Segmentation is proposed to stop being optional. Most hospitals cannot prove theirs.
On 6 January 2025, HHS published a Notice of Proposed Rulemaking in the Federal Register that would substantially rewrite the HIPAA Security Rule. The headline changes are well covered: multi-factor authentication on all ePHI access, encryption at rest and in transit, and the removal of the addressable/required distinction that has let organisations document a reason for not doing something rather than doing it.
The change that matters most operationally has had less attention. The NPRM would introduce network segmentation as an explicit implementation specification. Worth being precise here, because it is widely misreported: segmentation is not currently an addressable specification being promoted to required. It is a new requirement. The NPRM also proposes a technology asset inventory and a network map.
Two caveats before anyone reorganises a budget around this. The comment period closed on 7 March 2025. As of September 2026 there is no final rule, no compliance deadline, and it may still change or be withdrawn. Anyone telling you segmentation is currently mandatory under HIPAA is wrong. Under the voluntary HPH Cybersecurity Performance Goals, both segmentation and asset inventory sit in the enhanced tier rather than the essential one.
But the direction is not ambiguous, and the practical problem it exposes exists today regardless of what the final rule says.
Here is the problem. Ask a hospital whether its clinical VLAN is isolated and the answer is usually yes. Ask how that is known and you get a diagram — often a good one, drawn by someone competent, describing an intended state. The diagram is a statement of intent. It is not evidence.
The gap between the two is where everything interesting lives. A rule added for a project that ended in 2023 and never removed. A management VLAN that reaches every segment because it has to. A modality workstation that a department installed with a vendor and mentioned to nobody. A route added during an incident at three in the morning and never reverted. None of these appear on the diagram, and all of them are visible in traffic records the organisation already keeps.
This is not a criticism of hospital network teams. It is a structural consequence of running a clinical estate: change windows are scarce, equipment cannot be taken down at will, software is frequently vendor-controlled, and the person who understood the 2019 decision has left. Patching is not unavailable — the FDA requires manufacturers of applicable cyber devices to support it — but it happens on the vendor's schedule rather than yours. Network position ends up carrying load that patching carries elsewhere, and it is the control verified least often.
What would evidence actually look like? Three artefacts: the firewall configuration, some period of traffic records, and a written statement of intended segmentation. The first two usually exist. The third often does not, and its absence is more informative than anything an assessment would produce — if nothing is written down, there is no intent to check observed traffic against.
There is an important limit here, and it is worth stating because the vendor pitch usually omits it. Observing traffic between two segments proves a path is open. Observing no traffic proves nothing at all; the path may exist and simply be unused, or your capture point may not sit where you think it does. Asymmetric routing, a missed trunk, or a mirror configured on the wrong side of a device will each produce a confident and wrong conclusion. Any honest assessment reports what it could not see alongside what it did.
That asymmetry is why the useful finding is always the positive one. 'Your matrix says these segments do not communicate, and here are 4,812 flows between them over seven days' is actionable and hard to argue with. 'We saw nothing, so you are fine' is not a finding, and should never be presented as one.
If the rule is finalised as proposed, the organisations that will struggle are not the ones with poor segmentation. They are the ones with reasonable segmentation and no way to demonstrate it. I do not have data on how common that is, and I am wary of the numbers circulating — most trace back to vendor surveys with undisclosed denominators. It is a hypothesis I am testing, not a statistic.