While I'm not a fan of checkbox security. Given that major parts of the healthcare industry don't even seem to get over that bar, maybe it's time to put something in place to give network defenders a lever to pull on to get the basics sorted.
Not having MFA and encryption for data at rest should be treated as willful negligence when a company is breached.