Insights

The HIPAA-to-CMMC Gap Most Military Health Contractors Don’t See

Written by James Reid | Aug 3, 2026, 11:00:00 AM

 

If your company supports military health programs, you’ve probably already invested seriously in HIPAA compliance. Your program was likely built over years, so you know the drill: annual risk assessments, business associate agreements, breach notification policies.

But now the CMMC 2.0 framework is showing up in many client defense contracts, and we noticed a definite trend. Many companies are feeling confident because of their extensive HIPAA compliance expertise. At first glance, HIPAA and CMMC 2.0 seem pretty similar given their focus on cybersecurity and risk. Companies may assume that since they already have a mature security program, they’re almost there when it comes to CMMC.

And, while that assumption seems reasonable, it’s actually far from the truth, and often the first thing that derails a CMMC readiness effort.

Two Frameworks, One Dangerous Assumption

Both HIPAA and CMMC share the foundational goal of protecting sensitive data. They both call for organizations to put strict privacy controls, incident response procedures, and staff training into action. Also, the same staff members are often involved in both efforts and the same systems may house the data from both frameworks.

But the differences is where a lot of defense contractors are getting tripped up.

Where HIPAA Stops and CMMC Begins

The most critical difference comes down to who they apply to and what data they are protecting:

HIPAA is for the Healthcare sector:
It regulates healthcare environments and it protects Protected Health Information (PHI), things like patient medical records, lab results, and billing history.

CMMC 2.0 is for the Defense sector: It regulates Department of Defense contractors and suppliers (the Defense Industrial Base), things like military blueprints, weapon schematics, and defense logistics.

Ultimately, HIPAA protects patient privacy, while CMMC protects national security.

HIPAA is more focused on administrative, physical, and technical safeguards while CMMC 2.0 extends to domains beyond healthcare: from configuration management to system protection, and from personnel security to supply chain risk management.1

To document controls, CMMC 2.0 maintains a formal System Security Plan (SSP) and manages Plans of Action and Milestones (POA&Ms) to capture unresolved gaps.

As if CMMC compliance wasn’t complex enough, years of delays and revisions created a lot of readiness gaps. So plenty of organizations pushed readiness efforts down on their priority lists, thinking they’ll wait until CMMC requirements start showing up in active contracts.2

The Hidden Work Behind CMMC 2.0 Readiness

The biggest surprises in a CMMC project usually involve classifying data correctly and proving compliance through documentation.

Data classification determines scope

The hardest part of CMMC compliance can be figuring out what data qualifies as CUI and where it lives. Under HIPAA, health data about a servicemember might be PHI. But if it relates to operational readiness, deployment suitability, or a classified research program, that same data might also be CUI under CMMC. And some data might be both.

Organizations spend weeks (or more) just trying to figure out which systems are in scope for CMMC, and which are only in scope for HIPAA. Even though the work is time-consuming and tedious, it can also be the most important thing an organization does before starting remediation.

HIPAA documentation doesn’t automatically transfer

The documentation standards between CMMC and HIPAA may seem similar but, in practice, they are far from it. Here’s just a few examples:

 

  • HIPAA’s risk assessment doesn’t meet the CMMC gap analysis requirement.
  • A HIPAA Security Officer designation doesn’t automatically translate into a CMMC-compliant access control program.
  • An incident response plan written for a healthcare context will need to be reviewed and likely revised to meet the evidentiary standards a C3PAO assessor will apply.
  • Data classification and scoping across clinical and defense environments.
  • NIST SP 800-171 gap analysis ag against existing HIPAA controls.
  • SSP and POA&M development built to C3PAO evidentiary standards.
  • SPRS baseline scoring and remediation planning.
  • Prioritized roadmaps for organizations managing multiple compliance frameworks.

 

Companies are finding that assessors are quickly finding gaps when one program's documentation is applied to the other’s requirements.

Gaining the Health Defense Edge with NexusTek

Because military health contracting is such a specialized market, there’s a limited number of organizations that can support Defense Health Agency programs, military medical research, and VA-adjacent defense contracts. Once CMMC becomes commonplace in contracts, those who can show both HIPAA compliance and CMMC 2.0 readiness will have a clear advantage over those who can only check one box.

NexusTek helps organizations working where healthcare and defense requirements intersect. Since we’re not a Certified Third-Party Assessment Organization (C3PAO), we don’t perform certification assessments. But we help organizations prepare for them to spot any gaps, plan remediation, and build the documentation they need to support compliance. Our process includes:

If CMMC requirements are starting to appear in your military health contracts, now is the time to understand where you stand.

Contact NexusTek for a CMMC 2.0 Readiness Assessment and build a plan before certification becomes a contract requirements https://www.nexustek.com/cmmc-2-0-compliance-services

Sources:

1. Department of Defense, Cybersecurity Maturity Model Certification (CMMC) Model Overview 2.0, accessed June 2026

2. DefenseScoop, Pentagon begins enforcing CMMC compliance, but readiness gaps remain, November 2025