Resource
HIPAA, CJIS, and CMMC: Making Sense of the Compliance Alphabet Soup
Compliance used to be something one person handled once a year with a checklist. For businesses in healthcare, government-adjacent work, or the defense supply chain, it's now a standing requirement with real technical teeth behind it. Here's what these three frameworks actually require, and why the acronym matters less than what's behind it.
Why compliance stopped being a once-a-year task.
For a long time, compliance meant filling out a form, checking some boxes, and moving on until the next renewal. That approach doesn't hold up anymore for businesses handling regulated data. HIPAA, CJIS, and CMMC all now expect ongoing, demonstrable controls, not a document that gets dusted off annually. The shift isn't bureaucratic overreach. It reflects how much more these frameworks now assume about what a business's technical environment actually looks like day to day.

HIPAA: healthcare's baseline, and where it actually bites.
HIPAA applies to healthcare providers and anyone handling protected health information (PHI) on their behalf. Most practices know HIPAA exists. Fewer have translated it into specific technical requirements: access logging, encryption at rest and in transit, Business Associate Agreements with every vendor that touches PHI, and a documented breach notification process with real timelines attached. The gap usually isn't awareness of HIPAA. It's the distance between knowing compliance is required and having evidence that the specific technical controls are actually in place. See our Healthcare industry page.
The consequences aren't abstract. Civil penalties from HHS scale by culpability and can reach well into six and seven figures per violation category for neglect that isn't corrected, adjusted upward every year. Criminal penalties exist separately, prosecuted by the Department of Justice rather than HHS, and they apply to individuals, not just organizations. Knowingly obtaining or disclosing PHI carries up to one year in prison and a $50,000 fine. Doing so under false pretenses raises that to five years and $100,000. Doing it for personal gain, commercial advantage, or malicious intent raises it again to ten years and $250,000. These aren't theoretical tiers. Employees have been prosecuted and sentenced under them for accessing or stealing patient data.
CJIS: the standard behind law enforcement and government-adjacent data.
CJIS (Criminal Justice Information Services) sets the security standard for any organization that touches criminal justice information, most directly law enforcement agencies, but also vendors and IT providers supporting them. CJIS requirements are specific and technical: advanced authentication, encryption standards, personnel security screening, and audit logging that goes further than what most general business compliance requires. Working within CJIS requirements means an IT environment has to be built to a standard that assumes scrutiny, not one that hopes to avoid it.
CMMC: the defense supply chain's answer to inconsistent security.
CMMC (Cybersecurity Maturity Model Certification) exists because the defense supply chain learned, repeatedly, that contractual promises about security weren't being verified. It applies to businesses that handle Controlled Unclassified Information as part of Department of Defense contracts, directly or as a subcontractor.
CMMC doesn't have its own separate criminal penalty structure. The real exposure comes from the False Claims Act, the same law originally written to catch Civil War-era defense fraud, which the Department of Justice now applies directly to false cybersecurity claims. If a contractor certifies compliance it hasn't actually implemented, that certification can be treated as a false claim to the federal government, triggering treble damages (three times the government's loss) plus per-claim penalties, with no requirement to prove intent to deceive. Reckless disregard or willful ignorance of the truth is enough. Recent settlements have run into the millions of dollars: one defense contractor paid $4.6 million after submitting an inflated cybersecurity self-assessment score, another paid $8.4 million for certifying compliance it hadn't fully implemented, neither case involved an actual data breach. The penalty was for the inaccuracy of the claim itself.
Criminal exposure exists too, though it arrives through fraud statutes rather than CMMC directly: the Department of Justice has brought wire fraud and obstruction charges against individuals over cybersecurity misrepresentation on government contracts, carrying potential decades-long prison exposure in the most serious cases. The executive who signs a compliance attestation is personally accountable for it, and not knowing has not held up as a defense when that executive should have known.
What these three frameworks actually have in common.
Despite covering different industries, HIPAA, CJIS, and CMMC share a structure: they require specific technical controls, they require documentation that those controls exist and are followed, and they increasingly expect evidence over self-reported assurance. That overlap matters practically. A business that has built real governance, documented policies, risk assessments, audit-ready evidence, isn't starting from zero when a second framework applies. The underlying work transfers. See Governance, Risk & Compliance.
The risk of treating compliance as a one-time project.
The businesses that get caught off guard are usually the ones that treated their last compliance push as a finished project rather than an ongoing standard. Frameworks get updated. Environments change. A control that was accurate eighteen months ago may not reflect what's actually configured today. Compliance that isn't maintained on a schedule eventually becomes inaccurate, and an inaccurate compliance posture is often worse than an acknowledged gap, because it looks like a misrepresentation rather than an oversight. The same evidence gap shows up in cyber insurance readiness.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
IT for Healthcare
How HIPAA's technical requirements get implemented day to day.
Read more: IT for HealthcareGovernance, Risk & Compliance
The documentation and evidence layer all three frameworks require.
Read more: Governance, Risk & ComplianceCyber Insurance Readiness
Where compliance evidence and insurance requirements overlap directly.
Read more: Cyber Insurance ReadinessNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
