00:00:14 --> 00:00:20
Today we’re looking at a new twist that could hit any business running a patient portal that also touches DoD contracts.
00:00:20 --> 00:00:34
That’s right. The Department of Defense is tightening the rules around Controlled Unclassified Information, or CUI, and it’s forcing a lot of healthcare and defense contractors to re-examine what data lives in their portals.
00:00:35 --> 00:00:39
So the question is: when does a patient portal actually become subject to the CMMC?
00:00:40 --> 00:00:53
The trigger is simple: if the portal stores or processes CUI for a DoD contract, it falls under the NIST SP 800-171 controls and must achieve Level Two certification.
00:00:53 --> 00:01:00
And that means the 110 controls from NIST SP 800-171 Revision 2, right?
00:01:00 --> 00:01:11
Exactly. Those 110 controls are grouped into 14 domains-access control, audit and accountability, system and communications protection, and so on.
00:01:12 --> 00:01:15
Does that apply to all patient data, or just certain parts?
00:01:16 --> 00:01:34
Only the data that the contract designates as CUI. If your portal only handles civilian patient records, CMMC doesn’t apply. But if you’re a DoD contractor and your portal stores technical data, procurement details, or any other defense information, those pieces become CUI.
00:01:34 --> 00:01:37
How do organizations know if their data is CUI?
00:01:37 --> 00:01:50
The contract must explicitly state that the system handles CUI. The designation isn’t self-determined; it comes from the designating agency and is defined under 32 CFR Part 2002.
00:01:51 --> 00:01:55
So the contract includes DFARS 252-7012?
00:01:56 --> 00:02:14
Yes, that clause requires protecting CUI with the 110 controls. And if the contract includes DFARS 252-7021, you’re also subject to the acquisition rule that came into effect on November 10, 2025.
00:02:14 --> 00:02:17
What about Federal Contract Information, or FCI?
00:02:18 --> 00:02:31
FCI is a different beast. It’s covered by Level One, which is 15 basic safeguarding requirements from FAR 52-21. But CUI is Level Two, so it’s a higher bar.
00:02:31 --> 00:02:39
So a portal that only handles civilian patient data is safe from CMMC, but if it touches DoD data, it’s on Level Two?
00:02:39 --> 00:02:45
That’s the crux. The portal’s scope must be mapped precisely to see if any CUI flows through it.
00:02:45 --> 00:02:50
The article mentioned a shift in scope by enclaving CUI. How does that work?
00:02:50 --> 00:03:05
Enclaving means isolating the CUI into a dedicated boundary-like a GCC High tenant or a separate cloud landing zone-so the 110 controls apply only to that narrow slice, not the entire enterprise.
00:03:05 --> 00:03:07
That sounds like a huge cost saving.
00:03:07 --> 00:03:20
Indeed. If your entire network handled CUI, you’d need to implement 110 controls everywhere, which is expensive and complex. Enclaving trims the audit surface and the ongoing maintenance.
00:03:21 --> 00:03:23
What’s the timeline for getting a Level Two certificate?
00:03:24 --> 00:03:38
Most readiness engagements last 12 to 14 weeks. But from gap assessment to a C3PAO-ready state can take 6 to 18 months, depending on your starting posture and how complex the CUI environment is.
00:03:39 --> 00:03:40
And the certification itself?
00:03:40 --> 00:03:57
Only a Certified CMMC Professional Assessment Organization, or C3PAO, can conduct the assessment and issue the Level Two certificate. The results go to eMASS and the certificate appears in the Supplier Performance Risk System.
00:03:57 --> 00:04:00
Can a Registered Provider Organization handle the assessment?
00:04:01 --> 00:04:13
No, an RPO like Petronella Technology Group, Inc. can prepare you, but the final assessment must be performed by an independent C3PAO to avoid conflicts of interest.
00:04:13 --> 00:04:15
How many C3PAOs are there?
00:04:15 --> 00:04:32
As of March 2026, the list had 103 authorized C3PAOs. Level Two certifications grew from 773 in January 2026 to 1 in May 2026.
00:04:32 --> 00:04:33
That’s a lot of growth.
00:04:34 --> 00:04:43
It shows the program is maturing, but it also means competition for C3PAO resources can be tight, especially when deadlines loom.
00:04:43 --> 00:04:46
Speaking of deadlines, what’s the current status?
00:04:46 --> 00:04:58
The DoD CIO suspended the Phase II deadline in July 2026. Phase I self-assessments remain in force, so contractors still need to perform those internal reviews.
00:04:58 --> 00:05:01
Self-assessments-what do they involve?
00:05:01 --> 00:05:16
They’re a series of internal checks against the 110 controls, documented in a System Security Plan, or SSP. It’s a living document that records owners, evidence pointers, and policies across the 14 domains.
00:05:16 --> 00:05:19
So the SSP is essential for the assessment?
00:05:19 --> 00:05:32
Absolutely. The SSP, along with 14 control-family policies, an incident response plan, an acceptable use policy, and a media protection policy, form the foundation of the evidence package.
00:05:33 --> 00:05:37
What about incident reporting? The article mentioned a 72-hour window.
00:05:37 --> 00:05:53
DFARS 252-7012 mandates reporting any cyber incident affecting covered defense information to the DoD within 72 hours of discovery, through the dibnet.dod.mil portal.
00:05:53 --> 00:05:57
That portal requires a DoD-approved medium assurance certificate?
00:05:57 --> 00:06:04
Yes, you must obtain that certificate ahead of time. Without it, you can’t submit the report, which would be a compliance breach.
00:06:05 --> 00:06:08
Once an incident is reported, what else must be done?
00:06:08 --> 00:06:20
You need to preserve images of affected systems and monitoring data for at least 90 days, submit isolated malicious software to the government, and hold cloud providers to a FedRAMP Moderate baseline.
00:06:21 --> 00:06:24
The article also mentioned the need for FIPS-validated cryptography.
00:06:24 --> 00:06:38
Correct. NIST SP 800-171 requires FIPS-validated cryptography for protecting CUI. Strong commercial encryption that isn’t FIPS-validated doesn’t meet the standard.
00:06:38 --> 00:06:41
And if the portal is hosted on a cloud provider?
00:06:41 --> 00:06:50
The provider must meet a FedRAMP Moderate baseline-or an equivalent-because encrypted CUI in a cloud still requires that protection.
00:06:50 --> 00:06:51
So many moving parts.
00:06:52 --> 00:07:02
It’s a complex puzzle: scope definition, enclaving, control implementation, documentation, incident reporting, and finally, the C3PAO assessment.
00:07:02 --> 00:07:05
What are the biggest pitfalls that organizations run into?
00:07:05 --> 00:07:17
Over-scoping is a common mistake-applying the 110 controls to the entire enterprise when only a specific portal handles CUI. That inflates cost and effort.
00:07:17 --> 00:07:20
And ignoring the 72-hour reporting requirement?
00:07:20 --> 00:07:28
Exactly. Many fail to secure the medium assurance certificate in advance, so they can’t report in time and risk non-compliance.
00:07:28 --> 00:07:30
Unvalidated cryptography is another.
00:07:30 --> 00:07:38
Yes, using non-FIPS-validated encryption for CUI is a direct “not met” finding and can derail an assessment.
00:07:39 --> 00:07:41
Flow-down to subcontractors-why is that important?
00:07:42 --> 00:07:56
DFARS 252-7012 must be flowed down whenever subcontractors handle covered defense information. They must report their own incidents and provide the report number to you.
00:07:56 --> 00:07:58
So the SSP can’t be static.
00:07:58 --> 00:08:09
Right. It’s a living document. Every change in architecture, cloud provider, or system requires an SSP update, or the assessment will flag it as outdated.
00:08:09 --> 00:08:12
The article mentioned the cost of readiness engagements.
00:08:12 --> 00:08:22
A typical readiness engagement for a mid-size contractor runs 12 to 14 weeks, covering discovery, gap analysis, remediation, and a readiness handoff.
00:08:22 --> 00:08:24
And the remediation sprint?
00:08:24 --> 00:08:36
That’s usually weeks five through twelve, focused on high-priority gaps-like implementing FIPS-validated cryptography, ensuring FedRAMP compliance, and tightening access controls.
00:08:36 --> 00:08:38
What about the final assessment?
00:08:38 --> 00:08:50
Once you’re ready, you hand off to a C3PAO, who performs the assessment, submits findings to eMASS, and if everything meets the Level Two criteria, issues the certificate.
00:08:50 --> 00:08:54
The article also touched on the DOJ Civil Cyber-Fraud Initiative settlements.
00:08:54 --> 00:09:06
Those settlements-Verizon, Penn State, Raytheon, Georgia Tech-highlight the financial risk of non-compliance, but they’re more of a cautionary backdrop than a direct regulatory requirement.
00:09:06 --> 00:09:11
So the main focus remains on scope, enclaving, controls, and reporting.
00:09:11 --> 00:09:17
Exactly. That’s the core of the compliance journey for any patient portal that might touch DoD data.
00:09:17 --> 00:09:22
Given all that, what should organizations do next to align their portals with these requirements?
00:09:22 --> 00:09:27
We’ll walk through a practical approach-starting with a quick scoping call to map out the CUI boundaries.
00:09:28 --> 00:09:34
That call will identify which patient data, if any, is designated CUI and where it resides.
00:09:34 --> 00:09:40
Once the boundaries are clear, the next step is to assess whether we can enclave the CUI in a dedicated environment.
00:09:41 --> 00:09:49
And that decision will shape the entire compliance strategy, from control implementation to the eventual C3PAO assessment.
00:09:49 --> 00:09:55
So let’s dive into the first practical step: defining the CUI scope and choosing the right enclave strategy.
00:09:56 --> 00:10:02
That’s where we can start turning these regulatory requirements into a concrete plan for your organization.
00:10:02 --> 00:10:09
So now that we’ve mapped the CUI boundaries, the next logical step is to document the scope in a System Security Plan.
00:10:09 --> 00:10:19
Exactly, the SSP must list every system, data flow, and control owner. It’s the foundation for the 110 controls and the evidence trail.
00:10:19 --> 00:10:24
And that evidence trail feeds directly into the 72-hour incident reporting requirement, right?
00:10:25 --> 00:10:38
Yes. DFARS 252-7012 mandates reporting any cyber incident that affects covered defense information within 72 hours via the DoD portal.
00:10:38 --> 00:10:45
That portal requires a DoD-approved medium assurance certificate. Do you recommend getting that in parallel with the SSP?
00:10:45 --> 00:10:53
Absolutely. It’s a gatekeeper. Without the certificate you can’t submit incident data, and you risk non-compliance penalties.
00:10:53 --> 00:11:00
Speaking of penalties, the DOJ settlements show the financial stakes. How does that shape the urgency for compliance?
00:11:01 --> 00:11:14
Settlements like Verizon’s $4.09 million or Raytheon’s $8.4 million illustrate that non-compliance can be costly. It’s a strong motivator to finish the gap analysis early.
00:11:14 --> 00:11:20
Let’s talk gap analysis. What should an organization look for during that phase?
00:11:20 --> 00:11:36
Start by mapping each of the 14 NIST SP 800-171 domains. See which of the 110 controls are met, partially met, or absent. Prioritize controls that protect CUI in transit and at rest.
00:11:36 --> 00:11:39
Those are the FIPS-validated cryptography controls, correct?
00:11:39 --> 00:11:49
Correct. Using strong encryption that isn’t FIPS-validated is a direct ‘not met’ finding. Make sure all cryptographic modules meet the standard.
00:11:49 --> 00:11:53
Once the gaps are identified, what’s the remediation sprint like?
00:11:53 --> 00:12:04
Typically it spans weeks five through twelve. Focus on establishing role-based access, ensuring secure audit logs, and configuring network segmentation for the enclave.
00:12:04 --> 00:12:10
Segmentation is key to keeping the enclave isolated from civilian data. How do you enforce that technically?
00:12:11 --> 00:12:21
Use dedicated cloud landing zones or a GCC High tenant. Apply strict firewall rules, enforce zero-trust access, and limit inter-tenant data flow.
00:12:22 --> 00:12:26
That makes sense. Now, what about the mock assessment you mentioned earlier?
00:12:27 --> 00:12:39
The mock assessment is a rehearsal. It tests whether your evidence, SSP, and POA&M are ready for the real C3PAO. It often reveals gaps you missed during remediation.
00:12:39 --> 00:12:42
And the POA&M-how is that managed over time?
00:12:42 --> 00:12:55
Review it quarterly. Any new findings or changes in scope must be added, and the plan must be closed within 180 days per 32 CFR 170.21.
00:12:55 --> 00:12:59
What are the most common mistakes organizations make during this entire process?
00:12:59 --> 00:13:08
Over-scoping is the biggest. Applying controls to the entire network when only a portal handles CUI inflates effort and cost.
00:13:08 --> 00:13:11
Another mistake is ignoring the 72-hour reporting requirement.
00:13:12 --> 00:13:18
Exactly. Failure to report within that window triggers DFARS penalties. It’s non-negotiable.
00:13:19 --> 00:13:22
Unvalidated cryptography is also a frequent pitfall.
00:13:22 --> 00:13:29
Yes. Many vendors default to commercial encryption that isn’t FIPS-validated. That’s a direct compliance failure.
00:13:30 --> 00:13:33
Flow-down to subcontractors is another area that trips people up.
00:13:33 --> 00:13:47
Correct. DFARS 252-7012 must be flowed down. Verify each subcontractor’s compliance and have contractual clauses that obligate them to report incidents.
00:13:47 --> 00:13:51
What about the SSP being a living document? How often should it be updated?
00:13:51 --> 00:14:01
Every time you change architecture, cloud provider, or add new services. A stale SSP can cause a C3PAO to fail the assessment.
00:14:01 --> 00:14:07
Let’s consider the timeline. How long does it take from gap assessment to C3PAO readiness?
00:14:07 --> 00:14:17
Typically 6 to 18 months, depending on starting posture and complexity. A mid-size contractor’s readiness engagement runs 12 to 14 weeks.
00:14:17 --> 00:14:21
And once you’re C3PAO ready, what’s the assessment process like?
00:14:22 --> 00:14:34
The C3PAO conducts the assessment, submits findings to eMASS, and if all Level Two criteria are met, issues the certificate. The certificate is stored in SPRS.
00:14:34 --> 00:14:38
The article mentioned Phase II suspension. How does that affect the timeline?
00:14:38 --> 00:14:51
Phase II deadlines are suspended as of July 2026, but Phase I self-assessments remain. So you can still complete your self-assessment and prepare for the eventual C3PAO assessment.
00:14:52 --> 00:14:57
What if an organization only handles civilian patient data and not DoD contracts?
00:14:57 --> 00:15:05
Then CMMC doesn’t apply. You’re only subject to HIPAA, which is a separate framework focused on ePHI.
00:15:05 --> 00:15:10
But if a future contract introduces CUI, would the existing portal need to be re-enclave?
00:15:10 --> 00:15:19
Yes. You’d need to reassess scope, re-enclave if necessary, and ensure all 110 controls are applied to the new CUI boundary.
00:15:20 --> 00:15:23
What questions do listeners frequently ask about this process?
00:15:23 --> 00:15:35
Common questions include: ‘Do I need a FedRAMP Moderate baseline for my cloud provider?’ ‘How do I handle multiple vendors?’ ‘What are the specific FIPS requirements for encryption?’
00:15:35 --> 00:15:37
And how do you recommend addressing those?
00:15:37 --> 00:15:50
Verify your provider’s FedRAMP status first. For multiple vendors, document each vendor’s compliance and include flow-down clauses. For FIPS, use validated modules from approved vendors.
00:15:50 --> 00:15:55
Another question is about cost. How can organizations manage the financial impact?
00:15:56 --> 00:16:06
Enclaving CUI in a narrowly scoped boundary reduces the number of controls you must implement across the entire network, lowering cost and complexity.
00:16:06 --> 00:16:11
That makes sense. Are there any tools that can help with the SSP and POA&M?
00:16:11 --> 00:16:23
There are commercial platforms that automate evidence collection and map controls to NIST SP 800-171. They can streamline the gap analysis and remediation planning.
00:16:24 --> 00:16:27
Do you recommend starting with a scoping call before engaging a readiness provider?
00:16:28 --> 00:16:37
Definitely. A 30-minute scoping call can identify the CUI boundary, assess initial readiness, and provide a fixed-scope quote for the engagement.
00:16:37 --> 00:16:42
Once we’ve scoped and identified the enclave, what’s the next immediate action?
00:16:42 --> 00:16:51
Immediately begin the SSP drafting. Assign owners for each control, gather evidence, and set up the POA&M template.
00:16:51 --> 00:16:55
How do we ensure that the SSP remains accurate during the remediation sprint?
00:16:55 --> 00:17:03
Use a living document approach-update controls as they’re implemented, and document any changes in system architecture or data flow.
00:17:04 --> 00:17:08
During the remediation sprint, what are the top three controls to tackle first?
00:17:08 --> 00:17:19
Prioritize access control, audit and accountability, and system and communications protection. These domains directly address CUI confidentiality and integrity.
00:17:20 --> 00:17:25
After remediation, we run the mock assessment. What should we look for if the mock assessment fails?
00:17:26 --> 00:17:38
Identify the specific ‘not met’ findings, update your POA&M, and schedule additional remediation. The goal is to reduce evidence gaps before the C3PAO arrives.
00:17:38 --> 00:17:44
Finally, what’s the key takeaway for organizations that might be on the fence about investing in CMMC readiness?
00:17:44 --> 00:17:58
The key takeaway is that proper scoping, enclaving, and disciplined implementation of the 110 controls protect both your organization and your DoD partners, and avoid costly settlements and penalties.
00:17:58 --> 00:18:04
Thank you for walking us through the entire journey, from scoping to the final C3PAO assessment.
00:18:04 --> 00:18:10
It’s been a pleasure. Remember, the goal is to keep your patient portal secure while meeting DoD obligations.
00:18:11 --> 00:18:18
Absolutely. And for listeners, the next step is to schedule that scoping call to begin defining their CUI boundaries.
00:18:18 --> 00:18:24
Exactly. That call will clarify which data is CUI, where it resides, and what controls are needed.
00:18:25 --> 00:18:30
Once that’s clear, the organization can choose the enclave strategy that best fits their architecture.
00:18:30 --> 00:18:37
And from there, the remediation sprint, mock, and C3PAO readiness follow in a predictable sequence.
00:18:37 --> 00:18:48
Great. So the path is clear: scope, enclave, SSP, remediation, mock, and finally the C3PAO assessment.
00:18:48 --> 00:18:58
Yes, and keeping the SSP alive, the POA&M up-to-date, and the incident response plan ready will sustain compliance over the triennial reassessment cycle.