
Author: Navneet Lounsberry
Healthcare organizations serving the DoD often overestimate how far their existing compliance posture will carry them. Here’s where the gaps actually are, and what it takes to close them before assessment day.
If your organization operates in healthcare and is now pursuing Department of Defense contracts, you have likely had a version of this conversation internally: “We already handle HIPAA. How different can CMMC really be?”
It is a reasonable question. HIPAA’s Security Rule does create a foundation in access management, encryption, and audit logging that overlaps meaningfully with many of the 110 security requirements in CMMC Level 2. Organizations that have invested seriously in HIPAA compliance are not starting from zero. That is the good news.
The problem is that this partial overlap creates a sense of readiness that does not match reality. In our work with healthcare organizations pursuing CMMC certification, we consistently find that the gap between perceived readiness and actual readiness is wider than leadership expects. The cost of discovering that gap at assessment time, rather than during preparation, can be measured in lost contract eligibility, remediation delays, and budget overruns that could have been avoided.
Credit where it is due: HIPAA-compliant organizations often have real strengths that translate to CMMC. These typically include:
This is genuine overlap, and it represents real value. But it also tends to be where the comfort level stops matching the compliance reality.
HIPAA vs. CMMC Level 2 Comparison
| Domain | HIPAA Security Rule | CMMC Level 2 (NIST 800-171) |
| Access Control | Role-based access to PHI at the application level | Least-privilege access to CUI at the data level; separation of duties; MFA for privileged accounts; session controls |
| Data Scoping | PHI identified and protected within covered systems | Formal CUI boundary definition across all systems that process, store, or transmit CUI; asset categorization required |
| Documentation | Policies and procedures documented; enforcement largely reactive | SSP, POA&Ms, network diagrams, and operational evidence actively assessed |
| Encryption | Addressable specification for PHI at rest and in transit | Required for CUI; must use FIPS 140-2 validated cryptographic modules |
| Audit & Logging | Audit trails for PHI access | Comprehensive logging, review, and retention across the CUI environment |
| Risk Assessment | Periodic risk analysis required | Formal risk assessments on a defined cadence; continuous monitoring; active vulnerability management |
| Incident Response | Breach notification procedures | Documented IR plans with defined roles, regular testing/exercises, and lessons-learned integration |
| Network Protection | Not explicitly prescribed | Network segmentation, boundary protections, secure remote access, email/web security controls |
| Configuration Mgmt. | Not explicitly prescribed | Baseline configurations, change control, restriction of nonessential software |
| Personnel Security | General workforce training on privacy and security | Insider threat awareness, role-based training for elevated access, formal CUI personnel screening |
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171. (A useful distinction for readers less familiar with the framework: NIST SP 800-171 is the control set; CMMC Level 2 is the certification program that verifies implementation against it.) HIPAA’s Security Rule, while robust for its intended purpose, was designed to protect patient health information within a healthcare delivery context. CMMC was designed to protect sensitive government data across a much broader threat landscape. The requirements reflect that difference in several critical areas.
HIPAA requires access controls around PHI, and many organizations implement this through role-based access at the application level. CMMC Level 2 demands something more precise. Organizations must implement least-privilege access across all systems that process, store, or transmit CUI. They need to enforce separation of duties, control access to CUI at the data level (not just the application level), and restrict the use of privileged accounts with specific technical controls. The NIST 800-171 Access Control (AC) family is particularly demanding here: think multi-factor authentication for all privileged accounts, session lock and termination controls, and active monitoring of privileged account activity. For healthcare organizations accustomed to broader access models built for clinical workflow efficiency, this often requires rethinking how access is provisioned, reviewed, and revoked across the entire CUI boundary.
This is frequently the largest blind spot. HIPAA compliance centers on PHI, and healthcare organizations generally know where their patient data lives. CMMC Level 2 requires organizations to identify every system, device, and user that touches CUI, and to define a formal assessment boundary around those assets. In healthcare environments, where clinical, research, and administrative systems often share infrastructure, this scoping exercise can reveal that CUI flows through far more systems than anyone initially assumed. Without a clear CUI boundary, organizations risk either underscoping (and failing assessment) or overscoping (and dramatically inflating the cost of compliance).

HIPAA requires documented policies and procedures, but enforcement has historically been triggered primarily by complaints and breaches, supplemented by periodic OCR audits. Organizations can operate for years with policies that are written broadly and never formally tested against operational evidence. CMMC Level 2 assessors expect a fundamentally different standard of proof. This means a comprehensive System Security Plan (SSP), formal Plans of Action and Milestones (POA&Ms) for any gaps, network diagrams that reflect the actual CUI boundary, and evidence that policies are reviewed, updated, and enforced on a defined schedule. Critically, assessors will want to see operational evidence: change approval tickets, system logs, training completion records, and risk registers that demonstrate controls are consistently used, not just documented. The documentation burden alone is typically two to three times what most HIPAA-compliant organizations have in place.
HIPAA does not prescribe detailed configuration management practices. CMMC Level 2 does. Organizations must maintain baseline configurations for all systems in the CUI environment, track and control changes, restrict the use of nonessential software, and enforce security configuration settings. In healthcare, where legacy systems and proprietary medical devices are common, meeting these requirements often uncovers infrastructure that cannot be easily brought into compliance without segmentation or replacement.
HIPAA requires risk analysis, but in practice many healthcare organizations treat this as a periodic exercise rather than an ongoing operational discipline. CMMC Level 2 expects formal, documented risk assessments conducted on a defined cadence, active vulnerability management, and continuous monitoring of the CUI environment. This includes regular vulnerability scanning, remediation tracking, and the ability to demonstrate that security posture is being evaluated and adjusted over time. For organizations that have relied on annual or biannual HIPAA risk assessments, the shift to a continuous monitoring model is a significant operational change.
Network segmentation, boundary protections, secure remote access controls, and email and web security are central to NIST 800-171 and CMMC Level 2, but are only implied, if addressed at all, in HIPAA’s Security Rule. Healthcare organizations operating mixed environments with clinical, research, and administrative systems on shared network infrastructure will often find that their current architecture does not provide the segmentation or boundary protections that CMMC requires around the CUI environment.
HIPAA’s breach notification requirements give most healthcare organizations a starting point for incident response, but CMMC Level 2 expects something considerably more mature. Organizations need documented incident response plans with defined roles and responsibilities, evidence of regular testing and tabletop exercises, and the ability to demonstrate that lessons learned from incidents and exercises are incorporated into updated procedures. The distinction here is between a reactive notification process and a proactive, tested response capability.
While HIPAA requires workforce training on privacy and security, CMMC Level 2 adds requirements around insider threat awareness, role-based security training for users with elevated access, and formal screening processes for personnel who will handle CUI. Healthcare organizations that rely on annual HIPAA training modules typically find that their training program needs significant expansion to satisfy CMMC requirements.
CMMC requirements are being phased into DoD solicitations beginning in late 2025, with Level 2 (C3PAO) requirements appearing in more contracts through 2026 and 2027. Full program implementation is targeted by late 2028. For healthcare organizations that serve the DoD, whether as providers, medical device manufacturers, health IT vendors, or managed service providers supporting military healthcare infrastructure, the compliance timeline is now operational, not theoretical.
What makes this particularly consequential is the assessment model. For most CUI-handling contracts once the phased rollout is complete, CMMC Level 2 certification will require a third-party assessment by an accredited C3PAO, conducted every three years. (It is worth noting that during the early phases of the rollout, some Level 2 contracts may allow self-assessment, depending on the contract type and DoD’s phased implementation schedule. But the trajectory is clearly toward third-party certification for the majority of CUI-related work.)
Organizations must achieve a minimum score of 88 out of 110 points to receive conditional certification, with all remaining gaps remediated within 180 days under a Plan of Action and Milestones. Two important caveats here: the scoring model is point-based, not a simple count of controls passed, and only certain lower-impact requirements may be deferred via POA&M, subject to DoD rules. Failure to close POA&M items within the 180-day window will affect certification status. This is a fundamentally different accountability structure than anything in the HIPAA enforcement model.
Organizations that assume their HIPAA posture covers the majority of CMMC requirements often discover the gap too late in the process, when a formal gap analysis reveals deficiencies that require months of remediation before they can credibly pursue assessment. In a competitive contract environment, that delay is the difference between eligibility and exclusion.
The organizations that navigate this transition most effectively are the ones that treat CMMC preparation as a structured project rather than a checkbox exercise. That starts with an honest assessment of where they actually stand, informed by expertise that bridges both the healthcare compliance world and the NIST/CMMC framework.
A well-executed gap analysis should accomplish several things:
This is not about creating alarm or suggesting that HIPAA compliance has no value in the CMMC context. It clearly does. The point is that the value has limits, and knowing exactly where those limits are is what separates organizations that certify on schedule from those that scramble to catch up.
At Idenhaus, we work with healthcare organizations that are navigating this exact transition. Our background in Identity and Access Management gives us a particular vantage point on the access control, governance, and documentation challenges that sit at the center of the HIPAA-to-CMMC gap. We are not a product vendor and we are not a C3PAO. We are consultants who help organizations understand where they stand, build a clear plan, and execute the remediation work that positions them for successful assessment.
If your organization is weighing CMMC compliance and wondering how much of the work is already done, the answer is worth knowing precisely. A structured gap analysis is the fastest way to get that clarity and the most effective way to avoid surprises downstream.
Contact me to schedule an initial conversation about your CMMC readiness. We will give you an honest picture of where you stand and a practical roadmap for closing the gap.
Have a more general question about cybersecurity? You can always drop us a line, and our experts will get back to you shortly. Looking for some more CMMC reading? Our list of CMMC-related blogs is always growing. Why not check one out?
About the Author:
Navneet Lounsberry is the Director of Business Development at Idenhaus Cybersecurity, an Atlanta-based IAM and cybersecurity consultancy with 15 years of enterprise experience. A Georgia Tech graduate with a career spanning IBM, SAP, Manhattan Associates, and UKG, Navneet brings a practitioner's perspective to identity security, CMMC compliance, and the very human decisions that determine whether organizations earn five stars from attackers or one.