the risk analysis, it’s time to implement security measures that address the identified risks, and that’s where ZTNA comes in.
Day-to-Day Measures There are three actions on the HIPAA checklist that are covered by taking a Zero Trust approach. They include:
• Deploy ePHI access control measures for the minimum necessary workforce members your organization requires to carry out daily tasks
• Implement mechanisms to record and examine access to ePHI
• Guard against unauthorized access to ePHI while it’s in transit over the network
The very foundation of ZTNA is to only provide resource access to those who need it, which complies with HIPAA’s minimum necessary requirement.
Modern ZTNA solutions also come with robust logging, which allows administrators to see exactly who has been accessing ePHI databases, and when. Logs can also be processed by tools such as a SIEM that may further enhance network visibility, detect unknown threats, or support compliance reporting.
Finally, the Cloud VPN component of ZTNA ensures that any ePHI is encrypted in transit preventing unauthorized access.
In addition to these three points, a ZTNA can also help protect against improper destruction or alteration of ePHI through its restrictive access permissions and logging capabilities.
5HIPA A CHECKL IST
HIPAA Technical Safeguards ACCESS CONTROL Organizations must implement centrally-controlled unique credentials for each user and establish procedures to govern the release or disclosure of ePHI during an emergency, automatic log off and encryption.
INTEGRITY CONTROLS Organizations must implement policies and procedures to ensure that ePHI is not improperly altered or destroyed.
AUDIT CONTROLS Organizations must register attempted access to ePHI and record what is done with that data once it has been accessed.
TRANSMISSION SECURITY Organizations must guard against unauthorized access to ePHI that is being transmitted over an electronic network.
Harmony SASE Private Access for Healthcare Security Harmony SASE’s Private Access solution provides the enforcement and protection healthcare organizations need using the ZTNA approach. Our platform offers seamless and secure least privilege access to resources.
In addition, our Internet Access offering protects against malicious software entering the organization’s network by scanning for threats such as viruses and ransomware.
We also help maintain your organization’s productivity with a global backbone ensuring high- performance connectivity for all your users, worldwide.
Book a demo with Check Point today to transform your network security.
6HIPA A CHECKL IST
Meet Harmony SASE 2x Faster Internet Access | Full Mesh Private Access | Secure SD-WAN Offering a game-changing alternative, Harmony SASE delivers 2x faster internet security combined with full mesh Zero Trust Access and optimized SD-WAN performance— all with an emphasis on ease- of-use and streamlined management.
Combining innovative on-device and cloud- delivered network protections, Harmony SASE offers a local browsing experience with tighter security and privacy, and an identity-centric zero trust access policy that accommodates everyone: employees, BYOD and third parties. Its SD-WAN solution unifies industry-leading threat prevention with optimized connectivity, automated steering for over 10,000 applications and seamless link failover for uninterrupted web conferencing.
Harmony SASE enables any business to build a secure corporate network over a private global backbone in less than an hour. The service is managed from a unified console and is backed by an award-winning global support team that has you covered 24/7. To learn more, visit checkpoint.com or sign up for a demo.
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 1-800-429-4391
www.checkpoint.com
© 2023 Check Point Software Technologies Ltd. All rights reserved.