The healthcare industry is facing increasing pressure to address the fragmentation in their security systems. Many healthcare security leaders have recognized that their infrastructure is fragmented, posing significant risks, but remain uncertain about how to integrate these systems without incurring substantial costs.
The challenge is rooted in the sector's historical development, where physical security and cybersecurity evolved independently under separate management. Facility management typically handles badge readers, cameras, and alarms, while IT departments manage networks and software, each under different procurement and reporting structures.
However, with the latest Health Insurance Portability and Accountability Act (HIPAA) updates nearing completion, the importance of addressing this fragmentation has transformed from an operational requirement into a regulatory mandate.
Vulnerability of disconnected systems
Disconnected security infrastructure poses active vulnerabilities. In hypothetical scenarios shared with hospital security teams, a simple act such as an intruder accessing an unsecured server room exemplifies how physical breaches turn into cybersecurity issues. This is due to network convergence, where physical security devices like cameras and access panels operate on the same networks as clinical systems, transforming seemingly isolated vulnerabilities into network-wide security threats.
The infamous ransomware attack in a London hospital, affecting blood work operations, originated from a physical security breach, underlining the risks associated with disconnected systems which extend beyond administrative inconveniences to exploitable vulnerabilities.
The need for unified security systems
Healthcare facilities need a unified platform for managing security solutionsWhile many hospitals report having security systems in place, the lack of connectivity between them remains a significant issue. Healthcare facilities need a unified platform for managing access control, video surveillance, visitor management, and intrusion detection.
This integrated infrastructure enables automated functions such as credential revocation and real-time access monitoring, which are otherwise impossible with standalone systems. The emphasis on unified infrastructure is also economically advantageous, as it reduces the ongoing costs of maintaining disconnected systems and simplifies compliance with looming regulatory requirements.
Regulatory momentum from HIPAA updates
The imminent HIPAA update, the first major one in over 10 years, signals a regulatory shift, emphasizing the need for integrated security systems across healthcare facilities. New requirements, such as the revocation of physical access credentials within an hour of employee termination across all facilities, demand systems capable of interfacing with human resource workflows to automate these processes.
HHS estimates initial compliance costs at $9 billion, largely due to retrofits for integrating systems not originally designed to work together. Facilities that begin proactive investments in this infrastructure now will find these preparations less costly than the emergency actions required under regulatory deadlines.
Beyond compliance: A case for safety
While compliance with HIPAA updates is crucial, the benefits of unified security infrastructure stretch beyond meeting regulatory demands. Such systems significantly enhance workplace safety in healthcare settings, where workers face heightened risks of violence.
With US hospitals spending significant amounts on violence-related costs, the integration of security systems effectively reduces these risks by closing operational gaps. The conversation should not only focus on meeting compliance but should also address improving safety, ultimately making these investments beneficial for protecting healthcare personnel and patients alike.
Visitor management and infrastructure connectivity
Acre’s FAST-PASS enables fast, secure visitor processing through a unified access control platformVisitor management remains a visible risk in facilities with disconnected infrastructure. Despite hospitals being open environments, the manual processing of visitors often creates vulnerabilities. The updated HIPAA regulations now explicitly include visitor management within their scope, linking it to broader compliance requirements like network segmentation.
Acre's FAST-PASS solution offers an expedited and secure visitor processing system that integrates directly with the broader access control platform, streamlining compliance and operational security from a central interface.
Proactive approach to compliance
Healthcare organisations have a window to approach the HIPAA compliance deadline either reactively or proactively. The former involves merely ticking compliance boxes, potentially leaving underlying issues unaddressed, while the latter includes using this regulatory moment as an impetus to implement truly effective security infrastructure.
Organisations that invest now in unified systems will inevitably develop more secure, efficient, and scalable operations, ultimately fostering environments where both staff and patients are genuinely safer.
Lately, when talking to healthcare security leaders, one thing has been coming up more than anything else: they know their security infrastructure is disconnected; they know it creates risk, and they’re not sure how to close the gap without a costly overhaul.
That’s not a failure of intent. It’s a consequence of how security was built in the healthcare sector. Over decades, physical security and cybersecurity have developed distinct disciplines with separate ownership. Facility teams would manage badge readers, cameras, and alarm panels where IT managed networks, servers, and software. Each domain had its own vendors, its own procurement cycles, and its own reporting lines. Understandably, back then the assumption was that running them independently was sufficient.
That assumption has since broken down in a big way – and the consequences are showing up in incident reports, compliance gaps, and operational risk that most organisations haven’t fully mapped out yet.
Now, with the most significant update to HIPAA in over a decade nearly final, the pressure to address that fragmentation is no longer just operational. It's regulatory.
Disconnected infrastructure is an active vulnerability
Here’s a scenario to use when talking to hospital security teams:
A bad actor walks into a hospital, finds an unsecured server room, and plugs in a laptop. At what point does that become a cyber problem?
The answer is: immediately. And it never stops being a physical security problem either.
The reason is network convergence. Physical security devices – cameras, access control panels, intercoms, alarm systems – are no longer standalone hardware operating in isolation. They’re IP-connected devices running on the same infrastructure as clinical systems and patient records. A compromised camera becomes a network entry point. An unsecured access control panel can serve as a pivot to a server. A visitor who reaches a networked terminal has potentially bypassed digital defenses entirely – without even touching a keyboard.
The London hospital ransomware attack that shut down blood work operations didn’t begin with a sophisticated intrusion. It began with physical access to the facility. That’s the operational reality healthcare organisations are now working within. Disconnected security infrastructure doesn’t just create administrative friction; it creates exploitable gaps.
What unified security infrastructure requires
When asked hospitals to describe their current security posture, the most common answer is: we have systems in place, but they aren't connected.
Most organisations have some level of physical security deployed. What's typically missing is a common operational layer – a way to manage access control, video, visitor management, and intrusion detection from a single platform rather than through separate consoles with no shared data.
The facilities that are furthest ahead aren't always the ones with the largest budgets. They're the ones that made a deliberate decision to stop procuring point solutions and start building toward integrated infrastructure. That shift changes what's possible: automated credential revocation, real-time access visibility across sites, incident response that correlates physical and digital events in a single view, and the list goes on. None of that is available when the systems can't communicate.
The fragmentation itself is also a cost driver, not just a security problem. Organisations running disconnected systems across multiple vendors face higher support overhead, inconsistent policy enforcement, and expensive integration work when they eventually need to consolidate. The organisations investing in unified infrastructure now are building an asset. The ones deferring it are accumulating technical debt with a compliance deadline attached.
The compliance forcing function
The first major update to HIPAA in more than a decade is nearly final. It represents the clearest regulatory signal yet, noting that standalone, disconnected security systems are no longer adequate for healthcare environments.
Every control becomes mandatory – this includes multifactor authentication, encryption, network segmentation, annual penetration testing. And one requirement under the HIPAA access control rules that most organisations aren't prepared for: physical access credentials must be revoked within one hour of employee termination, across every facility, every door, every restricted area simultaneously. Can your current system do that?
This required function is not achievable with disconnected systems. It requires access control that integrates with HR workflows, so that credential revocation happens automatically when a termination is processed – not when someone remembers to chase down a badge. The infrastructure required to meet that single requirement is the same infrastructure that closes the broader gaps across the estate.
HHS estimates first-year compliance costs at $9 billion – in large part because so many organisations are paying to retrofit integration that should have been built in from the start. The facilities beginning this work now have a different path available. Proactive infrastructure investment is significantly less expensive than emergency remediation under a regulatory deadline.
The safety case goes beyond compliance
To be direct about something. The HIPAA deadline is a forcing function — but it shouldn't be the only reason healthcare organisations are having this conversation.
The infrastructure required to meet the updated standards – unified access control, real-time monitoring, automated credential management, visitor screening – is the same infrastructure that makes hospitals genuinely safer for the people working in them every day.
The numbers make that case plainly. Healthcare workers are five times more likely to experience workplace violence than workers in any other industry, and US hospitals spent $18.27 billion on violence-related costs in 2023. These aren't abstract statistics — they reflect what happens when the systems designed to protect people operate in isolation from each other. Connected infrastructure doesn't just satisfy a compliance requirement. It closes the gaps that put staff at risk in the first place.
Compliance and operational safety aren't parallel goals. They're the same investment, finally being recognised as such.
What this looks like at the point of entry
One of the places with disconnected infrastructure is creating the most visible risk that is visitor management. Hospitals are inherently open environments – patients, families, contractors, and vendors moving through constantly. That accessibility is operationally necessary. It's also one of the most consistent vulnerabilities in the security posture of most facilities.
Running background checks, issuing credentials, tracking who's in the building – most facilities still handle this manually, or with tools that sit outside their core security infrastructure. Under the updated HIPAA requirements, visitor management is explicitly in scope. It connects directly to the network segmentation and audit trail requirements that are expected to become mandatory later this year.
FAST-PASS is Acre's answer to this. It processes every visitor in seconds, cross-checks automatically against watchlists, and generates the compliance record as part of the workflow — not assembled after the fact. It connects directly into the broader access control platform, so visitor data isn't siloed the moment someone walks through the door. New visitors in 15–20 seconds, returning guests in under 10.
It's a practical example of what connected infrastructure looks like at the front door.
FAST-PASS is part of the Acre Identity platform, which is built to support HIPAA, ISO 27001, and Joint Commission readiness from the ground up.
The window is still open
There are two ways healthcare organisations can approach the HIPAA deadline. The first path is to treat it as a line to clear – address the specific requirements, document compliance, and move on. That approach is expensive, produces compliance without capability, and leaves the underlying infrastructure problem unsolved.
The other is to treat this moment as the organisational catalyst to build security infrastructure that actually works – where unified systems, automated workflows, and real-time visibility become the foundation, and compliance is a byproduct rather than a project.
The tools to do this exist. The regulatory direction is clear. The organisations that make this investment now will emerge with hospitals where staff are safer, patients are better protected, and security operations are manageable at scale. That's the outcome worth building toward – and with the deadline approaching, the organisations that start now will have options that those who wait won’t.