“Zero trust” gets thrown around a lot in cybersecurity marketing, usually without much explanation of what it actually requires you to do. That vagueness is a problem, because zero trust isn’t just a buzzword this year — it’s quietly becoming the backbone regulators and cyber-insurers expect to see, especially as HIPAA’s Security Rule shifts from “addressable” safeguards to mandatory ones.
Here’s what zero trust actually means, why it lines up so closely with HIPAA, and where to start without ripping out everything you already have.
What “zero trust” actually means
Strip away the marketing, and zero trust comes down to one idea from NIST’s official framework (SP 800-207): never trust, always verify. No user, device, or application gets automatic trust just because it’s already inside your network. Every request for access gets checked, every time, based on who’s asking, what device they’re on, and whether that request looks normal.That’s a real shift from the old model, where anyone who made it past the office firewall or VPN was treated as trusted from then on. Zero trust assumes an attacker could already be inside, and designs access controls so that being “inside” doesn’t automatically mean anything.
Why this matters for HIPAA right now
Zero trust isn’t itself a HIPAA requirement. But its building blocks map almost one-to-one onto the safeguards HHS is preparing to make mandatory in the 2026 Security Rule update: multi-factor authentication, encryption, tighter access controls, and continuous monitoring. Where those used to be “addressable” — meaning a practice could document a reason for skipping them — the direction of travel is toward “required, full stop.”
Cyber-insurance underwriters are moving the same direction. Applications increasingly ask not just “do you have MFA,” but “is access limited by role, logged, and re-verified continuously.” That’s a zero trust question wearing an insurance-form disguise.
The five areas worth focusing on
CISA’s maturity model breaks zero trust into five practical areas. You don’t need to max out all five on day one, but each is worth an honest look.
- Identity: is every login verified with MFA, and are old accounts (former staff, unused vendor logins) actually disabled, not just forgotten?
- Devices: do you know which devices are touching your EHR, and are they patched, encrypted, and monitored — not just “probably fine”?
- Networks: is your network segmented so a compromised front-desk PC can’t reach billing systems or backups directly?
- Applications and workloads: are staff only able to reach the specific systems their role needs, instead of broad access “just in case”?
- Data: is PHI encrypted at rest and in transit, with access logged so you can actually answer “who looked at this record” if asked?
How to start without a rip-and-replace project
Zero trust sounds like it demands a full infrastructure overhaul. In practice, most practices already have pieces of it and just need to connect them.
- Start with identity: enforce MFA everywhere, and run a clean sweep of who still has access to what.
- Segment what you can: separate clinical systems from guest Wi-Fi and general office traffic before touching anything more complex.
- Turn on the logging you already have: most EHRs, firewalls, and cloud platforms log access by default — the gap is usually that nobody reviews it.
- Tighten access by role: move from “everyone can see everything” to access scoped to what each role actually needs.
- Treat it as a maturity curve, not a finish line: CISA’s own model has four stages from traditional to optimal. Moving up one stage this year is a legitimate, defensible step.
Where ACS fits in
This is exactly the kind of gap analysis we run during a free IT and HIPAA assessment: where your identity, device, network, and data controls stand today, and the shortest realistic path to closing them before the 2026 Security Rule changes take effect.


