When HIPAA Compliance Turns Your CTO Into the Bottleneck

Your CTO probably became responsible for HIPAA Compliance for a good reason.

When the company had eight employees, there wasn't anyone else.

They designed the architecture, knew which systems handled PHI, and answered buyer security questions.

When something needed to be fixed, they knew exactly where to look.

At that stage, giving compliance to the CTO made sense.

It was fast and there were fewer systems.

There were fewer employees and fewer customers.

And more autonomy for the person making compliance decisions while understanding its impact.

Then the company started succeeding and that's when your environment changed.

Growth Changes the Conditions Around the CTO

A 30-person health tech company doesn't operate like an eight-person company with 22 additional employees.

The organization becomes more complicated.

Sales is pursuing larger health systems.

Engineering has a small team and less time to ship code.

New SaaS applications are introduced.

More vendors process company or patient data.

Employees come and go.

AI tools find their way into workflows.

Enterprise buyers start requesting compliance documentation.

The number of decisions involving compliance increases.

But compliance ownership often stays where it started.

With the CTO.

There usually isn't a moment when someone formally decides this is the right operating model.

It happens through inertia.

The CTO handled compliance yesterday.

So the CTO handles it today.

Success Reinforces the Behavior

This is a primary reason companies stay in this model longer than they should.

It keeps working.

A questionnaire comes in.

The CTO answers it.

A buyer asks for an architecture diagram.

The CTO provides it.

Someone needs evidence of encryption.

Engineering pulls it together.

A customer asks about disaster recovery.

The CTO joins the call.

The deal eventually moves forward.

From the outside, the process worked.

Inside the company, something else happened.

A senior technical leader stopped what they were doing to make it work.

Every time the CTO steps in and solves the problem, the organization gets another reason to continue relying on the CTO.

Nobody feels pressure to build a different system because the current one still produces an answer.

This can continue for a long time.

Until volume exposes it.

Enterprise Sales Changes the Environment Again

Selling into larger healthcare organizations introduces a different level of scrutiny.

Health systems have their own responsibility for understanding the risk created by business associates handling PHI.

HHS makes clear that organizations can seek additional assurances from vendors based on their own risk analysis and compliance activities.

Those assurances can include documentation of safeguards and compliance assessments.

That shows up in the sales process.

Security questionnaires get longer.

The questions become more specific.

Buyers ask for policies.

Then they ask for evidence behind the policies.

Legal reviews the BAA.

Security wants penetration test results.

Someone asks when the last incident response exercise occurred.

Another buyer wants to understand your vendors.

The next one asks about AI.

The buyer is operating under pressure too.

They understand what third-party failures can do to hospital operations.

Every new vendor introduces another dependency they have to understand and defend.

So as your company moves upmarket, the questions naturally become harder.

The buyer has more at stake.

Hospitals are operating in an environment where third-party technology has become a significant source of cyber risk. The American Hospital Association continues to highlight third-party vendors as a major cybersecurity concern for healthcare organizations.

That scrutiny eventually reaches every health tech company trying to sell to them.

The CTO Responds the Way They Always Have

This is where the problem becomes interesting.

The CTO usually doesn't ignore the work.

They absorb it.

That's exactly what you would expect from someone who helped build the company.

They know the product.

They understand the infrastructure.

They care about the deal.

They don't want sales waiting.

And they probably don't trust someone without technical context to answer detailed questions about the environment.

So another questionnaire lands in their inbox.

They finish it.

Then another.

They finish that one too.

Eventually compliance starts competing with the job they were originally hired to do.

Architecture.

Engineering leadership.

Product development.

Technical strategy.

Hiring.

Scaling infrastructure.

The company now has two needs pulling on the same person.

Both are important.

Neither is getting simpler.

The Warning Signs Are Usually Operational

Companies sometimes wait for a breach before recognizing that their operating model needs to mature.

There are earlier signals.

Your sales team regularly needs the CTO to move deals forward.

Security questionnaires sit unanswered while engineering takes priority.

Different people provide different answers to buyer questions.

Policies exist, but nobody is sure they reflect how the company operates.

Risk assessments never happen.

Vendor inventory falls behind.

Compliance work gets pushed behind customer commitments and product releases.

Enterprise Buyers Are Increasing the Pressure

The regulatory environment provides another clue about where expectations are heading.

HHS' proposed update to the HIPAA Security Rule includes more prescriptive requirements around incident response testing, vulnerability scanning, penetration testing, multifactor authentication, network segmentation, backup and recovery, annual compliance audits, and documented technical safeguards. The current Security Rule remains in effect while the proposal proceeds.

Look at what those requirements have in common.

They require ongoing operation.

Someone has to schedule the test.

Someone has to review vulnerabilities.

Someone has to track remediation.

Someone has to maintain the documentation.

Someone has to verify that the control still works six months later.

Compliance maturity requires follow-through.

That becomes difficult when ownership depends on whichever engineer has enough time that week.

Why Hiring More Engineers Won't Solve the Problem

I've seen companies respond at this stage by assuming additional engineering capacity will take care of compliance.

More engineers certainly help implement controls.

But compliance leadership requires another layer of work.

Someone needs to determine what needs to happen, who owns it, when it needs to happen, what evidence should exist, and whether the work actually gets completed.

Someone also needs to understand what healthcare buyers expect before the questionnaire arrives.

That responsibility becomes increasingly important as sales volume grows.

Without it, the CTO remains the escalation point.

The Company Needs a Compliance Operating Model

Reaching this stage doesn't automatically mean you need a large internal security department.

A 25-person health tech company probably doesn't.

It does need clear ownership.

The company should know:

Who owns the HIPAA Compliance program?

Who owns risk analysis?

Who tracks remediation?

Who reviews vendors?

Who owns incident response exercises?

Who prepares compliance evidence?

Who maintains questionnaire responses?

Who works with sales when a buyer has a compliance concern?

Those responsibilities can be distributed.

Accountability cannot be vague.

The goal is to create a compliance function that continues operating when the CTO is focused somewhere else.

The CTO Should Still Be Involved

The CTO remains critical.

Compliance decisions affect architecture.

Engineering implements many of the controls.

The CTO understands technical tradeoffs that nobody else in the organization may understand as deeply.

The difference is how their time gets used.

Their involvement should center on decisions that require their expertise.

It shouldn't depend on them remembering where the latest policy lives or answering the encryption section of compliance questionnaires sales receives.

That's an expensive use of a CTO.

It's also difficult to scale.

Growth Changed What the Company Needed

The original compliance model was built for an earlier version of the organization.

It worked because the company was smaller.

Growth changed the environment around it.

More customers created more scrutiny.

More employees created more access.

More technology created more dependencies.

More enterprise deals created more questionnaires.

More regulatory expectations created more pressure.

The company changed faster than the compliance model supporting it.

The CTO is still capable of doing the work.

There is simply too much of it for the company to keep depending on them.

And that is usually the signal that HIPAA Compliance needs an owner.

—Larry

L Trotter II

As Founder and CEO of Inherent Security, Larry Trotter II is responsible for defining the mission and vision of the company, ensuring execution aligns with the business purpose. Larry has transformed Inherent Security from a consultancy to a cybersecurity company through partnerships and expert acquisitions. Today the company leverages its healthcare and government expertise to accelerate compliance operation for clients.

Larry has provided services for 12 years across the private industry developing security strategies and managing security operations for Fortune 500 companies and healthcare organizations. He is influential business leader who can demonstrate the value proposition of security and its direct link to customers.

Larry graduated from Old Dominion University with a bachelor’s degree in Business Administration with a focus on IT and Networking. Larry has accumulated certifications such as the CISM, ISO27001 Lead Implementer, GCIA and others. He serves on the Board of Directors for the MIT Enterprise Forum DC and Baltimore.

https://www.inherentsecurity.com
Next
Next

Why Health Systems Treat Health Tech Security as a Patient Safety Issue