Compliance conversations spiral fast. A business owner asks "do we need to worry about this?" and within five minutes someone's talking about frameworks and acronyms that don't apply to them at all. If you're running a small or mid-sized organization in Columbus, Cleveland, or anywhere else in Ohio, three regimes come up constantly — CMMC, HIPAA, and Ohio's own data breach statute — and almost nobody explains which ones actually apply to a given business or what it costs to get into shape for the one that does.
Here's the direct answer: CMMC only applies if you hold a Department of War contract or subcontract touching Controlled Unclassified Information or Federal Contract Information; HIPAA only applies if you create, receive, or transmit protected health information as a covered entity or business associate; and Ohio's breach notification law applies to every business in the state regardless of industry, the moment you hold Ohio residents' personal information. Most SMBs are in scope for one of these, not all three, and the sequence you tackle them in matters as much as the substance.
CMMC applies to companies in the Department of War supply chain: contractors and subcontractors who handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). The practical test: check contracts for DFARS clause 252.204-7012. If it's present, CMMC obligations exist whether or not you've started planning. If not, and no CUI or FCI flows through your systems, CMMC is not your problem this year.
The timeline here has moved, and this is the kind of detail that goes stale fast. On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, which had been scheduled to take effect November 10, 2026, and stood up a CMMC Reform Task Force to conduct a 60-day review (Department of War CIO, CMMC program page). That November 2026 deadline is suspended and should not be treated as an active target. What has not changed: Phase I self-assessment requirements remain firmly in place, NIST SP 800-171 Revision 2 continues to be enforced through self-assessment during the review period, and the contractual obligation to protect CUI under DFARS 252.204-7012 was never suspended (Department of War CIO, CMMC program page). We covered the mechanics of that suspension in our breakdown of what defense contractors still need to do; this article's job is narrower — deciding whether CMMC applies to you at all.
If you are in scope, the practical move during the pause is to close gaps and build evidence, not wait it out. The Task Force's report is expected roughly 60 days from the July announcement, and officials haven't ruled out scaling the program back further or reinstating a revised third-party requirement. Betting on a specific outcome is worse than doing the NIST SP 800-171 work now, since it's required either way. If you're a manufacturer working out where CMMC sits in your roadmap, our CMMC compliance explainer for manufacturers goes deeper on scoping CUI boundaries.
HIPAA applies to any organization that creates, receives, maintains, or transmits protected health information (PHI): covered entities like medical practices and insurers, and business associates — IT vendors, billing companies, benefits administrators, any platform touching employee health data on a covered entity's behalf. If your business fits neither description, HIPAA doesn't reach you, no matter how sensitive the data you otherwise handle.
For organizations in scope, the Security Rule requires administrative, physical, and technical safeguards for electronic PHI, codified at 45 CFR Part 160 and Subparts A and C of Part 164 (HHS Office for Civil Rights, Security Rule guidance). A documented risk assessment is the most commonly missing evidence we see — not from negligence, but because nobody has repeated it in years. It's a standing requirement, not a one-time item from 2019 you can call current.
There's also a timeline detail worth being precise about, since it has shifted twice in the past year. HHS proposed a significant overhaul of the Security Rule in a Notice of Proposed Rulemaking published in the Federal Register in January 2025. That proposal was never in effect — nothing has been finalized, so nothing has been rolled back. HHS's agenda had targeted a final rule for May 2026, but the agency has since moved the rulemaking to its long-term actions list, with a current projected final-action date of July 2027 (HHS Office for Civil Rights, Security Rule guidance). That date is HHS's own planning estimate, not a statutory deadline, and it has already slipped once, so treat it as a signal rather than something to schedule against. What that delay does not change is the existing Security Rule, which remains fully enforceable today exactly as it has been for years. We covered the delay itself in our piece on why healthcare organizations should not wait; the point here is narrower: don't let an uncertain future rule excuse deferring work the current rule already requires.
One HIPAA scope question we get constantly from Ohio SMBs that don't think of themselves as healthcare companies: if your billing vendor, IT provider, or benefits platform touches PHI on your behalf, you likely need a signed Business Associate Agreement with them, and a breach on their end is still your compliance exposure. We walked through that scenario in our article on why a billing vendor's breach becomes your HIPAA problem.
Separate from any federal framework, and applying to essentially every Ohio business regardless of industry, Ohio Revised Code §1349.19 requires that any person who owns or licenses computerized data including personal information disclose a breach of the security of the system to affected Ohio residents once discovered, if the unauthorized access "causes or reasonably is believed will cause a material risk of identity theft or other fraud" (Ohio Revised Code §1349.19). The statute is precise on timing: disclosure must happen "in the most expedient time possible but not later than forty-five days following its discovery," subject to legitimate law enforcement delay (Ohio Revised Code §1349.19). Notice can be written, electronic, by phone, or substitute notice under conditions tied to cost or population size. This obligation exists regardless of industry — if you hold Ohio residents' Social Security numbers, driver's license numbers, or financial account numbers with access codes, this statute reaches you.
Ohio also offers something few other states do: a legal safe harbor, not a mandate. Ohio Revised Code Chapter 1354, the Ohio Data Protection Act, gives a covered entity an affirmative defense — not blanket immunity — against tort claims alleging that a failure to implement reasonable security controls caused a data breach, provided the business creates, maintains, and actually complies with a written cybersecurity program that "reasonably conforms to an industry recognized cybersecurity framework" (Ohio Revised Code Chapter 1354, §1354.02). The statute is explicit this is a tort-litigation defense, not a shield against contract claims, and it creates no private right of action of its own. Safe Harbor doesn't mean you can't be sued or investigated; it means that if you are sued, and you can show a real, maintained program, you have a defense to raise.
The recognized frameworks are enumerated by statute. Under ORC §1354.03, reasonable conformance to the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/800-53A, FedRAMP, the CIS Critical Security Controls, or ISO/IEC 27000 qualifies, as does — for regulated entities — conformance to the HIPAA Security Rule, Gramm-Leach-Bliley Title V, FISMA, or HITECH, or PCI DSS paired with one of the frameworks above (Ohio Revised Code §1354.03). That's what makes Safe Harbor useful for sequencing: a healthcare SMB already doing real HIPAA Security Rule work, or a manufacturer building NIST SP 800-171 for CMMC readiness, is simultaneously building the evidence Ohio rewards. One solid program can satisfy two obligations at once.
| Regime | Who it actually applies to | What you must be able to produce |
|---|---|---|
| CMMC | Department of War contractors/subcontractors with DFARS 252.204-7012 in their contracts, handling CUI or FCI | A current NIST SP 800-171 Rev 2 self-assessment, SPRS score, and documented remediation plan |
| HIPAA | Covered entities and business associates that create, receive, or transmit PHI | A risk assessment from the last 12 months, a Security Rule safeguards inventory, and signed BAAs with vendors touching PHI |
| Ohio ORC §1349.19 / §1354 | Every business holding Ohio residents' personal information | A breach response plan meeting the 45-day trigger, plus — for Safe Harbor — a written program conforming to a recognized framework |
Start by ruling things out, not in. Most SMBs think they need to worry about all three because the acronyms show up together in vendor marketing. In practice, scoping takes an afternoon: pull your contracts for DFARS clauses to settle CMMC, identify whether PHI flows through your systems to settle HIPAA, and assume the Ohio breach statute applies by default, because it almost always does.
Once scope is clear, the sequence that makes financial sense is usually the reverse of how people prioritize by fear. Ohio's breach notification obligation is cheapest to prepare for and needed by every business, so it comes first: a documented incident response plan that hits the 45-day trigger, with clear ownership of the notification decision. If you're regulated under HIPAA, the risk assessment and safeguards documentation is next, since it doubles as evidence for Ohio Safe Harbor conformance under ORC §1354.03. CMMC, where it applies, is usually the most expensive and slowest to build because of CUI boundary work and the assessment ecosystem around it — but building against NIST SP 800-171 now means you're not starting from zero once the Task Force's recommendations land. The cost curve is real: a basic incident response plan is a modest project; a full HIPAA risk assessment and remediation program is a mid five-figure undertaking for most SMBs; CMMC Level 2 readiness runs well into six figures once boundary work, documentation, and assessment fees are counted.
The throughline Ric sees across budgeting conversations with SMB owners is that businesses treat these as one undifferentiated compliance burden and either overspend covering all three or underspend because the acronyms feel interchangeable and equally optional. They're neither. Scope first, then sequence by what's mandatory versus what's protective, then let the evidence you build for one regime do double duty wherever the statutes allow it — which, thanks to ORC §1354.03, is more often than most SMBs realize. Our overview of cybersecurity and compliance for SMBs in 2026 is a useful companion on budgeting for this, and if you're deciding whether you need a fractional compliance advisor or a managed provider to carry it, our comparison of MSP, MSSP, and vCISO models lays out how those roles differ.
One scoping question that trips up Ohio SMBs more than the three regimes above is what happens when AI tools start touching PHI or CUI without anyone formally deciding they should. A billing assistant or copilot tool summarizing patient records doesn't stop being a HIPAA question because it's AI-powered, and the guardrails needed look like the Security Rule safeguards you're already supposed to have. Our AI Lab piece on AI in healthcare and HIPAA risk goes deeper on that exposure, and if you're working out whether a given AI question is a security, governance, or compliance problem, our breakdown of the differences between the three is the companion piece to read next.
None of this is static. CMMC's Reform Task Force report, HHS's next agenda update, and any future amendment to Ohio's statute could move these specifics within a year. The scoping questions — DFARS-clause contract, PHI, Ohio residents' personal information — stay the right starting point regardless of how the deadlines shift.
The fastest way to waste money on compliance is treating CMMC, HIPAA, and Ohio's breach law as one undifferentiated obligation instead of scoping which ones apply to your business and sequencing the evidence accordingly.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.