Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Get Ahead of New Healthcare Cybersecurity Standards

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) required hospital networks, clinics, and research institutes to meet strict healthcare cybersecurity standards. But complying with the new Strengthening American Cybersecurity Act may be a whole new level of challenge. The bill, enacted on March 15, takes a carrot and stick approach to security. It…

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Share

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) required hospital networks, clinics, and research institutes to meet strict healthcare cybersecurity standards. But complying with the new Strengthening American Cybersecurity Act may be a whole new level of challenge.

The bill, enacted on March 15, takes a carrot and stick approach to security. It comprises three distinct acts. The Federal Information Security Modernization Act of 2022 and the Federal Secure Cloud Improvement and Jobs Act of 2022 could be described as carrots. They encourage covered entities to be proactive in improving their resilience to attacks. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 is more of a stick. It stipulates harsher sanctions for breach notifications.

The rulemaking process, conducted by the Cybersecurity and Infrastructure Agency (CISA), is yet to begin in earnest. Accordingly, the extent of the law’s coverage is unclear. Currently only federal agencies and operators of critical infrastructure are definitely covered. However, the “Healthcare and Public Health Sector” is one of CISA’s 16 previously earmarked critical sectors. So the Strengthening American Cybersecurity Act will likely usher in new healthcare cybersecurity standards. The sooner they come, the better, given how the threat landscape is evolving.

Stricter Reporting Is Likely

Among the most stringent compliance requirements in the new Act is the focus on making cyberattack reporting faster and more detailed. The law requires covered entities to notify CISA within 72 hours of a breach occurring. When ransom payments are made, organizations must tell CISA within 24 hours. (Read The Life-Threatening Rise of Ransomware in Healthcare.) Reports to CISA must be detailed and provide information about how the incident happened and which security controls were in place.

Healthcare providers are familiar with the need to report certain types of HIPAA breaches. Indeed many have been busy instituting procedures to notify Protected Health Information (PHA) exposure within 60 days to comply with the most recent version of the law. However, few organizations are likely ready for the swift response reporting stipulated by the Strengthening America Cybersecurity Act.

HIPAA is designed to secure PHA only. The reporting requirements in the Strengthening America Cybersecurity Act are much broader. And the new law’s definition of a cybersecurity incident is still unclear. What is clear is that covered organizations must respond to cyberattacks much faster than they do now.

Unfortunately, when responding to security incidents healthcare organizations perform exceptionally poorly. A cross-sectoral study by Immersive Labs found health care organizations received an average cyber incident performance score of only 18 percent. This was the worst of any sector in the study. (Read The Top Three Weaknesses in Healthcare Cybersecurity.)

Stopping Attacks Is the Best Way to Beat Reporting Requirements

The best way to reduce the stress of reporting requirements is to stop breaches in the first place. Regrettably, preventing attacks is also something healthcare organizations are poor at. Last year almost 1 in 2 residents in many US states had their personal healthcare information exposed by a cyberattack.

Tighter healthcare cybersecurity standards may bring increased risk of legal action. And the average healthcare data breach already costs over $9 million and takes 75 days to contain.

Healthcare’s poor record at stopping and reporting attacks is partly a product of culture. Cybersecurity has traditionally been under-prioritized. Even in 2021, with ransomware attacks on healthcare soaring, a ComputerWeekly report showed barely 1 in 10 hospital executives prioritized cybersecurity.

Another part of the recently passed law, the Federal Information Security Modernization Act of 2022, sets out a framework for changing this status quo. This act requires covered organizations to implement a range of preventive cybersecurity measures. Implementing zero-trust architecture may soon become mandatory.

The Case for Zero-Trust in Healthcare

Taking a zero-trust approach to security essentially means no network entity is automatically assumed to be safe, even after initial verification. This approach is urgently required within healthcare.

Providing care to patients means healthcare organizations offer threat actors an immense range of attack vectors. These are both technological and human. With endpoint numbers soaring, it’s chilling to note more than half of healthcare IoT devices host a known unpatched vulnerability. No less unsettling is that almost a quarter of healthcare staff have not received any security awareness training.

Healthcare organizations can’t overcome these inherent and long-standing vulnerabilities by plastering over cracks. Instead of trusting verified endpoints and devices, organizations need a security strategy that never trusts anything or anyone connected to its network. Making this happen is part technological and part cultural.

The obvious challenge of implementing zero-trust in healthcare is how to balance healthcare professionals’ operational requirements with tighter security controls. Healthcare professionals and hospital staff need to access patient data effortlessly. In many cases, security controls that get in the way can be dangerous to patient health.

Security teams must work with practitioners and administrators to develop authentication procedures and policies that fit real-world scenarios to overcome these obstacles.

In healthcare, an effective zero-trust strategy is one that strikes a balance between accessibility and security. Zero-trust technology protects hospital networks from malicious code execution and provides deterministic protection without impacting performance or straining networks.

With Regulation Looming, Don’t Delay Security Improvements

We don’t yet know precisely what the Strengthening American Cybersecurity Act requires of healthcare organizations. By the time the rulemaking process finishes, CISA may choose to apply a different version of the law’s current statutes.

However, it’s clear regulators will ask more of healthcare organizations’ cybersecurity. Zero-trust architecture is a central part of the security improvements federal regulators will require for healthcare organizations.

Learn more about how zero-trust architecture and Moving Target Defense protects against the advanced cyberthreats healthcare needs to defend against. Read the white paper: Zero Trust + Moving Target Defense—The Ultimate Ransomware Strategy.

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

More nurses did not lift safety culture scores in a 205-hospital analysis

More nurses did not lift safety culture scores in a 205-hospital analysis

A 2026 analysis in the Journal of Hospital Management and Health Policy combined 2021–2022 HSOPC results with AHA, HCRIS, and AHRF data across 205 hospitals and reported that small increases in nurse and physician staffing lined up with slightly lower “percent positive” patient safety culture scores in several dimensions. According to the Journal of Healthcare Management abstract hosted on Ovid, the study described a 2% decrease in positive staffing perceptions with β=−0.02 per additional nurse FTE and a −0.01 change in perceived reporting of patient safety events per additional nurse, while additional physician staffing was associated with −0.01 changes in perceptions of communication openness and organizational learning, and joint ventures were associated with a −0.03 change in perceptions of management support for safety (all p<0.05). The operational read is that adding headcount by itself does not ensure stronger safety-culture signals; hospitals also need the workflows that turn observations into closed-loop fixes, from “just culture” reporting expectations to facilities work-order follow-through, as described by Sentara Health leaders in Chief Healthcare Executive and by Health Facilities Management’s environment-of-care guidance. For health system operators, the near-term consequence shows up in how HSOPC survey targets connect to leader scorecards, rounding programs, digital reporting tools, and joint-venture governance, especially where staffing growth is driven by complexity and handoffs.

  • 01If HSOPC “percent positive” scores are a board KPI, staffing increases can move in the opposite direction unless reporting and learning loops scale too. The study’s negative coefficients are small, but they signal a measurement risk during growth.
  • 02Facilities and clinical safety cultures converge in the same pipeline: observation, reporting, triage, work order, verification. HFM Magazine’s door-lock example is the same system problem as event reporting, it is throughput and closure, not awareness.
  • 03Joint ventures can add operational complexity that dilutes perceived management support for safety. That belongs in JV governance charters and integration playbooks, not only in finance models.

Sep 1, 2026

Smart ICU and ambient AI cut errors when they feed data and notes into the EMR

Smart ICU and ambient AI cut errors when they feed data and notes into the EMR

Two HIMSS26 APAC case studies point to the same operational lesson: hospitals are getting measurable gains from “smart ICU” device integration and ambient AI documentation only when those tools are tightly integrated into core clinical workflows. Pondok Indah Hospital Group in Indonesia reported reductions of up to 70% in ICU administrative errors and 40% in adverse drug reactions after integrating smart devices, according to Healthcare IT News. Sir H.N. Reliance Foundation Hospital in India reported ambient AI is now used for nearly 90% of progress notes and shift handovers across five live use cases on a single EMR-integrated platform, also reported by Healthcare IT News. New JAMA Network cardiovascular research adds a parallel signal on the clinical side, with AI-enabled acquisition and interpretation approaches moving into screening and triage workflows, which raises procurement questions about validation, interoperability, and change management at the bedside.

  • 01A useful benchmark is emerging for documentation automation: “nearly 90% of progress notes and shift handovers” on ambient AI when it is deployed as one EMR-integrated platform, not a set of point tools (Healthcare IT News).
  • 02The measurable ROI in ‘smart ICU’ programs shows up where operators feel pain: fewer administrative errors and medication-related events, not in abstract “digitization” metrics (Healthcare IT News reported up to 70% and 40% reductions, respectively).
  • 03For hospitals with multiple device vendors and fragmented documentation workflows, integration work, interfaces, identity, order context, and governance, is likely to consume more effort than model selection, so contracts and implementation plans should price integration explicitly.

Sep 1, 2026

Gartner says AI budgets are growing faster than the rules to control them

Gartner says AI budgets are growing faster than the rules to control them

Gartner’s late-August 2026 research points to a familiar operational pattern in enterprise AI: budgets are rising faster than the controls meant to keep costs and risk predictable. In a Aug. 26 press release, Gartner said AI spending by customer service leaders surged 38% even as overall service and support budgets rose 2%. Earlier, at Gartner’s March 2026 Data & Analytics Summit, Gartner analysts said only 44% of organizations had adopted financial guardrails or AI FinOps practices, a gap that becomes more painful as AI workloads scale. The practical takeaway for CIOs, customer service operations leaders, and data and analytics teams is to treat AI governance, cost attribution, and human escalation paths as procurement requirements, not after-the-fact fixes.

  • 01A useful benchmark for planning: Gartner pegs AI spend growth in customer service at 38% versus 2% budget growth overall, a mismatch that forces reallocation and harder ROI proof.
  • 02Only 44% of organizations have adopted AI FinOps-style guardrails, according to Gartner. If AI is moving into production, chargeback and consumption limits need to be designed into the rollout.
  • 03Gartner also forecasts spending on securing AI will hit $4.8 billion in 2027, signaling that AI security is becoming a standalone budget line rather than a feature bundled into existing platforms.

Sep 1, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512