Two years after a single unprotected login screen at Change Healthcare froze claims and prescriptions across the country, healthcare cybersecurity in 2026 looks less like a compliance checkbox and more like an operating condition. Ransom demands are climbing, a proposed federal rule that would force major security upgrades has been stuck in review for over a year, and hospital boards are being asked to treat cyber resilience as a patient-safety issue rather than an IT line item. This article surveys the threat landscape, the uncertain regulatory picture, and where health systems are actually putting their security budgets as of 2026. It is general background information, not legal or compliance advice.
The Threat Landscape: Ransomware and Third-Party Risk Keep Compounding
Ransomware remains the dominant threat to hospitals and health systems, and the numbers have continued moving in the wrong direction. Industry trackers reported average ransom demands against healthcare targets climbing sharply into 2026, with some analyses putting early-2026 average demands in the range of several million to tens of millions of dollars for the largest incidents — a marked jump from prior years. Attacks against multi-location physician groups and specialty clinics, not just large hospital systems, rose noticeably through late 2025 and into 2026, reflecting attackers’ interest in softer, less-resourced targets that still hold valuable patient data.
The consequences extend well past IT downtime. Surveys of breached healthcare organizations have found that ransomware incidents are associated with delayed procedures, longer patient stays, increased transfers or diversions to other facilities, and — in a meaningful share of cases — measurable increases in mortality. That combination of financial and clinical stakes is why cybersecurity conversations inside health systems increasingly sit with the chief medical officer and the board, not only the CISO.
Layered on top of ransomware is a second, arguably more structural problem: third-party and supply-chain risk. Since the 2024 Change Healthcare incident — in which compromised credentials on a remote-access portal without multi-factor authentication cascaded into a nationwide disruption of claims and pharmacy transactions — healthcare has had to reckon with how much of its infrastructure runs through a small number of shared vendors. That reckoning hasn’t produced a fix. Reports to HHS’s Office for Civil Rights (OCR) involving business-associate breaches have continued at a high volume since 2025, and a single compromised billing processor, EHR host, or cloud vendor can still affect dozens of unrelated provider organizations simultaneously. A 2026 attack affecting device maker Stryker underscored that supply-chain exposure now extends to medical device and equipment vendors, not just data-processing intermediaries.
The HIPAA Security Rule Overhaul: Still Proposed, Still Unresolved
The single most-watched regulatory question in healthcare cybersecurity heading into 2026 is what happens to the proposed overhaul of the HIPAA Security Rule — and as of this writing, it remains genuinely unresolved. This section should be read with that uncertainty front and center.
Where things stand. HHS OCR issued a Notice of Proposed Rulemaking (NPRM) in late December 2024, published in the Federal Register in early January 2025, proposing the most substantial rewrite of the Security Rule (45 CFR Part 164, Subpart C) since 2013. The proposal would eliminate the long-standing distinction between “required” and “addressable” implementation specifications, making nearly all safeguards mandatory rather than subject to an organization’s own risk-based judgment. Specific provisions discussed in the NPRM include mandatory encryption of electronic protected health information (ePHI) at rest and in transit, multi-factor authentication for systems that touch ePHI, written technology asset inventories and network maps updated at least annually, mandatory penetration testing and vulnerability scanning on defined schedules, and tighter, more direct verification that business associates have actually implemented required safeguards rather than relying on contract language alone.
The public comment period closed in March 2025, and OCR received several thousand comments (roughly 4,700) — a volume the agency has publicly acknowledged it is still working through, with finalization kept on its regulatory agenda but no firm commitment that a final rule will actually issue. A coalition of hospital and provider associations has formally asked HHS to withdraw or substantially narrow the proposal, citing implementation costs and compressed timelines that they argue would fall hardest on rural hospitals, small physician practices, and other under-resourced providers. OCR leadership has acknowledged both the high cost of inaction on cybersecurity and the legitimate burden concerns raised in comments, without committing to a timeline for a final rule.
What this means practically. As of mid-2026, no final rule has been issued, no compliance clock has started, and there is no confirmed date by which one will. Anyone telling you the “2026 HIPAA update” is settled law is getting ahead of the actual record. Organizations should treat the NPRM’s specific requirements, numeric deadlines, and cost estimates as a proposal that could still change materially — or not advance at all — rather than as a compliance target to build toward on a fixed timeline.
A parallel legislative track. Separately from the OCR rulemaking, Congress has been advancing its own health-sector cybersecurity legislation. In early 2026, a Senate committee voted by a wide, bipartisan margin to advance the Health Care Cybersecurity and Resiliency Act, which would statutorily require HIPAA-regulated entities to implement baseline protections such as multi-factor authentication, encryption, and periodic penetration testing, aligned with NIST and CISA frameworks. The bill would also direct HHS to define a safe-harbor framework that could reduce penalties for entities that can demonstrate sustained use of recognized security practices, and would fund grant programs to help rural and safety-net providers absorb the cost of upgrades. Passing committee is a meaningful step, but it is not enactment — the bill still needs further floor action in both chambers before it could become law. Between the stalled NPRM and the still-moving legislation, there are currently two live, uncertain paths toward a legally binding update to healthcare’s security baseline, and neither has reached the finish line.
HHS Cybersecurity Performance Goals: The Voluntary Baseline That Already Exists
While the regulatory rulemaking sits in limbo, HHS has continued promoting a voluntary framework that is already in active use: the Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs), published through the HHS 405(d) program and maintained on the HHS Cyber Gateway. The CPGs were built on the same structural model as the Cybersecurity and Infrastructure Security Agency’s (CISA) cross-sector CPGs, adapted specifically for the operational realities of hospitals, clinics, and health IT vendors.
HHS publishes the current CPGs and supporting materials directly on the HHS Cyber Gateway, which is the most reliable place to confirm the current version and any updates. The CPGs are organized into two tiers:
- Essential goals — lower-cost, foundational practices that HHS considers a baseline any healthcare organization should be able to implement, such as basic multi-factor authentication, email security controls, and asset inventory practices.
- Enhanced goals — more advanced practices aimed at organizations with greater resources and more mature security programs, including more comprehensive network segmentation, centralized log management, and formal third-party risk assessment processes.
Because the CPGs are voluntary, they carry no independent enforcement mechanism today. Their practical significance is twofold: they give smaller organizations a prioritized starting point instead of an undifferentiated list of “best practices,” and they signal the direction regulators and legislators are already moving — many of the essential and enhanced CPGs overlap heavily with provisions in both the stalled HIPAA NPRM and the pending Senate legislation. Organizations that adopt the CPGs now are, in effect, hedging against multiple possible regulatory outcomes at once.
405(d) and the Health Industry Cybersecurity Practices (HICP)
The CPGs sit on top of a broader body of guidance developed through the HHS 405(d) Program, a public-private collaboration between HHS and the Healthcare and Public Health Sector Coordinating Council. Its flagship resource, Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP), was first published in 2018 and substantially updated in 2023.
HICP is structured to be usable regardless of an organization’s size: a main document identifies the sector’s top current threats — including ransomware, social engineering (expanded in the 2023 edition to cover smishing, whaling, and business email compromise alongside traditional phishing), loss or theft of equipment, insider and negligent-user data loss, and connected medical-device risk — and maps each to ten recommended cybersecurity practices. Two companion technical volumes then translate those ten practices into concrete controls: one scoped for small organizations with limited dedicated IT security staff, and one scoped for medium and large organizations that can support more sophisticated technical controls. The 2023 update also added attack-simulation exercises and formal cybersecurity risk assessment and management guidance as explicit practices, reflecting how much the threat model had shifted since 2018.
For health systems trying to decide where to start — or where to focus limited security budgets — 405(d) and HICP function as the connective tissue between high-level federal goals (the CPGs) and day-to-day technical implementation, without requiring an organization to reinvent a security program from first principles.
Where Health Systems Are Actually Investing in 2026
Budget surveys of health system and payer technology leaders heading into 2026 point to a few consistent investment priorities:
- Broad increases in cybersecurity spending. A large majority of health system technology leaders report plans to grow cybersecurity budgets in 2026, with reported increases substantial enough to make security one of the fastest-growing lines in health IT budgets generally, alongside core clinical systems.
- Identity and access controls. Multi-factor authentication, privileged access management, and identity governance continue to top priority lists — unsurprising given that compromised credentials, as in the Change Healthcare incident, remain one of the most common initial access methods in healthcare breaches.
- Network segmentation and resilience architecture. Rather than betting on a single new tool, many organizations are investing in segmentation, immutable backups, and continuous monitoring designed to contain and recover from an intrusion quickly rather than prevent every possible entry point — an acknowledgment that determined attackers will eventually get in.
- Medical device and operational technology (OT) security. A significant share of health systems report increasing budgets specifically for connected medical device and OT security, an area historically underfunded relative to traditional IT, and one made more urgent by 2026 incidents touching device manufacturers directly.
- AI-enabled defense — and AI-enabled risk. Artificial intelligence shows up on both sides of the 2026 ledger. Security leaders are investing in AI-assisted threat detection and triage to help thin security teams keep pace with alert volume, while simultaneously flagging that AI is lowering the skill barrier for attackers to automate reconnaissance and generate convincing phishing content. Several 2026 industry reports also warn that AI-enabled medical devices and clinical AI tools are being deployed faster than the security processes needed to govern them, creating a new category of risk that traditional IT security programs weren’t built to cover.
- Third-party risk management. Given the run of vendor-driven incidents since 2024, more organizations report formalizing vendor risk assessment programs — moving beyond a signed business associate agreement toward ongoing verification of a vendor’s actual security posture, mirroring exactly the kind of scrutiny the stalled HIPAA NPRM would make mandatory.
What This Means Going Into the Rest of 2026
The throughline across the threat data, the stalled rulemaking, the voluntary HHS goals, and the investment surveys is the same: the industry consensus on what good healthcare cybersecurity looks like — strong identity controls, encryption, segmentation, tested incident response, and real accountability for vendors — is not actually in dispute. What remains unresolved is whether, when, and through which mechanism (a finalized HIPAA rule, new federal legislation, or continued voluntary adoption of CPGs and HICP) that consensus becomes a binding floor for the entire sector. Health systems that wait for legal certainty before acting are, in practice, choosing to defend against 2024’s threat landscape with 2026 attackers already inside the perimeter. Organizations evaluating their own compliance posture and security roadmap should work with qualified counsel and reference primary guidance directly from HHS and CISA rather than relying on secondary summaries — including this one — for anything requiring legal precision.
Related reading
- The Proposed 2025 HIPAA Security Rule Overhaul
- Health IT Priorities for 2026: What Leaders Are Watching
Frequently Asked Questions
Has the HIPAA Security Rule update been finalized in 2026?
No. As of mid-2026, HHS OCR’s proposed overhaul of the HIPAA Security Rule remains a Notice of Proposed Rulemaking issued in late December 2024 and published in the Federal Register in January 2025. The comment period closed in March 2025 with several thousand submissions still under review, and no final rule or enforceable compliance deadline has been issued.
What is the difference between the HIPAA Security Rule NPRM and the Health Care Cybersecurity and Resiliency Act?
The NPRM is an HHS regulatory proposal to rewrite existing Security Rule requirements; the Resiliency Act is separate legislation moving through Congress that would create statutory cybersecurity mandates and a safe-harbor framework. Both propose similar controls (MFA, encryption, penetration testing) but neither has been finalized or enacted as of this writing.
What are the HHS Cybersecurity Performance Goals (CPGs)?
The CPGs are a voluntary set of prioritized cybersecurity practices published by HHS for the healthcare and public health sector, split into “essential” (foundational, lower-cost) and “enhanced” (more advanced) tiers. They are modeled on CISA’s cross-sector goals and align closely with the HHS 405(d) Health Industry Cybersecurity Practices guidance.
Why does third-party vendor risk keep coming up in healthcare cybersecurity discussions?
Healthcare has consolidated claims processing, billing, EHR hosting, and other critical functions into a small number of large vendors. When one vendor is compromised, as with Change Healthcare in 2024, the disruption cascades to every provider that depends on it, making vendor security an operational risk for organizations that were never directly breached themselves.
Where can I find authoritative guidance on healthcare cybersecurity requirements?
HHS maintains current guidance through its Office for Civil Rights HIPAA security pages and the HHS Cyber Gateway, and the Cybersecurity and Infrastructure Security Agency (CISA) publishes sector-specific resources for healthcare and public health. Both should be checked directly for the most current status of any proposed rule or guidance discussed here.
