September 29, 2026
Key takeaways
  • Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
  • AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
  • Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
  • Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.

Last Updated on October 7, 2026

Strong cybersecurity is imperative for patient safety, care continuity, data privacy, and stakeholder trust across the healthcare vertical. While final action on the proposed HIPAA Security Rule update has been delayed until July 2027, this does not change the controls covered entities must implement.

 

HIPAA remains the foundational regulatory baseline for healthcare cybersecurity and privacy. But healthcare firms face intense, rapidly evolving financial, operational, and legal/compliance pressures driving them to deploy safeguards well beyond basic HIPAA compliance and independent of its update timeline. 

 

This post explains four major reasons why.

Key takeaways

  • Today’s advanced cyberattacks directly threaten patient safety, healthcare data privacy, stakeholder trust, and operational continuity for HIPAA covered entities.
  • Major pressures driving healthcare cybersecurity upgrades include AI-powered ransomware threats, stricter cyber insurance requirements, new regulations, and dangerous financial risks.
  • The proposed new HIPAA security requirements represent a compliance baseline, not a comprehensive control implementation to counter modern threats.
  • Waiting for the final HIPAA Security Rule update will only increase costs, prolong the implementation timeline, and increase cyber risk exposure.

Reason 1: Cyberattacks that directly threaten patient safety

Emerging AI-powered cyberattacks directly threaten patient safety and care continuity along with presenting significant financial and reputational risk. Major concerns include:

    • Ransomware attacks that derail electronic health record (EHR) systems, force ambulance diversions, delay critical procedures, and increase the risk of clinical errors. Healthcare network protection is now a core element of patient safety, leaving organizations no choice but to bolster their safeguards.
  • Third-party cyber risk. Healthcare systems are dependent on interlaced supply chains that include billing, records management, and other service providers; medical device manufacturers; SaaS vendors; and many other partners. Attackers frequently breach third-party systems as a stepping stone into customer networks. Vendor risk management programs, including comprehensive security assessments, are becoming ubiquitous across the healthcare ecosystem. Service providers must meet these requirements to remain competitive.

Reason 2: Financial and competitive imperatives

The financial and competitive fallout from a major cybersecurity incident can devastate a healthcare entity. Some of the worst consequences include:

  • Massive data breach costs. The healthcare vertical consistently has the highest average data breach costs of any industry, often reaching millions of dollars per incident. Key reasons include low downtime tolerance, lengthy recovery cycles, and costly emergency IT intervention to quickly remediate care-critical services. 
  • Class-action lawsuits. Major healthcare data breaches are almost always followed by class-action lawsuits citing cybersecurity and privacy negligence. These proceedings involve thousands of patients and employees and can create onerous financial liabilities. Combined with follow-on reputational impacts such litigation can sink a healthcare business.

Reason 3: New regulations besides HIPAA

The delay in finalizing the HIPAA Security Rule update has given covered entities more time to plan and execute cybersecurity improvements. But other regulations are taking that time right back:

  • US state-level regulations. State-level healthcare cybersecurity and privacy laws are often stricter than HIPAA around technical, administrative, and breach notification/response measures. For example, the California Confidentiality of Medical Information Act (CMIA) has higher penalty caps than HIPAA, while the Massachusetts 201 CMR 17 law already mandates strong encryption and a comprehensive security plan. State-level laws may also give citizens the right to sue hospitals and other healthcare firms directly for data exposure on top of potential federal-level actions. 
  • The FTC Health Breach Notification Rule. The US Federal Trade Commission (FTC) imposes strict data security requirements for healthcare apps and IoT devices that HIPAA does not cover. The FTC has issued substantial civil penalties against healthcare firms for improper data sharing with third-party advertisers.
  • HHS Cybersecurity Performance Goals (CPGs). The US Department of Health and Human Services (HHS), which also oversees HIPAA, has outlined “essential” and “enhanced” cybersecurity controls. Although currently voluntary, HHS intends to convert this guidance into enforceable regulations connected to HIPAA and Medicare/Medicaid reimbursement models and associated federal funding. 

Reason 4: Stringent cyber insurance requirements

Cyber insurance providers already mandate many of the proposed HIPAA Security Rule controls as prerequisites for obtaining coverage. Healthcare businesses face severe financial, legal, operational, and reputational risks from large-scale cyberattacks—making risk transfer through insurance essential for business survival.

Core controls that modern cyber insurance policies now overwhelmingly mandate include:

  • Multifactor authentication (MFA) across all email systems, remote access services (e.g., VPN and Remote Desktop Protocol), and privileged accounts.
  • Vulnerability scanning and patch management, including a regular patching cadence. 
  • Immutable encrypted and offline/offsite backups to support ransomware recovery.
  • Endpoint detection and response (EDR) or managed detection and response (MDR) with active, 24×7 monitoring and behavioral threat detection across all devices.
  • A documented, tested, and current incident response plan to contain impacts from data breaches and other active cyber incidents.

 

Other controls that cyber insurers may require include:

  • Business process controls to prevent unauthorized financial transactions and wire fraud.
  • Regular, documented employee training, including security awareness and phishing simulations.
  • Network segmentation to isolate legacy medical devices from core administrative networks. 
  • AES-256 encryption protecting all sensitive data both at rest and in transit.
  • Verifiable compliance with all applicable security, privacy, and regulatory requirements (e.g., PCI-DSS, SEC security guidelines).
  • A vendor risk management program.
  • Least-privilege access controls.

 

Failure to deploy or maintain required controls can lead to coverage denial or higher premiums. Misrepresenting your controls during the policy application process can lead to a policy being voided.

Frequently Asked Questions

 

What is the proposed HIPAA Security Rule?

A: The proposed HIPAA Security Rule is a Notice of Proposed Rulemaking (NPRM) from the U.S. Department of Health and Human Services (HHS) designed to update cybersecurity standards for electronic protected health information (ePHI).

 

Why isn’t HIPAA compliance enough to prevent today’s advanced cyberattacks?

A: HIPAA compliance sets a baseline for protecting ePHI, but it is not intended to define comprehensive technical controls. A company could pass a HIPAA audit and still face excessive cyber risk from ransomware and other prevalent attacks. 

 

What trusted cybersecurity frameworks can support HIPAA compliance?

A: Best-practice cybersecurity standards that are widely adopted in by healthcare leaders include HITRUST CSF, the NIST Cybersecurity Framework (NIST CSF), and ISO 27001.

 

How do zero trust principles apply to healthcare data protection?

A: The zero-trust view presumes that attacks are already in progress both outside and inside the network. Instead of trusting a user or device by default, zero trust recommends role-based access control, continuous verification, and network micro-segmentation to contain attack impacts.

 

How can hospitals protect connected medical devices that lack adequate onboard security?

A: Internet of Medical Things (IoMT) devices like monitors or infusion pumps need to be isolated on clinical network segments. Configuration and patching best practices are also important.

What’s next?

Taking steps now to bring cybersecurity in line with the threat landscape can help healthcare companies control data breach losses, reduce legal/compliance risks, and improve competitiveness. Waiting until HIPAA mandates new requirements will only increase costs and delay time to value while exposing your business to potentially overwhelming cyberattacks.

 

CBIZ is a trusted partner with extensive experience helping customers efficiently achieve and maintain HIPAA compliance while demonstrating robust cybersecurity to regulators and other stakeholders.

Connect with a member of our cybersecurity team to discuss how HIPAA Security Rule changes could impact your business and develop a strategic approach to address them.



Back to Blog