Cybersecurity: What Every NP Must Know Part 1 – Overview

Just a few years ago, cybersecurity was treated simply as an IT issue within a medical practice or healthcare organization.
Thatโ€™s no longer the case. Today, cybersecurity in healthcare organizations is viewed as part of the bigger national system.

Perhaps you remember… February 21, 2024…

A ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary processing 40% of all medical claims in the US, exposed a critical weakness in the U.S. healthcare system.

This was not your average data breachโ€ฆ

The cyberattack caused major disruption to the US healthcare system, affecting claims processing, delaying payments, disrupting prescription refills, and creating widespread financial instability across practices, especially for smaller and rural ones.

Hereโ€™s what made this incident so alarmingโ€ฆ

Change Healthcare functioned as a centralized hub for claims and prescription data, and when it was attacked, the entire system felt the impact.

Approximately 190 million individuals had sensitive data exposed; it was one of the worst attacks on the US healthcare system.

This cyberattack made it clear that healthcare today is so interconnected that a single point of failure can ripple across the entire ecosystem, triggering a major shift in regulatory thinking.

When a cyberattack can delay access to life-saving care and medications and threaten the viability of medical practices, it is no longer an isolated compliance issue but a matter of national resilience.

The response to the systemic risk is the Health Care Cybersecurity and Resiliency Act of 2025 (S. 3315).

This legislation represents the most significant overhaul of healthcare data security since the HITECH Act of 2009, which primarily encouraged providers to adopt electronic health records to ensure the privacy of healthcare data. 

At its core, Senate Bill 3315  replaces the previous โ€œtrust-basedโ€ compliance model with one built on verifiable evidence.

In the past, organizations were expected to make โ€œreasonable effortsโ€ to protect data. Under the new framework, they now must prove it with documentation, logs, testing results, and audits.

If passed, the new legislation would require all HIPAA-regulated entities to implement minimum cybersecurity standards, including:

  • MFA – Multi Factor Authentication:
    Moving from simple passwords to mandatory multifactor authentication (MFA) to gain system access.
  • Data Protection:
    Encrypt all electronic protected health information (ePHI), at rest and during transit.
  • Security Testing:
    Conduct audits and penetration testing (simulated cyberattack to check for exploitable vulnerabilities) to maintain the integrity of information systems.
  • Framework:
    Alignment with established standards like the NIST (National Institute of Standards and Technology) frameworks.

The key theme is clear: saying your systems are secure is no longer enough; you must be able to prove it.

Since managing cybersecurity at this scale requires more than a single agency, S. 3315 formalizes a coordinated federal effort involving three primary players.

  • HHS – The Department of Health and Human Services:
    takes the lead role. It is responsible for updating HIPAA regulations, developing a national incident response plan, and reporting to Congress on the state of healthcare cybersecurity.
  • CISA – The Cybersecurity and Infrastructure Security Agency: serves as the technical backbone, providing expertise, developing training programs, and helping improve cybersecurity literacy across the healthcare workforce.
  • ASPR – The Administration for Strategic Preparedness and Response: plays a particularly important role as the Sector Risk Management Agency. Its focus is identifying hidden risksโ€”especially third-party vendors whose failure could create widespread disruption.

Together, these agencies create a structured ecosystem designed to identify threats before they escalate and to respond effectively when incidents occur.

While the legislation’s goals are widely supported, its implementation raises real concerns, particularly for smaller practices.

Implementation estimates across the entire healthcare industry are $30 billion.

For independent practices already operating on thin margins, this is not just a minor inconvenience but a major challenge.

Adding new layers of cybersecurity is expensive and can feel overwhelming, particularly when operating with a small team, limited IT support, and a tight budget.

To address this issue, the legislation includes โ€œSafe Harborโ€ for certain entities.

Previously, Safe Harbor was more of a guideline. However, under S. 3315, it becomes a formal requirement that must be considered.

Under Safe Harbor provisions, offices that can demonstrate they followed โ€œrecognized security practicesโ€ for at least 12 months before a data breach may receive reduced penalties and fewer regulatory consequences.

In practical terms, this means documentation matters more than ever. Itโ€™s not enough to implement security measures: you must track, record, and maintain evidence of your efforts.

Practices that proactively adopt strong cybersecurity measures may significantly reduce their legal and financial risks if a breach occurs.

The proposed legislation acknowledges that not all healthcare organizations have the same resources.

To prevent cybersecurity from becoming a โ€œluxuryโ€ only large systems can afford, the bill includes some targeted support:

  • Federal grants for rural clinics, nonprofit hospitals, and Federally Qualified Health Centers (FQHCs)
  • Tailored guidance for low-resource settings
  • Specialized assistance for high-risk sectors like the Indian Health Services and cancer centers

These provisions are essential because without them, the gap between large health systems and smaller practices would continue to widen.

Unfortunately, they donโ€™t address the needs of other small medical offices that may struggle to implement the required changes. Hopefully, this will be addressed before the bill is signed into law.

The proposed legislation has passed the US Senate Committee on Health, Education, Labor, and Pensions (HELP Committee). suggesting a high likelihood that it will be signed into law.

Historically, organizations can expect a relatively short implementation window, known as the โ€œsix-month rule,โ€ after final regulations are published.

This means practices will need to act quickly; waiting is neither viable nor smart.

The following lists the new requirements:

  • Implement multifactor authentication across all systems
  • Maintain a complete inventory of all devices, software, and vendors
  • Ensure encryption of data both at rest and in transit
  • Conduct annual penetration testing
  • Develop and test an incident response plan
  • Invest in ongoing staff training and cybersecurity awareness
  • Document, document, document

Some things are easier to implement than others. Donโ€™t wait to get started; start implementing as soon as you can.

These are no longer โ€œbest practices.โ€ They are quickly becoming baseline expectations.

The proposed changes represent a new standard.

Promises or policies no longer define healthcare cybersecurity. Today, they are defined by documented, auditable evidenceโ€ฆ by proof.

Practices that understand this shift and begin preparing now will not only protect their businesses but also position themselves to thrive in a more demanding regulatory environment.

For Nurse Practitioners and independent practice owners, this is more than a compliance issue; it’s a business imperative.

Weโ€™ll cover what to do and how to start implementing the new requirements in subsequent articles.

And weโ€™ll keep you up to date on changes to the legislation as soon as information becomes available.


How prepared are you should the proposed legislation become law?

Let us know in the comments below…


By Johanna Hofmann, MBA, MAc., EAMP; regular contributor to the NPBusiness blog.

Leave a Reply


Your email address will not be published. Required fields are marked

This site uses Akismet to reduce spam. Learn how your comment data is processed.

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}