Walk through a mid-sized clinic with a network scanner and the result surprises almost everyone who runs one: infusion pumps, patient monitors, imaging equipment, smart thermometers, badge readers, and a tablet cart, all holding IP addresses on the same network as the front-desk PCs. Nobody decided to build a connected-device fleet. It accumulated, one purchase at a time, and in most practices no single person can say today how many of these devices exist, what software they run, or when they were last patched. That gap used to be invisible. Two regulatory developments are making it expensive.
Why clinical devices break normal IT assumptions
The instinct is to manage these devices like laptops, and the instinct fails for three structural reasons. Clinical devices live far longer than office hardware; a monitor bought in 2018 may be in service well into the 2030s, long after its operating system stopped receiving mainstream support. Patching is usually vendor-controlled, because the software on a regulated device cannot be modified freely without affecting its certified state, so your team cannot simply push updates the way it does to workstations. And the devices handle electronic protected health information by design, which means every one of them sits inside your HIPAA scope whether or not anyone wrote that down.
The practical consequence: a clinic’s riskiest endpoints are often the ones its IT provider has the least authority over. That is not a reason to panic. It is a reason to inventory.
What HIPAA requires today, and what the proposed update would change
Start with the current rule, because it is enforced right now. The HIPAA Security Rule already requires a documented risk analysis covering every system that touches patient data, connected clinical devices included, and incomplete risk analysis remains the deficiency regulators cite most often in investigations. The financial stakes moved this year: civil penalty amounts were inflation-adjusted effective January 2026, with the annual cap for the most serious tier of violation now above $2.1 million.
Then there is the proposed overhaul. In January 2025, the Department of Health and Human Services published a proposed update to the Security Rule, the largest since the rule was written. As drafted, it would make encryption of patient data mandatory at rest and in transit, require multi-factor authentication, and oblige practices to maintain a technology asset inventory and network map, with network segmentation among the expected safeguards. The long-standing flexibility that let organizations treat some measures as “addressable” would largely disappear.
The honest status report: the update is still a proposal, not law. The comment period closed in March 2025, more than a hundred hospital systems and provider associations have asked HHS to withdraw it, and the federal regulatory agenda has pushed the target for final action out to mid-2027. It may be finalized as written, narrowed, delayed again, or dropped. Planning for a clinic should not bet on any single outcome, and it does not need to, because the measures in the proposal are the same ones auditors and cyber insurers already ask about under the current rule.
When a device fleet outgrows managed IT
Somewhere in this work, every practice hits a scale question. For most independent clinics, the honest answer is that a competent managed IT provider plus disciplined inventory and segmentation covers the requirement; a dedicated platform for a dozen off-the-shelf devices is money spent on a problem you do not have. The calculation changes at a specific threshold: when the organization runs remote patient monitoring programs, operates custom or semi-custom devices, or manages device counts in the hundreds across sites, ad hoc oversight stops scaling. That is the point where purpose-built healthcare IoT solutions earn their cost, and it says something that engineering firms in this space tend to open by examining whether an organization’s existing stack already covers the requirement before proposing anything new. A vendor who starts by trying to disqualify you is usually the vendor worth a second call.
If you are under that threshold, write the threshold down anyway. Knowing in advance what growth event triggers the next tier of tooling turns a future emergency purchase into a planned one.
The 90-day fix list
Whatever happens with the rulemaking, four actions cover most of the exposure, and none of them waits on Washington:
- Run device discovery and build the inventory. Every connected device, with model, software version, data it touches, and the person responsible. The proposed rule would make this mandatory; the current rule already assumes you have it.
- Segment the network. Clinical devices do not belong on the same flat network as email and browsing. Segmentation is the single control that most limits damage when, not if, one device is compromised.
- Put patch terms in writing with device vendors. If the vendor controls updates, your contract should state how fast they ship fixes for known vulnerabilities and who is notified. Silence in the contract becomes your liability in the incident report.
- Define offboarding. A device leaving service must leave the network and the inventory the same week, with stored patient data handled per your retention policy.
A clinic that completes these four items is in a defensible position under the current rule and substantially prepared for the proposed one, whichever version of it arrives.
Device lifecycles outlast everything else in your stack
The uncomfortable long-term truth is that connected clinical equipment operates on decade-plus lifecycles while security expectations now move on annual ones, and that mismatch is permanent. It helps to understand how the engineering side is responding: manufacturers are being pushed toward devices with signed update mechanisms, component-level software inventories, and security designed in before certification rather than patched in after. Reading an engineering-side overview of IoMT security is a useful exercise for a clinic for one specific reason: it tells you what to demand in your next procurement, not just your next audit.
Three questions to put to your IT provider this week: how many connected clinical devices are on our network right now, which of them can you not patch, and what happens on the network if one of them is compromised on a Tuesday afternoon? If all three come back with specific answers, you are ahead of most of the industry. Any blank stare is your starting point.
