Just a few years ago, cybersecurity was treated simply as an IT issue within a medical practice or healthcare organization.
Thatโs no longer the case. Today, cybersecurity in healthcare organizations is viewed as part of the bigger national system.
2024: A Wake-Up Call
Perhaps you remember… February 21, 2024…
A ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary processing 40% of all medical claims in the US, exposed a critical weakness in the U.S. healthcare system.
This was not your average data breachโฆ
The cyberattack caused major disruption to the US healthcare system, affecting claims processing, delaying payments, disrupting prescription refills, and creating widespread financial instability across practices, especially for smaller and rural ones.
Hereโs what made this incident so alarmingโฆ
Change Healthcare functioned as a centralized hub for claims and prescription data, and when it was attacked, the entire system felt the impact.
Approximately 190 million individuals had sensitive data exposed; it was one of the worst attacks on the US healthcare system.
This cyberattack made it clear that healthcare today is so interconnected that a single point of failure can ripple across the entire ecosystem, triggering a major shift in regulatory thinking.
When a cyberattack can delay access to life-saving care and medications and threaten the viability of medical practices, it is no longer an isolated compliance issue but a matter of national resilience.
Updates to Legislation
The response to the systemic risk is the Health Care Cybersecurity and Resiliency Act of 2025 (S. 3315).
This legislation represents the most significant overhaul of healthcare data security since the HITECH Act of 2009, which primarily encouraged providers to adopt electronic health records to ensure the privacy of healthcare data.
At its core, Senate Bill 3315 replaces the previous โtrust-basedโ compliance model with one built on verifiable evidence.
In the past, organizations were expected to make โreasonable effortsโ to protect data. Under the new framework, they now must prove it with documentation, logs, testing results, and audits.
If passed, the new legislation would require all HIPAA-regulated entities to implement minimum cybersecurity standards, including:
- MFA – Multi Factor Authentication:
Moving from simple passwords to mandatory multifactor authentication (MFA) to gain system access. - Data Protection:
Encrypt all electronic protected health information (ePHI), at rest and during transit. - Security Testing:
Conduct audits and penetration testing (simulated cyberattack to check for exploitable vulnerabilities) to maintain the integrity of information systems. - Framework:
Alignment with established standards like the NIST (National Institute of Standards and Technology) frameworks.
The key theme is clear: saying your systems are secure is no longer enough; you must be able to prove it.
A New Approach
Since managing cybersecurity at this scale requires more than a single agency, S. 3315 formalizes a coordinated federal effort involving three primary players.
- HHS – The Department of Health and Human Services:
takes the lead role. It is responsible for updating HIPAA regulations, developing a national incident response plan, and reporting to Congress on the state of healthcare cybersecurity. - CISA – The Cybersecurity and Infrastructure Security Agency: serves as the technical backbone, providing expertise, developing training programs, and helping improve cybersecurity literacy across the healthcare workforce.
- ASPR – The Administration for Strategic Preparedness and Response: plays a particularly important role as the Sector Risk Management Agency. Its focus is identifying hidden risksโespecially third-party vendors whose failure could create widespread disruption.
Together, these agencies create a structured ecosystem designed to identify threats before they escalate and to respond effectively when incidents occur.
The Problemโฆ
While the legislation’s goals are widely supported, its implementation raises real concerns, particularly for smaller practices.
Implementation estimates across the entire healthcare industry are $30 billion.
For independent practices already operating on thin margins, this is not just a minor inconvenience but a major challenge.
Adding new layers of cybersecurity is expensive and can feel overwhelming, particularly when operating with a small team, limited IT support, and a tight budget.
To address this issue, the legislation includes โSafe Harborโ for certain entities.
Safe Harbor for Eligible Practices
Previously, Safe Harbor was more of a guideline. However, under S. 3315, it becomes a formal requirement that must be considered.
Under Safe Harbor provisions, offices that can demonstrate they followed โrecognized security practicesโ for at least 12 months before a data breach may receive reduced penalties and fewer regulatory consequences.
In practical terms, this means documentation matters more than ever. Itโs not enough to implement security measures: you must track, record, and maintain evidence of your efforts.
Practices that proactively adopt strong cybersecurity measures may significantly reduce their legal and financial risks if a breach occurs.
Support for Some Providers
The proposed legislation acknowledges that not all healthcare organizations have the same resources.
To prevent cybersecurity from becoming a โluxuryโ only large systems can afford, the bill includes some targeted support:
- Federal grants for rural clinics, nonprofit hospitals, and Federally Qualified Health Centers (FQHCs)
- Tailored guidance for low-resource settings
- Specialized assistance for high-risk sectors like the Indian Health Services and cancer centers
These provisions are essential because without them, the gap between large health systems and smaller practices would continue to widen.
Unfortunately, they donโt address the needs of other small medical offices that may struggle to implement the required changes. Hopefully, this will be addressed before the bill is signed into law.
Whatโs Next?
The proposed legislation has passed the US Senate Committee on Health, Education, Labor, and Pensions (HELP Committee). suggesting a high likelihood that it will be signed into law.
Historically, organizations can expect a relatively short implementation window, known as the โsix-month rule,โ after final regulations are published.
This means practices will need to act quickly; waiting is neither viable nor smart.
A Checklist
The following lists the new requirements:
- Implement multifactor authentication across all systems
- Maintain a complete inventory of all devices, software, and vendors
- Ensure encryption of data both at rest and in transit
- Conduct annual penetration testing
- Develop and test an incident response plan
- Invest in ongoing staff training and cybersecurity awareness
- Document, document, document
Some things are easier to implement than others. Donโt wait to get started; start implementing as soon as you can.
These are no longer โbest practices.โ They are quickly becoming baseline expectations.
In Closingโฆ
The proposed changes represent a new standard.
Promises or policies no longer define healthcare cybersecurity. Today, they are defined by documented, auditable evidenceโฆ by proof.
Practices that understand this shift and begin preparing now will not only protect their businesses but also position themselves to thrive in a more demanding regulatory environment.
For Nurse Practitioners and independent practice owners, this is more than a compliance issue; it’s a business imperative.
How can you get started?
Weโll cover what to do and how to start implementing the new requirements in subsequent articles.
And weโll keep you up to date on changes to the legislation as soon as information becomes available.
How prepared are you should the proposed legislation become law?
Let us know in the comments below…
By Johanna Hofmann, MBA, MAc., EAMP; regular contributor to the NPBusiness blog.
