Deliverable 07 - Three-Year Strategic Plan
Unfortunately, for many, the prob-
lem isn’t an unwillingness to prioritize
cybersecurity solutions and practices, it’s
an inability to do so financially without
draining resources from other mission-
critical areas. The result is often the bare
minimum required for HIPAA compli-
ance, a choice that leaves the organiza-
tion vulnerable.
“Health care security cannot be run as a
compliance checkbox. Attackers are using
automated reconnaissance, ransomware
payloads, and supply chain pivots to target
hospitals and clinics because they know
the gaps are real and persistent. The only
path forward is to run continuous adver-
sarial testing, treat offensive tradecraft as a
must-have capability, and build a security
culture that matches the stakes: Lives, not
just data, are on the line,” says Nic Adams,
cofounder and CEO of 0RCUS. “Leadership
must stop delegating cyber risk to paper-
work and start treating it as an existential
business threat. Anything less is just wait-
ing for the next breach headline.”
Beyond the Bare Minimum Even provider organizations that are
compliant with current HIPAA security
mandates fall short in achieving the
necessary protection in today’s evolving
threat environment. To change that,
OCR proposed an extensive overhaul
of the existing regulation with the
“HIPAA Security Rule To Strengthen the
Cybersecurity of Electronic Protected
Health Information” proposed rule,
published to the Federal Register in
January 2025, but not expected to be
finalized until 2026.1,2
“Far too many regulated entities
do not view cybersecurity as a neces-
sary component of their operations that
allows them to fulfill their health care
missions. Anecdotal evidence suggests
that senior management often lacks
awareness of cybersecurity, including
both threats and methods for protecting
against such threats,” OCR wrote.
A dvanced cybersecurity tools and
protocols—many of which will be
codified when the Office for Civil
Rights (OCR) finalizes its overhaul
of the HIPAA Security Rule—
have been relegated to the budgetary wish list by many
hospitals and health systems. However, as threat levels
rise, the chorus of voices warning providers to make
enhanced cybersecurity a budget priority grows louder.
Strategi Initiative
By Elizabeth S. Goar
14�FOR THE RECORD • AUTUMN 202514�FOR THE RECORD • AUTUMN 2025
c e
Calculating the Risk-Reward Equation for Health Care Cybersecurity
Layna Cook Rush, CIPP/US, CIPP/C,
a shareholder with Baker Donelson who
heads up the law firm’s Data Incident
Response Team, concurs with OCR’s sen-
timents. Meeting the minimum require-
ments is unlikely to provide adequate
protection in today’s threat landscape. “Not
investing in an up-to-date cybersecurity
program opens an organization up to an
attack, which can lead to significant finan-
cial costs, including ransomware payments,
regulatory fines, lost profits during down-
time, and class action lawsuits,” she says.
Adams calls regulatory minimums a
“false floor,” adding that “doing the bare
minimum means attackers have a free
map to your environment, and regulators
have a trigger for postbreach penalties.”
According to Asdrúbal Pichardo, CEO
of Squalify, security and compliance are
not interchangeable. “Meeting the bare
minimum may check a box, but it won’t
stop a breach or the financial and opera-
tional chaos that follows. Organizations
hit with multimillion-dollar ransom
demands often discover too late that their
backups are insufficient and insurance
coverage limited,” he says, adding that
when postbreach lawsuits roll in and con-
trols are found to be substandard, “liabil-
ity becomes much harder to defend. Doing
the minimum might satisfy auditors, but
it won’t satisfy plaintiffs or your board.”
Baby Steps for Hardening Security There is no question that pro- vider organizations are fall- ing short on cybersecurity, including failing at proactive threat emulation, live adver- sary simulation, and real-time breach-path analysis,” says Nic Adams, cofounder and CEO of 0RCUS.
“Most rely on checklist compliance, HIPAA audits, policy templates, annual train- ings, basic [endpoint detection and response] deployments, or vulnerability scans, none of which simulate how real attackers breach medical infrastructure,” he says. “Secu- rity needs to stop being man- aged as another paperwork exercise, as it’s quintessential war gaming. Asset inventory is incomplete, segmentation is weak, and critical trust assumptions go untested. Vendors push point solutions, while attackers move through open lateral paths and mis- configured APIs [application programming interfaces]. The gap: zero offensive tradecraft and little real adversary per- spective. The industry still thinks in defense, not offense.”
While it sounds impossible, stronger protection can be achieved without breaking the bank. Adams advises providers to stop buying shelfware and instead focus on the following:
• enforcing least-privilege across all accounts, service roles, and medical device logins;
• mapping critical data flows and locking down exposed APIs, remote access, and file shares;
• rolling out phishing-resis- tant multifactor authen- tication (MFA), not just text codes or security questions;
• conducting basic breach- path tabletop exercises monthly, not annually;
• patching public facing assets and removing orphaned accounts; and
• hardening backups with offline storage and regular restoration drills.
Squalify CEO Asdrúbal Pichardo says immediate steps start with visibility in areas of vulnerability. Noting that you can’t protect what you don’t understand, he suggests ensuring that the organiza- tion’s risk assessment is current is “a lightweight but high-value step” to highlight strengths and weaknesses so the most serious risks can be addressed.
“The proposed updates to the HIPAA Security Rule included conducting annual risk assessments, rather than as needed, which is a good practice to ensure a periodic
situation report of cybersecu- rity, regardless of whether it ends up in the final updates. It costs next to nothing but quickly reveals policy gaps, access control weaknesses, and vendor or business associ- ate blind spots,” he says. “From there, focus on controls that reduce likelihood and impact of your biggest risks: tighten user provisioning, implement MFA on privileged accounts, and ensure backups are segmented and regularly tested.
“These steps don’t require massive capital outlays— though costs will vary with the size and complexity of the organization—but they dra- matically improve your cyber readiness,” Pichardo adds.
John Trest, chief learn- ing officer of VIPRE Security Group, says there are several budget-friendly actions pro- vider organizations can take right away to boost their secu- rity profile, including enforcing strong password policies and adding MFA for all accounts, especially those with access to patient data and administra- tive systems. Training employ- ees regularly on phishing, social engineering, secure handling of sensitive data, and perti- nent threat vectors is also pru- dent “as human error remains the top cause of breaches. To beat the forgetting curve, it’s
important to reinforce key les- sons with microlearning videos, posters, and ongoing discus- sions so that security as a whole stays top of mind,” he says.
Other recommendations include the following:
• keeping software, operat- ing systems, and medical devices updated with the latest security patches;
• auditing and limiting access controls by only giving employees the mini- mum access necessary based on their roles; and
• monitoring network activ- ity to quickly detect suspi- cious behavior. There are many low-cost monitoring tools that can add an extra layer of protection.
“These relatively inexpen- sive steps can help prevent the chaos, expense, and repu- tational fallout that follow a breach,” Trest says, emphasiz- ing that any steps are better than none in the current high- risk threat landscape. “Health care data is among the most valuable on the dark web,” Trest says. “Doing the bare minimum leaves organiza- tions wide open to a range of attacks and consequences. In short, minimal effort invites maximum risk.”
— ESG
16�FOR THE RECORD • AUTUMN 2025
Chris Cronin, a principal consultant
and partner with Halock Security Labs,
who invented the Duty of Care Risk Analy-
sis standard and is the primary author
of the Center for Internet Security Risk
Assessment Method, says what many
in the security business miss is that the
HIPAA Security Rule, as it’s written, is not
about prescriptive guidance: It’s about
taking reasonable action to prevent the
opportunity for harm.
Health and Human Services (HHS)
wants providers to demonstrate that they
considered protecting patients’ privacy
and data as they developed their cyberse-
curity strategies, Cronin says. That is why
the decision by OCR to avoid being overly
prescriptive in the original security rule
was a double-edged sword. OCR doesn’t
dictate exactly which controls to use,
which can be frustrating for some regu-
lated entities. However, it also means those
entities can justify which controls they use
based on the risk and the costs to reduce it.
Provider organizations “can’t read
the tea leaves to understand what HHS
wants,” he says. As a result, they tend to
rely on maturity assessments or audits to
identify specific compliance gaps, then
raid clinical and operational budgets for
technology solutions to close them.
They strive for compliance “without
actually addressing the reasonableness
question of HIPAA,” Cronin says. “Every
organization, including hospitals and
other clinical providers, is supposed to
be a balanced environment. Achieve your
mission, protect others you might harm,
and don’t spend more than the risk to
accomplish both.
“But if money in [the clinical] budget
gets shifted to the cybersecurity budget,
that better not reduce patient care,” he
continues. “That would not be reasonable
if patients suffered unnecessarily to afford
a ransomware safeguard that an audit
said was needed. The clinical environ-
ments aren’t being well served with these
maturity assessments and audits.”
In other cases, cybersecurity is ignored
due to budget limitations, which is also the
wrong approach because, when the inevi-
table breach or ransomware attack occurs
and OCR comes calling, saying there was
no money for a risk analysis will not fly.
“You need to show [regulators] that
what you did was reasonable, that it was a
balance between your budget and patient
care,” Cronin says. “You can’t just say,
‘We won’t do this because we don’t have
the budget.’ You have to do what you can
to reduce the risk to the patient and still
function as a hospital.”
Setting Standards There are numerous examples of provider
organizations falling short in their cyber-
security efforts and incurring financial
and reputational losses. However, the
most effective justification for changing
perceptions around cybersecurity invest-
ments can be found in a cybersecurity
unicorn: a health system that has never
experienced a breach.
“Knock wood,” says Kevin Torres, chief
information security officer (CISO) of
MemorialCare, a nonprofit health system
that includes four hospitals, two medical
groups, imaging centers, and surgical cen-
ters providing care to patients in Orange
County and Los Angeles County, Califor-
nia. The system’s success is a byproduct of
the system’s focus on creating a culture of
cybersecurity awareness that runs from
the top down.
“You need to spend an equal amount of
time on cultivating the culture as you do
with the implementation of tools to pro-
tect you, and it all starts with your employ-
ees. They are the main threat vector that is
being compromised,” Torres says.
Along with educational articles, man-
agement presentations, and monthly
governance, Torres and his team col-
laborated with MemorialCare’s market-
ing department to create a tip corner and
craft messages published in the monthly
CEO report to all employees. Initiatives
supporting that culture are as crucial to
his role as implementing safeguards and
conducting penetration testing.
“The more equipped your employees
are, and the more educated they are on
what to look for, the better off we are,” Tor-
res says. “We have built training programs
that are mandatory, like what to look for
in a phishing attempt. We test them at the
end, and they have to pass that test. Then
we hold them accountable … It’s not that
we want to penalize them. We want to
educate them. We want to work together
with them.”
Which is not to say that MemorialCare
doesn’t place a priority on investing in
state-of-the-art security tools. They do.
For example, the health system is imple-
menting an identity management system
from Clear, which rose to prominence
during the pandemic and continues to
partner with TSA at airports nationwide.
“Even with all the tools, you still have
a constant barrage of social engineering
[attacks] … We’re going to spend a lot of
time on access and the social engineer-
ing piece because we think that’s our big-
gest potential vulnerability,” Torres says,
adding that MemorialCare also utilizes
behavioral analytics and AI to detect
social engineering attempts earlier.
Torres recognizes that MemorialCare’s
views on cybersecurity are not the norm
and is careful not to take advantage by
overspending on tools that aren’t the right
fit. For those IT leaders who are as lucky,
he recommends benchmarking against
peers as much as possible to demonstrate
when spending is below average and put-
ting data at risk.
“The board at MemorialCare has
adopted a very strong and supportive
stance on cybersecurity. They don’t see
it as a technical problem. They see it as
an enterprise risk management issue,”
he says. “This is not a technical issue or a
cybersecurity issue to solve. It’s an orga-
nizational issue, and everybody has to get
behind that, from the CEO to the board
and all the way down.”
Making the Business Case MemorialCare’s perspective is something
CIOs and CISOs can emphasize when
seeking support for improving secu-
rity profiles. Rush suggests capturing
the attention of the C-suite by framing a
cybersecurity incident as a business risk,
rather than a technical concern.
“In addition to regulatory exposure,
there is the expense of operational down-
time, potential reputation damage,
and class action lawsuits. The costs of
a cybersecurity breach can easily out-
weigh the cost of instituting a strong
cybersecurity program. Having a strong
cybersecurity program is good for the
bottom line,” she says, noting that IBM in
its 2024 Cost of a Data Breach Report put
the price tag of the average health care
breach at nearly $9.8 million—the high-
est of any industry.3
“By contrast, by investing even a frac-
tion of that cost in its cybersecurity
program, an organization can establish
layered defenses, threat monitoring, and
response capabilities that will protect
against cyber incidents and reduce the
impact if one does occur,” Rush says.
AUTUMN 2025 • WWW.FORTHERECORDMAG.COM�17
Pichardo shares that leading with finan-
cial exposure is more effective than relying
on technical jargon when making the busi-
ness case around cybersecurity enhance-
ment. “C-suites and boards don’t need a
list of software vulnerabilities, they need to
understand potential revenue loss, regula-
tory fines and lawsuits, or patient churn
tied to a breach. Frame the conversation
in terms of risk-adjusted ROI [return on
investment]: how a targeted investment in
cybersecurity today can prevent multimil-
lion-dollar losses tomorrow,” he says. “The
question isn’t whether a breach could hap-
pen. It’s what it would cost the business if it
did, and whether you’re comfortable with
that risk sitting on the balance sheet.”
Making the business case for cyber-
security investments can be challenging
because “it can be difficult to provide an
economic analysis to a damaging event
with uncertain probability,” says George C.
Pappas, CDH-E, CEO of Intraprise Health,
by Health Catalyst. He recommends start-
ing with a validated security risk assess-
ment conducted by a third party. This will
construct a clear picture of the organiza-
tion’s security posture and provide a list of
its important security needs.
This analysis “can provide a roadmap
of fixes and their priority that you can
work on over time,” he says. “Next, com-
pare your own posture to similarly situ-
ated organizations. If the organization
has large gaps, there is a stronger argu-
ment for urgent/important needs to be
addressed. Lastly, examine the cost and
patient harm of cyberattacks on organiza-
tions of similar size and scale.”
John Trest, chief learning officer with
VIPRE Security Group, recommends com-
paring the cost of a security event with
that of proactive security investments,
from training to endpoint protection.
These “are usually a fraction of that cost
and are spread out over time,” while the
tangible and intangible costs of a cyberat-
tack “can take years, or even decades, to
rebuild.” Thus, he says, “while CEOs tend
to focus more on risk and ROI, it’s up to
IT leadership to clearly explain what’s at
stake and why stronger security matters.”
To that end, Trest recommends estab-
lishing a business case that communi-
cates the following:
• Financial risks: Highlight the poten-
tial fines for HIPAA noncompliance,
costs of breach remediation, patient
notification expenses, lawsuits, and
reputational damage.
• Operational disruption: A ransomware
attack can halt patient care, divert
employee time, and damage trust.
• Competitive advantage: Strong security
measures protect the organization’s
reputation and can be a market dif-
ferentiator for patients and partners.
Framing security as a patient safety
issue often resonates the most with
health care executives.
Adams suggests mapping every
investment directly to risk avoidance
and bottom-line preservation, as well as
quantifying the potential cost of down-
time, lost revenue, and regulatory pen-
alties. When possible, utilize real-world
breach case studies from similar organi-
zations and translate technical controls
into business impact, tying patient safety,
continuity of care, and brand reputation
to specific security gaps. Additional steps
include the following:
• show how adversarial simulation
closes existential exposure;
• frame cybersecurity expenditures as
business resilience, not IT overhead;
and
• demonstrate that regulatory fines and
breach losses exceed the incremental
cost of proactive security.
“Advanced security investments in
offensive simulation, robust segmenta-
tion, hardened backups, and continuous
red-teaming typically cost a fraction of a
single breach event,” Adams says. “Leader-
ship must recognize the asymmetry: One
breach can wipe out years of profit, while
security spend is predictable, measurable,
and reduces existential risk.”
Cyber Insurance One aspect of cybersecurity that is often
underappreciated, despite its growing
influence in decisions regarding appro-
priate protection, is insurance. In the
current risk environment, appropriate
coverage has become a significant and
essential line item, and premiums are ris-
ing with the stakes.
Ryan Griffin, who heads the US cyber-
insurance division of McGill and Part-
ners, notes that cyber coverage is a young
market, having only gained prominence
over the past 20 years. However, the rapid
advancement of both technology and the
capabilities of bad actors has accelerated
the maturation of coverage. The challenge
for insurers is that, unlike coverage for a
physical asset, cyber insurance is primar-
ily based on good faith.
“They’re taking the client’s word that
the [environment] is secure. It’s hard to
attest that you’ve implemented a [par-
ticular] security control throughout the
environment,” he says. “You may have
implemented it 95% of the way, but the
threat actors are really good at exploit-
ing the areas where you haven’t. Just from
a risk management standpoint, for CIOs
and their security officers, that is an abso-
lute nightmare challenge.”
Cyber insurers have also assumed a
dual role as protector and trusted advisor.
As such, they not only hold their beneficia-
ries accountable for meeting best practices
and providing appropriate protection but
also act as expert resources for accelerat-
ing recovery in terms of identifying where
and how the breach happened, the extent
of the damage, and all the required steps
that must be taken postbreach in terms
of reporting and notifications. They also
continuously scan the threat environment
and alert clients early to emerging threats,
as well as tracking data on everything from
trends in ransomware payments to threat
actors and breach mechanisms.
“The number one role the insurance
companies play is helping on the resil-
iency side when you do experience an
event,” Griffin says. “It’s basically ‘in case
of emergency, break glass’ [and] we’ll air-
drop a team of lawyers and cybersecurity
professionals to help you recover in those
first 72 hours.”
Insurance also protects against fines
and other penalties that regulators assess
following incidents, “which is a rarity in
the insurance world,” Griffin says. “Com-
pliance is in the eye of the beholder at
times, and usually, health systems are the
victim of an attacker. Sometimes we forget
that … It isn’t malicious noncompliance.
They were doing their best and thought
they were meeting the standards but were
still exploited.” �
Elizabeth S. Goar is a freelance health care writer in Wisconsin.
For references, view this article on our website at www.ForTheRecordmag.com.
18�FOR THE RECORD • AUTUMN 2025
Copyright of For the Record (Great Valley Publishing Company, Inc.) is the property of Great Valley Publishing Company, Inc. and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.