Short answer: the HIPAA Security Rule never uses the word “firewall.” It requires a risk analysis and safeguards — access control, audit controls, transmission security, malware protection, and backups — and for an organization with several locations, a consistent firewall and segmentation policy is how most of those safeguards are actually enforced. AI tools add a new kind of outbound traffic that belongs in that policy too.
Does HIPAA require a firewall?
HIPAA is technology-neutral. Instead of naming products, the Security Rule tells covered entities and business associates to protect electronic protected health information (ePHI) with administrative, physical, and technical safeguards chosen through a documented risk analysis. On a network that spans clinics, offices, and data centers, those requirements translate directly into firewall and segmentation decisions:
| Security Rule requirement | Citation | What it means across locations |
|---|---|---|
| Risk analysis and risk management | 45 CFR §164.308(a)(1) | Map every network path ePHI can take between sites and document the controls on each one |
| Protection from malicious software | §164.308(a)(5)(ii)(B) | Malware defenses at every location, not only headquarters |
| Data backup and contingency plan | §164.308(a)(7) | Backups that ransomware at one site cannot reach or encrypt |
| Access control | §164.312(a)(1) | Only authorized users and systems reach ePHI systems — enforced at the network layer as well as in applications |
| Audit controls | §164.312(b) | Record and examine activity on systems that hold ePHI, with logs collected centrally |
| Transmission security | §164.312(e)(1) | Protect ePHI moving between locations, typically with encrypted site-to-site links |
Some implementation specifications are “addressable” rather than “required.” Addressable does not mean optional: you implement the specification if it is reasonable and appropriate, or document why an equivalent alternative is used instead.
Firewall design for multi-location healthcare
Most problems in multi-site networks come from inconsistency: a newer clinic built to a different standard, a temporary rule nobody removed, a flat network that treats every location as one trusted zone. A sound design keeps the policy the same everywhere:
- One policy, managed centrally. Each site’s firewall enforces the same rule set, with site-specific exceptions documented.
- Encrypted links between sites. Site-to-site VPN or SD-WAN, so ePHI never crosses the internet in the clear.
- Segmentation inside every site. Separate zones for ePHI systems, clinical and IoT devices, staff workstations, and guest Wi-Fi.
- Default-deny egress from ePHI segments. Systems that hold patient data only reach the destinations they need, by allowlist.
- Central logging. Firewall and access events from every location flow to one place where someone actually reviews them.
- Scheduled rule reviews. After every site opening, closure, or system change — and on a fixed calendar in between.
Stopping malware from spreading between sites
Ransomware rarely stays where it lands. On a flat network, one infected workstation at a small clinic can reach file shares, EHR servers, and backups at every other location. The defenses are layered:
- Segment between sites, not just within them — a clinic should reach shared systems only through defined, monitored paths.
- Least privilege for admin accounts and remote access, so one stolen credential does not open every location.
- Endpoint protection and patching at every site, tracked centrally rather than left to each office.
- Backups isolated from the production network, with restores tested — a backup that can be encrypted is not a backup.
What AI tools change about your firewall rules
Every cloud AI tool staff use — chat assistants, dictation, coding helpers, browser extensions — is a new outbound path that can carry ePHI. Most organizations have no inventory of them. Treat them like any other data flow:
- Inventory the AI tools in use at every location, including browser extensions and features built into existing software.
- Allow only approved tools, each covered by a Business Associate Agreement where it handles ePHI.
- Block unapproved AI services at egress with DNS or web filtering, and log attempts.
On-premise AI turns this around. When the model runs on a server inside your ePHI segment, it needs no outbound access at all: approved applications reach it from inside the network, and the server itself sits behind a default-deny egress rule. Agent-to-agent traffic can be funneled through a single gateway where every call is logged. Compare on-premise and cloud AI deployment models, or see how GofarAI’s platform is designed to run with no outbound dependencies.
The proposed rule: segmentation may become mandatory
In January 2025, HHS proposed the first major update to the Security Rule in years. Among other changes, it would make network segmentation a required implementation specification instead of something organizations decide on through risk analysis. As of October 2026, the update has not been finalized; its expected timeline has already slipped and could change again. Check HHS’s Office for Civil Rights for the current status — but segmentation is sound practice whether or not it becomes mandatory.
Multi-location HIPAA firewall checklist
- A current network diagram showing every site and every path ePHI takes.
- One firewall policy, centrally managed, applied at each location.
- Encrypted links between all sites.
- Separate segments for ePHI systems, clinical devices, workstations, and guests.
- Default-deny egress from ePHI segments, with an allowlist.
- An inventory of AI and SaaS tools that touch ePHI, with BAA status for each.
- Malware protection on every endpoint and server, at every site.
- Backups isolated from the production network, with tested restores.
- Central logging of firewall and access events, reviewed on a schedule.
- Rule reviews after every site change and on a fixed calendar.
Frequently asked questions
Does HIPAA require a firewall?
Not by name. The HIPAA Security Rule requires a risk analysis and safeguards such as access control, audit controls, transmission security, and protection from malicious software. For any networked organization, firewalls are one of the main ways those safeguards are implemented, and auditors will expect to see them.
Do all locations need the same firewall rules?
They should follow the same policy, managed centrally and enforced consistently. Individual sites will have different devices and systems, but no location should be the weak link that gives an attacker a path to every other site.
Is a site-to-site VPN HIPAA compliant?
A properly configured, encrypted site-to-site VPN or SD-WAN link is a common way to meet the transmission security requirement for ePHI moving between locations. Whether your setup is compliant depends on your overall risk analysis and how the link is configured, monitored, and maintained.
How do AI tools change HIPAA firewall policy?
Every cloud AI tool — chat assistants, dictation, coding helpers, browser extensions — adds an outbound path that can carry ePHI. Inventory them, allow only approved tools covered by a Business Associate Agreement, and block the rest at egress. On-premise AI avoids the outbound path entirely.
This article is general information, not legal advice. Confirm your organization’s obligations with your compliance team or counsel.
Running AI across several locations? GofarAI Labs deploys open-weight models on hospital hardware, behind your firewall. Plan a pilot →