Deliverable 07 - Three-Year Strategic Plan

profilesoniam
EBSCO-FullText-12_14_20255.pdf

Unfortunately, for many, the prob-

lem isn’t an unwillingness to prioritize

cybersecurity solutions and practices, it’s

an inability to do so financially without

draining resources from other mission-

critical areas. The result is often the bare

minimum required for HIPAA compli-

ance, a choice that leaves the organiza-

tion vulnerable.

“Health care security cannot be run as a

compliance checkbox. Attackers are using

automated reconnaissance, ransomware

payloads, and supply chain pivots to target

hospitals and clinics because they know

the gaps are real and persistent. The only

path forward is to run continuous adver-

sarial testing, treat offensive tradecraft as a

must-have capability, and build a security

culture that matches the stakes: Lives, not

just data, are on the line,” says Nic Adams,

cofounder and CEO of 0RCUS. “Leadership

must stop delegating cyber risk to paper-

work and start treating it as an existential

business threat. Anything less is just wait-

ing for the next breach headline.”

Beyond the Bare Minimum Even provider organizations that are

compliant with current HIPAA security

mandates fall short in achieving the

necessary protection in today’s evolving

threat environment. To change that,

OCR proposed an extensive overhaul

of the existing regulation with the

“HIPAA Security Rule To Strengthen the

Cybersecurity of Electronic Protected

Health Information” proposed rule,

published to the Federal Register in

January 2025, but not expected to be

finalized until 2026.1,2

“Far too many regulated entities

do not view cybersecurity as a neces-

sary component of their operations that

allows them to fulfill their health care

missions. Anecdotal evidence suggests

that senior management often lacks

awareness of cybersecurity, including

both threats and methods for protecting

against such threats,” OCR wrote.

A dvanced cybersecurity tools and

protocols—many of which will be

codified when the Office for Civil

Rights (OCR) finalizes its overhaul

of the HIPAA Security Rule—

have been relegated to the budgetary wish list by many

hospitals and health systems. However, as threat levels

rise, the chorus of voices warning providers to make

enhanced cybersecurity a budget priority grows louder.

Strategi Initiative

By Elizabeth S. Goar

14�FOR THE RECORD • AUTUMN 202514�FOR THE RECORD • AUTUMN 2025

c e

Calculating the Risk-Reward Equation for Health Care Cybersecurity

Layna Cook Rush, CIPP/US, CIPP/C,

a shareholder with Baker Donelson who

heads up the law firm’s Data Incident

Response Team, concurs with OCR’s sen-

timents. Meeting the minimum require-

ments is unlikely to provide adequate

protection in today’s threat landscape. “Not

investing in an up-to-date cybersecurity

program opens an organization up to an

attack, which can lead to significant finan-

cial costs, including ransomware payments,

regulatory fines, lost profits during down-

time, and class action lawsuits,” she says.

Adams calls regulatory minimums a

“false floor,” adding that “doing the bare

minimum means attackers have a free

map to your environment, and regulators

have a trigger for postbreach penalties.”

According to Asdrúbal Pichardo, CEO

of Squalify, security and compliance are

not interchangeable. “Meeting the bare

minimum may check a box, but it won’t

stop a breach or the financial and opera-

tional chaos that follows. Organizations

hit with multimillion-dollar ransom

demands often discover too late that their

backups are insufficient and insurance

coverage limited,” he says, adding that

when postbreach lawsuits roll in and con-

trols are found to be substandard, “liabil-

ity becomes much harder to defend. Doing

the minimum might satisfy auditors, but

it won’t satisfy plaintiffs or your board.”

Baby Steps for Hardening Security There is no question that pro- vider organizations are fall- ing short on cybersecurity, including failing at proactive threat emulation, live adver- sary simulation, and real-time breach-path analysis,” says Nic Adams, cofounder and CEO of 0RCUS.

“Most rely on checklist compliance, HIPAA audits, policy templates, annual train- ings, basic [endpoint detection and response] deployments, or vulnerability scans, none of which simulate how real attackers breach medical infrastructure,” he says. “Secu- rity needs to stop being man- aged as another paperwork exercise, as it’s quintessential war gaming. Asset inventory is incomplete, segmentation is weak, and critical trust assumptions go untested. Vendors push point solutions, while attackers move through open lateral paths and mis- configured APIs [application programming interfaces]. The gap: zero offensive tradecraft and little real adversary per- spective. The industry still thinks in defense, not offense.”

While it sounds impossible, stronger protection can be achieved without breaking the bank. Adams advises providers to stop buying shelfware and instead focus on the following:

• enforcing least-privilege across all accounts, service roles, and medical device logins;

• mapping critical data flows and locking down exposed APIs, remote access, and file shares;

• rolling out phishing-resis- tant multifactor authen- tication (MFA), not just text codes or security questions;

• conducting basic breach- path tabletop exercises monthly, not annually;

• patching public facing assets and removing orphaned accounts; and

• hardening backups with offline storage and regular restoration drills.

Squalify CEO Asdrúbal Pichardo says immediate steps start with visibility in areas of vulnerability. Noting that you can’t protect what you don’t understand, he suggests ensuring that the organiza- tion’s risk assessment is current is “a lightweight but high-value step” to highlight strengths and weaknesses so the most serious risks can be addressed.

“The proposed updates to the HIPAA Security Rule included conducting annual risk assessments, rather than as needed, which is a good practice to ensure a periodic

situation report of cybersecu- rity, regardless of whether it ends up in the final updates. It costs next to nothing but quickly reveals policy gaps, access control weaknesses, and vendor or business associ- ate blind spots,” he says. “From there, focus on controls that reduce likelihood and impact of your biggest risks: tighten user provisioning, implement MFA on privileged accounts, and ensure backups are segmented and regularly tested.

“These steps don’t require massive capital outlays— though costs will vary with the size and complexity of the organization—but they dra- matically improve your cyber readiness,” Pichardo adds.

John Trest, chief learn- ing officer of VIPRE Security Group, says there are several budget-friendly actions pro- vider organizations can take right away to boost their secu- rity profile, including enforcing strong password policies and adding MFA for all accounts, especially those with access to patient data and administra- tive systems. Training employ- ees regularly on phishing, social engineering, secure handling of sensitive data, and perti- nent threat vectors is also pru- dent “as human error remains the top cause of breaches. To beat the forgetting curve, it’s

important to reinforce key les- sons with microlearning videos, posters, and ongoing discus- sions so that security as a whole stays top of mind,” he says.

Other recommendations include the following:

• keeping software, operat- ing systems, and medical devices updated with the latest security patches;

• auditing and limiting access controls by only giving employees the mini- mum access necessary based on their roles; and

• monitoring network activ- ity to quickly detect suspi- cious behavior. There are many low-cost monitoring tools that can add an extra layer of protection.

“These relatively inexpen- sive steps can help prevent the chaos, expense, and repu- tational fallout that follow a breach,” Trest says, emphasiz- ing that any steps are better than none in the current high- risk threat landscape. “Health care data is among the most valuable on the dark web,” Trest says. “Doing the bare minimum leaves organiza- tions wide open to a range of attacks and consequences. In short, minimal effort invites maximum risk.”

— ESG

16�FOR THE RECORD • AUTUMN 2025

Chris Cronin, a principal consultant

and partner with Halock Security Labs,

who invented the Duty of Care Risk Analy-

sis standard and is the primary author

of the Center for Internet Security Risk

Assessment Method, says what many

in the security business miss is that the

HIPAA Security Rule, as it’s written, is not

about prescriptive guidance: It’s about

taking reasonable action to prevent the

opportunity for harm.

Health and Human Services (HHS)

wants providers to demonstrate that they

considered protecting patients’ privacy

and data as they developed their cyberse-

curity strategies, Cronin says. That is why

the decision by OCR to avoid being overly

prescriptive in the original security rule

was a double-edged sword. OCR doesn’t

dictate exactly which controls to use,

which can be frustrating for some regu-

lated entities. However, it also means those

entities can justify which controls they use

based on the risk and the costs to reduce it.

Provider organizations “can’t read

the tea leaves to understand what HHS

wants,” he says. As a result, they tend to

rely on maturity assessments or audits to

identify specific compliance gaps, then

raid clinical and operational budgets for

technology solutions to close them.

They strive for compliance “without

actually addressing the reasonableness

question of HIPAA,” Cronin says. “Every

organization, including hospitals and

other clinical providers, is supposed to

be a balanced environment. Achieve your

mission, protect others you might harm,

and don’t spend more than the risk to

accomplish both.

“But if money in [the clinical] budget

gets shifted to the cybersecurity budget,

that better not reduce patient care,” he

continues. “That would not be reasonable

if patients suffered unnecessarily to afford

a ransomware safeguard that an audit

said was needed. The clinical environ-

ments aren’t being well served with these

maturity assessments and audits.”

In other cases, cybersecurity is ignored

due to budget limitations, which is also the

wrong approach because, when the inevi-

table breach or ransomware attack occurs

and OCR comes calling, saying there was

no money for a risk analysis will not fly.

“You need to show [regulators] that

what you did was reasonable, that it was a

balance between your budget and patient

care,” Cronin says. “You can’t just say,

‘We won’t do this because we don’t have

the budget.’ You have to do what you can

to reduce the risk to the patient and still

function as a hospital.”

Setting Standards There are numerous examples of provider

organizations falling short in their cyber-

security efforts and incurring financial

and reputational losses. However, the

most effective justification for changing

perceptions around cybersecurity invest-

ments can be found in a cybersecurity

unicorn: a health system that has never

experienced a breach.

“Knock wood,” says Kevin Torres, chief

information security officer (CISO) of

MemorialCare, a nonprofit health system

that includes four hospitals, two medical

groups, imaging centers, and surgical cen-

ters providing care to patients in Orange

County and Los Angeles County, Califor-

nia. The system’s success is a byproduct of

the system’s focus on creating a culture of

cybersecurity awareness that runs from

the top down.

“You need to spend an equal amount of

time on cultivating the culture as you do

with the implementation of tools to pro-

tect you, and it all starts with your employ-

ees. They are the main threat vector that is

being compromised,” Torres says.

Along with educational articles, man-

agement presentations, and monthly

governance, Torres and his team col-

laborated with MemorialCare’s market-

ing department to create a tip corner and

craft messages published in the monthly

CEO report to all employees. Initiatives

supporting that culture are as crucial to

his role as implementing safeguards and

conducting penetration testing.

“The more equipped your employees

are, and the more educated they are on

what to look for, the better off we are,” Tor-

res says. “We have built training programs

that are mandatory, like what to look for

in a phishing attempt. We test them at the

end, and they have to pass that test. Then

we hold them accountable … It’s not that

we want to penalize them. We want to

educate them. We want to work together

with them.”

Which is not to say that MemorialCare

doesn’t place a priority on investing in

state-of-the-art security tools. They do.

For example, the health system is imple-

menting an identity management system

from Clear, which rose to prominence

during the pandemic and continues to

partner with TSA at airports nationwide.

“Even with all the tools, you still have

a constant barrage of social engineering

[attacks] … We’re going to spend a lot of

time on access and the social engineer-

ing piece because we think that’s our big-

gest potential vulnerability,” Torres says,

adding that MemorialCare also utilizes

behavioral analytics and AI to detect

social engineering attempts earlier.

Torres recognizes that MemorialCare’s

views on cybersecurity are not the norm

and is careful not to take advantage by

overspending on tools that aren’t the right

fit. For those IT leaders who are as lucky,

he recommends benchmarking against

peers as much as possible to demonstrate

when spending is below average and put-

ting data at risk.

“The board at MemorialCare has

adopted a very strong and supportive

stance on cybersecurity. They don’t see

it as a technical problem. They see it as

an enterprise risk management issue,”

he says. “This is not a technical issue or a

cybersecurity issue to solve. It’s an orga-

nizational issue, and everybody has to get

behind that, from the CEO to the board

and all the way down.”

Making the Business Case MemorialCare’s perspective is something

CIOs and CISOs can emphasize when

seeking support for improving secu-

rity profiles. Rush suggests capturing

the attention of the C-suite by framing a

cybersecurity incident as a business risk,

rather than a technical concern.

“In addition to regulatory exposure,

there is the expense of operational down-

time, potential reputation damage,

and class action lawsuits. The costs of

a cybersecurity breach can easily out-

weigh the cost of instituting a strong

cybersecurity program. Having a strong

cybersecurity program is good for the

bottom line,” she says, noting that IBM in

its 2024 Cost of a Data Breach Report put

the price tag of the average health care

breach at nearly $9.8 million—the high-

est of any industry.3

“By contrast, by investing even a frac-

tion of that cost in its cybersecurity

program, an organization can establish

layered defenses, threat monitoring, and

response capabilities that will protect

against cyber incidents and reduce the

impact if one does occur,” Rush says.

AUTUMN 2025 • WWW.FORTHERECORDMAG.COM�17

Pichardo shares that leading with finan-

cial exposure is more effective than relying

on technical jargon when making the busi-

ness case around cybersecurity enhance-

ment. “C-suites and boards don’t need a

list of software vulnerabilities, they need to

understand potential revenue loss, regula-

tory fines and lawsuits, or patient churn

tied to a breach. Frame the conversation

in terms of risk-adjusted ROI [return on

investment]: how a targeted investment in

cybersecurity today can prevent multimil-

lion-dollar losses tomorrow,” he says. “The

question isn’t whether a breach could hap-

pen. It’s what it would cost the business if it

did, and whether you’re comfortable with

that risk sitting on the balance sheet.”

Making the business case for cyber-

security investments can be challenging

because “it can be difficult to provide an

economic analysis to a damaging event

with uncertain probability,” says George C.

Pappas, CDH-E, CEO of Intraprise Health,

by Health Catalyst. He recommends start-

ing with a validated security risk assess-

ment conducted by a third party. This will

construct a clear picture of the organiza-

tion’s security posture and provide a list of

its important security needs.

This analysis “can provide a roadmap

of fixes and their priority that you can

work on over time,” he says. “Next, com-

pare your own posture to similarly situ-

ated organizations. If the organization

has large gaps, there is a stronger argu-

ment for urgent/important needs to be

addressed. Lastly, examine the cost and

patient harm of cyberattacks on organiza-

tions of similar size and scale.”

John Trest, chief learning officer with

VIPRE Security Group, recommends com-

paring the cost of a security event with

that of proactive security investments,

from training to endpoint protection.

These “are usually a fraction of that cost

and are spread out over time,” while the

tangible and intangible costs of a cyberat-

tack “can take years, or even decades, to

rebuild.” Thus, he says, “while CEOs tend

to focus more on risk and ROI, it’s up to

IT leadership to clearly explain what’s at

stake and why stronger security matters.”

To that end, Trest recommends estab-

lishing a business case that communi-

cates the following:

• Financial risks: Highlight the poten-

tial fines for HIPAA noncompliance,

costs of breach remediation, patient

notification expenses, lawsuits, and

reputational damage.

• Operational disruption: A ransomware

attack can halt patient care, divert

employee time, and damage trust.

• Competitive advantage: Strong security

measures protect the organization’s

reputation and can be a market dif-

ferentiator for patients and partners.

Framing security as a patient safety

issue often resonates the most with

health care executives.

Adams suggests mapping every

investment directly to risk avoidance

and bottom-line preservation, as well as

quantifying the potential cost of down-

time, lost revenue, and regulatory pen-

alties. When possible, utilize real-world

breach case studies from similar organi-

zations and translate technical controls

into business impact, tying patient safety,

continuity of care, and brand reputation

to specific security gaps. Additional steps

include the following:

• show how adversarial simulation

closes existential exposure;

• frame cybersecurity expenditures as

business resilience, not IT overhead;

and

• demonstrate that regulatory fines and

breach losses exceed the incremental

cost of proactive security.

“Advanced security investments in

offensive simulation, robust segmenta-

tion, hardened backups, and continuous

red-teaming typically cost a fraction of a

single breach event,” Adams says. “Leader-

ship must recognize the asymmetry: One

breach can wipe out years of profit, while

security spend is predictable, measurable,

and reduces existential risk.”

Cyber Insurance One aspect of cybersecurity that is often

underappreciated, despite its growing

influence in decisions regarding appro-

priate protection, is insurance. In the

current risk environment, appropriate

coverage has become a significant and

essential line item, and premiums are ris-

ing with the stakes.

Ryan Griffin, who heads the US cyber-

insurance division of McGill and Part-

ners, notes that cyber coverage is a young

market, having only gained prominence

over the past 20 years. However, the rapid

advancement of both technology and the

capabilities of bad actors has accelerated

the maturation of coverage. The challenge

for insurers is that, unlike coverage for a

physical asset, cyber insurance is primar-

ily based on good faith.

“They’re taking the client’s word that

the [environment] is secure. It’s hard to

attest that you’ve implemented a [par-

ticular] security control throughout the

environment,” he says. “You may have

implemented it 95% of the way, but the

threat actors are really good at exploit-

ing the areas where you haven’t. Just from

a risk management standpoint, for CIOs

and their security officers, that is an abso-

lute nightmare challenge.”

Cyber insurers have also assumed a

dual role as protector and trusted advisor.

As such, they not only hold their beneficia-

ries accountable for meeting best practices

and providing appropriate protection but

also act as expert resources for accelerat-

ing recovery in terms of identifying where

and how the breach happened, the extent

of the damage, and all the required steps

that must be taken postbreach in terms

of reporting and notifications. They also

continuously scan the threat environment

and alert clients early to emerging threats,

as well as tracking data on everything from

trends in ransomware payments to threat

actors and breach mechanisms.

“The number one role the insurance

companies play is helping on the resil-

iency side when you do experience an

event,” Griffin says. “It’s basically ‘in case

of emergency, break glass’ [and] we’ll air-

drop a team of lawyers and cybersecurity

professionals to help you recover in those

first 72 hours.”

Insurance also protects against fines

and other penalties that regulators assess

following incidents, “which is a rarity in

the insurance world,” Griffin says. “Com-

pliance is in the eye of the beholder at

times, and usually, health systems are the

victim of an attacker. Sometimes we forget

that … It isn’t malicious noncompliance.

They were doing their best and thought

they were meeting the standards but were

still exploited.” �

Elizabeth S. Goar is a freelance health care writer in Wisconsin.

For references, view this article on our website at www.ForTheRecordmag.com.

18�FOR THE RECORD • AUTUMN 2025

Copyright of For the Record (Great Valley Publishing Company, Inc.) is the property of Great Valley Publishing Company, Inc. and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.