July 2, 2026 · KeyCaliber
HIPAA Is About to Make Asset Inventory Mandatory
For 20 years the Security Rule stayed vague about knowing your systems. A 2025 proposal would end that — requiring a technology asset inventory and a network map of how ePHI moves.
For two decades, the HIPAA Security Rule asked healthcare organizations to protect electronic protected health information without ever telling them, in plain terms, to know what systems they had. Many of its specifications were “addressable” — a word too many organizations read as optional. The result is visible in the breach reports: healthcare has become one of the most-attacked sectors, and investigations after the fact keep finding the same root cause — an incomplete or absent risk analysis, run against an environment no one had fully inventoried.
That era is ending.
What the 2025 proposal would require
In January 2025, HHS’s Office for Civil Rights issued a Notice of Proposed Rulemaking to modernize the Security Rule. Among the most consequential changes: it would make a technology asset inventory and a network map explicitly mandatory — removing the “addressable” flexibility that let organizations skip them.
As proposed, the technology asset inventory would require written documentation identifying all technology assets, including each asset’s location, the person accountable for it, and its version. Critically, it would cover not only assets that create, receive, maintain, or transmit ePHI, but also those that don’t — yet could still affect the confidentiality, integrity, or availability of ePHI.
The network map would have to illustrate how ePHI moves through your systems: how it enters, exits, and is accessed from outside, including the assets business associates use to handle it. Both the inventory and the map would need to be reviewed and updated at least every 12 months and whenever the environment changes.
The proposal isn’t final, and details may shift. But the direction is unmistakable, and the smart move is to be ready rather than surprised.
Inventory is the precondition for risk analysis
The reason this sits at the center of the proposal is simple: the Security Rule is built on risk analysis, and risk analysis is impossible without an inventory. You cannot identify threats to systems you haven’t enumerated, or find vulnerabilities on assets you can’t see. The NPRM makes the dependency explicit by requiring the asset inventory and network map to be reviewed as part of conducting the risk analysis.
OCR has been saying this indirectly for years through its enforcement actions. The proposed rule just stops leaving it to interpretation.
Why healthcare finds this hard
Healthcare environments are sprawling and heterogeneous: clinical workstations, imaging systems, networked medical devices and IoT, cloud EHR platforms, and a dense web of business associates who touch ePHI from outside your walls. Much of it is unmanaged, some of it is invisible to any single tool, and the network map of how ePHI flows across all of it rarely exists on paper. A manual inventory of that environment is out of date the moment it’s finished.
Where KeyCaliber fits
KeyCaliber builds the inventory this proposal anticipates from the tools you already run — connecting by API to your EDR, vulnerability scanners, CMDB, identity, and cloud, and correlating them into a single validated picture of every asset, kept continuously current.
For a HIPAA program, that maps onto what the rule is reaching for:
- Owner, location, and version are pulled from the systems that already hold them and reconciled into one record per asset — the fields the proposed inventory calls for.
- The assets that don’t obviously handle ePHI but could still affect it — the unmanaged host, the networked device, the shadow system — are exactly what KeyCaliber surfaces by correlating across tools.
- Because it maps how assets connect, it gives you the raw material for the network map of where ePHI can actually flow.
- Its coverage-gap detection shows which systems handling ePHI are missing controls, and its retained source payloads make the whole inventory defensible to an OCR investigator.
HIPAA is catching up to a truth its enforcement history already proved: you cannot protect health information on systems you never accounted for. Whether or not the final rule lands exactly as proposed, the organizations that inventory their environment now are the ones that will pass the risk analysis — and survive the breach investigation — later.
← All articles