A CMMC patient portal requires NIST SP 800-171 controls if it holds Controlled Unclassified Information from a DoD contract. Verify your portal scope before the next bid.
This guide explains how healthcare and defense contractors handle the intersection of patient data systems and CMMC requirements. It covers the specific regulatory triggers, the assessment process, and the practical steps to secure a portal that handles both clinical data and defense information.
Key Takeaways
- CMMC applies to patient portals only if they store or process Controlled Unclassified Information (CUI) for a DoD contract.
- Level Two compliance requires implementing all 110 controls from NIST SP 800-171 Revision 2.
- Only a C3PAO can issue a CMMC Level Two certificate; Registered Provider Organizations cannot perform the final assessment.
- Enclaving CUI in a dedicated boundary, such as a GCC High tenant, reduces the scope of required controls.
- The DoD CIO suspended the Phase II deadline in July 2026, but Phase I self-assessments remain in force.
Understanding the CMMC Patient Portal Intersection
Searchers asking about a CMMC patient portal are often healthcare providers or defense contractors who operate clinical information systems. The confusion stems from the fact that HIPAA and CMMC are distinct regulatory frameworks. HIPAA protects electronic protected health information (ePHI). CMMC protects Controlled Unclassified Information (CUI) in non-federal systems. A patient portal becomes subject to CMMC only when it handles CUI. This usually happens when a healthcare entity contracts with the Department of Defense to provide services that generate or receive defense information.
If your portal handles only standard patient data for civilian care, CMMC does not apply. However, if you hold a DoD contract and your portal stores data that meets the definition of CUI under 32 CFR Part 2002, you must comply with CMMC. The CMMC Program rule, 32 CFR Part 170, took effect on December 16, 2024. The acquisition rule, DFARS 252.204-7021, took effect on November 10, 2025. These rules create a mandatory certification path for contractors handling CUI.
When Does a Patient Portal Trigger CMMC?
The trigger is the presence of CUI. CUI is information that federal laws, regulations, or government-wide policies require agencies to protect. DoD Instruction 5200.48 implements the CUI program within the Department of Defense. For a patient portal to fall under CMMC, the data within it must be designated as CUI by the designating agency. This is not a self-determination. The contract must explicitly state that the system handles CUI. If the contract includes DFARS 252.204-7012, you are required to protect CUI using the 110 controls of NIST SP 800-171.
It is critical to distinguish between Federal Contract Information (FCI) and CUI. FCI is subject to Level One requirements, which include 15 basic safeguarding requirements from FAR 52.204-21. CUI is subject to Level Two requirements. Most patient portals that interact with DoD contracts will likely handle CUI if they store technical data, procurement information, or other sensitive defense data alongside patient records. You must map your data flows to determine if CUI is present.
Level Two Requirements for Secure Access
Level Two is the most common level for contractors handling CUI. It aligns directly with NIST SP 800-171 Revision 2. This standard contains 110 security requirements organized into 14 domains. These domains cover areas such as access control, audit and accountability, and system and communications protection. The goal is to protect the confidentiality of CUI in non-federal systems.
Core Control Domains
The 110 controls are not a checklist of specific technologies. They are outcome-based requirements. For example, the access control domain requires that you limit access to authorized users. The audit and accountability domain requires that you generate and protect audit records. The system and communications protection domain requires that you protect data in transit and at rest. NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. Strong but unvalidated encryption does not meet this requirement.
For a patient portal, this means you must ensure that the portal infrastructure meets these 110 controls if it is in scope for CUI. This includes the web servers, databases, and any cloud services that host the portal. If you use a cloud provider, that provider must meet a FedRAMP Moderate baseline or an equivalency. The DoD CIO FAQ clarifies that encrypted CUI is still CUI, and encrypted CUI in a cloud still needs FedRAMP Moderate or equivalency.
Assessment and Certification
Most Level Two programs require an assessment by a C3PAO (Certified CMMC Professional Assessment Organization). The C3PAO conducts the assessment and submits the results to eMASS. The certificate is then stored in the Supplier Performance Risk System (SPRS). Only a C3PAO can issue a CMMC Level Two certificate. An RPO, such as Petronella Technology Group, Inc., can prepare a contractor but cannot conduct the assessment or issue a certificate. This separation ensures independence in the certification process.
The list of authorized C3PAOs is maintained at cyberab.org/marketplace. As of the March 2026 Town Hall, there were 103 C3PAOs. Level Two certifications grew from 773 in January 2026 to 1,391 in May 2026. This growth indicates that the certification process is becoming more established. However, the DoD CIO announced on July 13, 2026, the suspension of the Phase II deadline. Phase I self-assessments remain in force, but later milestones are paused until further notice.
Scoping Your Patient Portal for Compliance
One of the biggest challenges for contractors is determining the scope of their CUI environment. If your entire enterprise network handles CUI, you must implement the 110 controls across the entire network. This is costly and complex. A more efficient approach is to enclave CUI into a narrowly scoped boundary. This could be a dedicated cloud landing zone or a GCC High tenant. By isolating CUI, you reduce the audit surface and lower ongoing costs.
Enclaving CUI in a Patient Portal
For a patient portal, enclaving might mean creating a separate instance of the portal that is used only for DoD contract work. This instance would be configured to meet all 110 NIST SP 800-171 controls. The rest of the portal, which handles civilian patient data, would not need to meet CMMC requirements. This approach requires clear technical boundaries and strict access controls to ensure that CUI does not leak into the non-CUI environment.
| Factor | Full Enterprise Scope | Enclaved Scope |
|---|---|---|
| Control Application | All 110 controls apply to entire network | 110 controls apply only to CUI boundary |
| Cost Impact | Higher due to broader remediation | Lower due to limited scope |
| Complexity | High, affects all systems | Moderate, focused on specific systems |
| Assessment Duration | Longer due to larger surface area | Shorter due to smaller surface area |
Enclaving is one of the biggest drivers of quote variance in CMMC readiness engagements. A typical CMMC Level Two readiness engagement runs 12 to 14 weeks for a mid-size contractor. This includes discovery, gap analysis, remediation, and a readiness handoff. The path from gap assessment to C3PAO-ready typically takes 6 to 18 months depending on your starting security posture and the complexity of your CUI environment.
Evaluating Your Current Security Posture
Before engaging a C3PAO, you must ensure that your patient portal is ready for assessment. This involves creating a System Security Plan (SSP) that covers all 110 NIST SP 800-171 controls. The SSP must identify the owners of each control and provide evidence pointers. You also need 14 control-family policies, an incident response plan, an acceptable use policy, and a media protection policy.
Incident Reporting Requirements
DFARS 252.204-7012 requires that cyber incidents affecting covered defense information be reported to DoD within 72 hours of discovery. This reporting is done through the DoD reporting portal at dibnet.dod.mil. To use this portal, you must obtain a DoD-approved medium assurance certificate in advance. After a reported incident, you must preserve images of affected systems and monitoring data for at least 90 days. You must also submit isolated malicious software to the government and hold cloud providers to a FedRAMP Moderate baseline.
Failure to meet these requirements can result in non-compliance with your contract. The DOJ Civil Cyber-Fraud Initiative has pursued settlements for false claims related to cybersecurity. Recent settlements include Verizon for $4.09M in 2023, Penn State for $1.25M in 2024, Raytheon for $8.4M in May 2025, and Georgia Tech for $875K in September 2025. These cases highlight the financial risk of non-compliance.
To evaluate your options, consider whether your current portal architecture supports the necessary controls. If not, you may need to invest in remediation. Petronella Technology Group, Inc. offers CMMC readiness consulting to help you navigate this process. Our team holds the CMMC Registered Practitioner credential and can guide you through the 110 controls. We do not perform Level Two assessments for clients we have prepared, due to Cyber AB independence rules. This ensures that our preparation work is unbiased and focused on getting you ready for a successful C3PAO assessment. For more information on how to secure your patient portal, visit our CMMC consultant services or review the CMMC compliance guide.
Step-by-Step Implementation Plan for a Compliant Patient Portal
Building a patient portal that satisfies both healthcare privacy standards and defense cybersecurity requirements requires a structured approach. You cannot simply layer controls on top of an existing system; you must define the boundary of your Controlled Unclassified Information (CUI) first. The following sequence aligns with the typical 12 to 14-week readiness engagement we see for mid-size contractors, though the path from gap assessment to C3PAO-ready can take 6 to 18 months depending on your starting security posture and the complexity of your CUI environment.
- Define the CUI Boundary. Identify exactly which patient data constitutes CUI under DoD contracts. Enclaving this data into a narrowly scoped boundary, such as a GCC High tenant or a dedicated cloud landing zone, is critical. This strategy keeps the 110 controls of NIST SP 800-171 from applying across your entire enterprise network, significantly reducing audit surface and ongoing cost.
- Conduct a Gap Analysis. Map your current controls against the 14 domains of NIST SP 800-171 Revision 2. This phase typically spans weeks 2 through 4 of a readiness engagement. You must identify which of the 110 practices are met, partially met, or not met. Remember that the SPRS self-assessment score ranges from minus 203 to 110, with controls carrying 1, 3, or 5 point weights.
- Remediate High-Priority Gaps. Execute a remediation sprint, usually weeks 5 through 12. Focus on technical controls that protect the confidentiality of CUI. NIST SP 800-171 requires FIPS-validated cryptography; strong but unvalidated encryption does not meet the requirement. If you use cloud services, ensure they hold a FedRAMP Moderate baseline or equivalency, as encrypted CUI in a cloud still needs this protection.
- Develop Documentation. Create a System Security Plan (SSP) covering all 110 controls with owners and evidence pointers. You also need 14 control-family policies, an incident response plan, an acceptable use policy, and a media protection policy. The SSP is a living document, not a one-time artifact.
- Perform a Mock Assessment. Use the Cyber AB CMMC Assessment Process (CAP) to conduct a mock assessment. This helps identify evidence gaps before the real assessor arrives. Only a C3PAO can issue a CMMC Level 2 certificate, so this step is about readiness, not certification.
- Prepare for the C3PAO Assessment. Select a C3PAO from the list maintained at cyberab.org/marketplace. The C3PAO will submit results to eMASS, and the certificate will be stored in SPRS. If any requirements are "not met," you must submit a Plan of Action and Milestones (POA&M) within the limits of 32 CFR 170.21, with a 180-day closeout period.
Common Mistakes in Patient Portal Assessments and How to Avoid Them
After reviewing numerous engagements, we see recurring errors that delay certification or lead to failed assessments. Avoiding these pitfalls can save months of remediation time.
- Over-Scoping the System. The most common mistake is applying CMMC controls to the entire enterprise network when only a specific patient portal handles CUI. If you do not enclave your CUI, you are responsible for 110 controls across every system that touches that data. By isolating the portal in a dedicated cloud landing zone, you limit the scope of the assessment and reduce the number of controls that must be fully implemented and evidenced.
- Ignoring the 72-Hour Incident Reporting Requirement. A cyber incident affecting covered defense information must be reported to DoD within 72 hours of discovery through the DoD reporting portal at dibnet.dod.mil. Many organizations fail to report because they do not have a DoD-approved medium assurance certificate obtained in advance. This certificate is required to access the portal. If you cannot report within 72 hours, you are non-compliant with DFARS 252.204-7012. Ensure your incident response plan includes a clear path to obtaining this certificate and a procedure for reporting.
- Using Unvalidated Cryptography. NIST SP 800-171 explicitly requires FIPS-validated cryptography to protect the confidentiality of CUI. Many patient portals use standard commercial encryption that is strong but not FIPS-validated. This is a direct "not met" finding. Verify that all encryption modules used to protect CUI are FIPS-validated.
- Failing to Flow Down Requirements to Subcontractors. DFARS 252.204-7012 must be flowed down to subcontractors when performance involves covered defense information. If your patient portal is built or hosted by a third party, that subcontractor must also comply. They must report their own incidents to DoD and provide the report number to you. Do not assume your vendor handles this; verify their compliance status and ensure the contract includes the necessary flow-down clauses.
- Treating the SSP as a Static Document. CMMC compliance is continuous. The SSP is a living document, and the POA&M is reviewed at least quarterly. If you update your portal, change your cloud provider, or modify your network architecture, you must update the SSP. A stale SSP will fail a C3PAO assessment because it does not reflect the current state of the system.
How to Choose a CMMC Readiness Provider for Your Patient Portal
Selecting the right partner is critical. You need a firm that understands both the technical requirements of NIST SP 800-171 and the specific nuances of patient data handling. Here are the questions to ask during your evaluation.
- Do you hold the CMMC Registered Practitioner credential? Every practitioner on the compliance team should hold the CMMC-RP designation. This ensures they have the specific training and knowledge required to guide you through the 110 controls. At Petronella Technology Group, Inc., every engineer assigned to a defense client holds this credential.
- Can you help us enclave our CUI? Ask if the provider has experience with GCC High tenants or dedicated cloud landing zones. Enclaving is one of the biggest drivers of quote variance and timeline reduction. A provider who can help you narrow the scope will save you significant time and cost.
- How do you handle the C3PAO independence rule? Only a C3PAO can issue a CMMC Level 2 certificate. A Registered Provider Organization (RPO) prepares a contractor but cannot conduct the assessment or issue a certificate. Ask if the firm is an RPO and if they have a process for handing off to an independent C3PAO. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization, RPO #1449, and does not perform Level 2 assessments for clients it has prepared, because Cyber AB independence rules prohibit it.
- What is your approach to incident response? Ask how they will help you prepare for the 72-hour reporting requirement. Do they assist in obtaining the DoD-approved medium assurance certificate? Do they rehearse the incident response process? A good provider will ensure you are ready to report an incident immediately upon discovery.
- Do you provide a fixed-scope quote? Ask if they can size a fixed-scope quote after a brief discovery conversation. A typical discovery conversation takes about 20 minutes and allows a provider to size a quote within two business days. This transparency helps you budget for the engagement.
How Petronella Technology Group, Inc. Helps
Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization, RPO #1449, specializing in CMMC readiness for regulated businesses and defense contractors. We understand the unique challenges of patient portals that handle CUI. Our team provides a structured approach to getting your portal compliant with NIST SP 800-171 Revision 2.
We begin with a free 30-minute scoping consultation run by a CMMC Registered Practitioner. This call helps us understand your current security posture and the scope of your CUI environment. From there, we can provide a fixed-scope quote for a readiness engagement. Our typical engagement runs 12 to 14 weeks for a mid-size contractor, including Discovery, Gap Analysis, Remediation Sprint, and C3PAO Readiness Handoff.
Every practitioner on our compliance team holds the CMMC-RP designation. Craig Petronella, our founder, holds CMMC-RP, CCNA, CWNE, NC Licensed Digital Forensic Examiner license #604180, and an MIT AI certificate, with 30+ years of experience. Our other engineers, Blake Rea, Justin Summers, and Jonathan Wood, also hold the CMMC-RP credential. This ensures that you are working with experts who have hands-on experience with the 110 controls and the assessment process.
We do not perform Level 2 assessments for clients we have prepared, as Cyber AB independence rules prohibit it. Instead, we prepare you for the assessment and provide a C3PAO shortlist with warm introductions. We also help you enclave your CUI to reduce audit surface and cost. Our services are delivered remote-first across all 50 states. For more information on our CMMC consulting services, visit our CMMC Consultant page.
Related guides from Petronella Technology Group, Inc.
Primary sources for this guide: 32 CFR Part 170 - CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM, SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems an.
Related reading
- CMMC Compliance: Gap Assessment, Levels 1 to 3
- CMMC Compliance Checklist 2026: Complete Requirements Guide
- CMMC Level 2 Requirements: The Complete 2026 Guide
- CMMC 2.0 Final Rule: What Contractors Must Do Now
- What Is CMMC: Complete Guide for Defense Contractors 2026
Frequently Asked Questions
Does a patient portal need to be CMMC Level 2 certified?
Yes, if the patient portal handles Controlled Unclassified Information (CUI) for a DoD contract, it must meet the requirements of NIST SP 800-171 Revision 2. This corresponds to CMMC Level 2. The portal must be assessed by a C3PAO, and the certificate must be stored in SPRS.
Can I use a commercial cloud provider for my patient portal?
Yes, but the cloud provider must hold a FedRAMP Moderate baseline or equivalency. Encrypted CUI in a cloud still needs this protection. If your provider does not have FedRAMP Moderate, you may need to use a different provider or implement additional controls to meet the requirement.
How long does it take to get a patient portal CMMC compliant?
A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. However, the path from gap assessment to C3PAO-ready can take 6 to 18 months depending on your starting security posture and the complexity of your CUI environment. Enclaving your CUI can shorten this timeline.
What is the difference between an RPO and a C3PAO?
An RPO, such as Petronella Technology Group, Inc., prepares a contractor for the CMMC assessment. A C3PAO conducts the assessment and issues the certificate. Only a C3PAO can issue a CMMC Level 2 certificate. An RPO cannot conduct the assessment or issue a certificate for a client it has prepared, due to independence rules.
Do I need to report every security incident to DoD?
You must report any cyber incident affecting covered defense information to DoD within 72 hours of discovery. This includes incidents on your patient portal if it handles CUI. You must use the DoD reporting portal at dibnet.dod.mil, which requires a DoD-approved medium assurance certificate obtained in advance.
How often do I need to be re-assessed?
CMMC Level 2 requires a triennial reassessment, meaning every three years. In between assessments, the SSP is a living document, and the POA&M is reviewed at least quarterly. You must maintain your controls and update your documentation as your system changes.
For a personalized assessment of your patient portal's CMMC readiness, call Penny, our AI assistant, at 919-348-4912, or use our contact form to schedule a free scoping consultation.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.