top of page

How to Choose a Healthcare Cybersecurity Provider

  • 2 hours ago
  • 14 min read
Cybersecurity for Healthcare

By Yonatan Hoorizadeh CISSP, CISM, CRISC, AAISM

Published By: Purple Shield Security

Published: August 11, 2026

Last updated: August 11, 2026

Start with a security risk analysis, not a product purchase. The best cybersecurity for healthcare is led by someone with no financial stake in what you buy, because that person can tell you to spend less. Ask any candidate provider one question first: do you resell, or take commission on, anything you might recommend?

Where should a healthcare organization start with cybersecurity?


Start with a security risk analysis that covers every system creating, receiving, maintaining, or transmitting electronic protected health information (ePHI). Not a vulnerability scan. Not a product demo. The risk analysis is the single provision the HHS Office for Civil Rights (OCR) cites most often in enforcement, and every downstream decision about budget, tooling, and vendors depends on knowing where patient data actually sits.


OCR has made that priority explicit. Its Risk Analysis Initiative had closed twelve enforcement actions as of early 2026, according to McDonald Hopkins, and OCR resolved six investigations with financial penalties in 2026 alone, collecting $1,278,000. In four ransomware settlements announced in April 2026, OCR found the same root cause in every case: no accurate and thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A). Those four entities paid $1,165,000 and accepted two-year corrective action plans, according to Sidley Austin.


OCR Director Paula M. Stannard put the agency's position plainly in the February 2026 settlement announcements: "Covered entities and business associates cannot protect electronic protected health information if they haven't identified potential risks and vulnerabilities to that health information."


Read that as a legal theory, because that is how OCR is using it. The regulator is not penalizing organizations for being attacked. It is penalizing them for never having understood where their ePHI lived. The unpatched server is a symptom. The missing risk analysis is the violation.


The sequence that works in practice runs in one direction: build the asset and data-flow inventory, run the risk analysis against it, produce a ranked remediation plan with owners and dates, then buy only the controls that plan calls for. Most practices run it backwards. They buy endpoint detection, subscribe to a compliance portal, and then try to reverse-engineer a risk analysis out of the tools they already own. OCR does not accept a tool inventory as a risk analysis, and neither does a plaintiff's attorney.


One lever small practices consistently miss: the HHS 405(d) Health Industry Cybersecurity Practices (HICP) framework counts as "recognized security practices" under Public Law 116-321. If you can demonstrate you had them in place for at least the previous twelve months, HHS is required to consider that when setting penalties, terminating an audit early, and shaping any resolution agreement. HICP is free, it is sized for small, medium, and large organizations, and it maps to the HHS Healthcare and Public Health Cybersecurity Performance Goals (HPH CPGs). For a fifteen-provider group with no security budget, twelve months of documented HICP alignment is worth more than any single product on the market.


Does the HIPAA Security Rule delay to 2027 mean you can wait?


No. In the Fall 2026 Unified Agenda, HHS moved the proposed HIPAA Security Rule amendments (RIN 0945-AA22) to its Long-Term Actions list and set July 2027 as the target for final action, according to Clark Hill. The current Security Rule remains fully enforceable, and OCR's 2026 enforcement record shows it is being enforced hard. The delay moved your deadline. It did not move your exposure.


OCR published the proposed rule in the Federal Register on January 6, 2025, and the comment period drew roughly 4,745 responses before closing that March. A coalition of more than 100 hospital systems and provider associations, including Cleveland Clinic, Yale New Haven Health System, the American Medical Association, and the American Academy of Pediatrics, formally asked HHS to withdraw it. Whether OCR finalizes it as written, narrows it, or drops it is unknown.


What is known is the compression risk. If the rule lands as proposed, it takes effect 60 days after publication with roughly 240 days to reach full compliance on most provisions. The word "addressable" disappears, which means encryption of ePHI at rest and in transit, multi-factor authentication, a complete technology asset inventory and network map, annual penetration testing, and 72-hour restoration of ePHI all become required rather than optional. Business associates would have 24 hours to notify covered entities of a security incident, down from the current 60-day outer limit.


Here is the part vendor content keeps skipping. HHS calculated the proposed changes at $9 billion in first-year industry cost and $6 billion annually for years two through five. Spreading that work across twenty-four months of ordinary budget cycles costs a mid-market provider group substantially less than compressing it into a 240-day scramble. The organizations that treat 2026 and 2027 as build time will pay less than the ones that wait for a publication date.


There is also a simpler reason not to wait: your cyber insurance carrier is already asking for the same controls. Renewal questionnaires in 2026 read like a technical audit rather than a checkbox form, and carriers increasingly run external scans against your perimeter before binding. If a provider is advising you to wait for the final rule, that tells you they are selling a compliance product on a regulatory release cycle rather than running a security program.


What kind of security provider does healthcare actually need?


Four different things are sold as "healthcare cybersecurity," and they solve different problems. Managed IT and managed security providers operate tools. Compliance platforms generate documentation. Assessment and penetration testing firms find problems and hand you a report. A vCISO (virtual Chief Information Security Officer) supplies the security leadership that decides what the other three should be doing. Most practices buy the first three and skip the fourth.


The gap matters because all three have a defined scope of work and none of them own your risk. Your managed IT provider is accountable for uptime and the stack it installed. Your compliance platform is accountable for producing a document. Your pen tester is accountable for the findings in the report. Nobody in that arrangement decides which of the ninety-one open findings gets fixed first, or answers to your board for that decision. That is the CISO function, and in a healthcare organization under a few hundred employees it is almost always unowned.


vCISO services and fractional CISO services are not the same thing

The two labels get used interchangeably and they should not be. A fractional CISO is typically an individual senior practitioner working with a handful of clients at ten to forty hours a month each, often willing to come on-site, usually specialized in one industry or stack. Fractional CISO services tend to flex to unusual situations because the person delivering them has run security programs directly. vCISO services are more often delivered through a firm with productized work: compliance templates, standardized gap assessments, board deck formats, always remote, cheaper per hour, less adaptable when your situation does not fit the template.


Both models beat the alternative on cost. A full-time healthcare CISO runs $250,000 to $600,000 or more in total compensation, and the role is genuinely hard to fill. Mid-market fractional and virtual CISO retainers commonly land between $3,000 and $12,000 a month depending on hours and scope. For a healthcare organization that needs judgment eight to twenty hours a month rather than forty hours a week, that math is not close.


The question to settle before you shop is which one you actually need. If your problem is "we have no documented program and an audit is coming," a productized vCISO engagement will get you there efficiently. If your problem is "we run six clinics, two EHRs, an ambient AI pilot, and an MSO relationship nobody has security-reviewed," you want a named senior practitioner who can sit in a room and make calls, not a template.


A size-based rule for picking the model

  1. Solo to roughly fifteen providers, single site: Get a risk analysis done properly and put a senior advisor on eight to sixteen hours a month. You do not need a full-time hire and a compliance subscription alone will not get you there. Document HICP alignment and start the twelve-month clock.

  2. Fifteen to one hundred providers, multi-site or multi-specialty: Move to a fractional CISO retainer with defined governance deliverables, and name an incident response contact in writing before you need one. This is also the size where business associate oversight stops being manageable in a spreadsheet.

  3. Above one hundred providers, an MSO, a private-equity-backed rollup, or any group with business associates downstream of you: You need someone whose only job is security governance, and that person needs to be structurally independent of whoever runs your IT. If the same firm operates your infrastructure and grades your infrastructure, you do not have an assessment, you have a self-review.


What questions separate a security partner from a reseller?


Ask questions that a conflicted provider cannot answer cleanly. Most healthcare security firms earn margin on hardware, software licensing, managed service contracts, or vendor referral fees, which means their recommendation and their revenue point in the same direction. That is not automatically disqualifying, but you need to know it before you weigh their advice. These seven questions surface it in a single call.


  1. Do you resell, receive commission on, or hold a partner agreement with anything you might recommend? The only fully clean answer is no. If the answer is yes, ask what percentage of their revenue comes from product margin. A firm earning most of its money on licensing will always find a licensing problem.

  2. Who personally signs the risk analysis, and what are their credentials? You want a named individual with credentials, not a firm logo. Ask whether that person would sign a risk analysis that identified their own prior work as a gap. Watch how long the pause is.

  3. What are your own confidentiality obligations to us? Your security provider will see ePHI and becomes a business associate. Ask for their BAA, their own SOC 2 Type II report or HITRUST certification, where your data physically sits, who on their staff can access it, and what happens to your findings when the engagement ends. For sensitive assessments, ask whether they will work under your outside counsel so the findings carry attorney-client privilege.

  4. Tell me about a time you told a client to spend less. Anyone who has genuinely run a security program has told a client to cancel a renewal, consolidate overlapping tools, or delay a purchase. If a candidate cannot produce that story, they have not been in a position where saying no cost them anything.

  5. What happens in month thirteen? Ask what the engagement looks like after the first assessment is delivered. A report is a deliverable. A program is a cadence: quarterly risk review, remediation tracking, vendor oversight, board reporting, annual reassessment. You are buying the second thing.

  6. If we are encrypted at two in the morning on a Saturday, what is your actual role? Ask how many other clients they hold retainers with, what their response commitment is, and whether that commitment survives a regional event where six of their clients are hit the same week. Get it in the contract.

  7. Do you also operate the IT you would be assessing? If they run your firewalls and also assess your firewalls, the assessment is marketing. Independence here is structural, not a matter of good intentions.


Purple Shield Security takes no product resale margin, holds no managed service contracts, and accepts no vendor referral fees, which is the reason we can answer question four with an actual story. Ask every firm you talk to the same seven questions and compare how comfortable each one sounds.


Where does healthcare risk actually live now?


Most healthcare breach exposure in 2026 sits outside the walls the organization controls. Business associates were involved in 43 percent of reported healthcare breaches in the first half of 2026, up from a 34 percent average across the prior nine years, according to HIPAA Journal's analysis of the HHS OCR breach portal. How you vet vendors now determines more of your exposure than your firewall does.


Vendors and business associates

The OCR breach portal recorded 189 large healthcare breaches affecting more than 19 million individuals in the first six months of 2026, with 173 of those attributed to hacking and IT incidents. Seven of the ten largest involved a business associate or vendor system. The largest, filed by TriZetto Provider Solutions in February 2026, affected 3,433,965 individuals through insurance eligibility verification records. The Verizon 2026 Data Breach Investigations Report found third-party breaches in healthcare rose 60 percent year over year.


One number reframes the whole problem. Patient Protect's State of Compliance review found that four business associate breaches accounted for 67.6 percent of all healthcare patient impact in the first quarter of 2026, from 1.9 percent of the incident count. A covered entity can run a well-defended network and still absorb most of its breach exposure through a revenue cycle vendor it onboarded in 2019 and never reassessed.

The vetting question almost nobody asks is the cascade question: which business associates does your business associate route PHI to? A billing platform that subcontracts transcription, analytics, or storage has created a fourth party your BAA never named. Ask for a current SOC 2 Type II report or HITRUST certification, ask who the auditor was, and ask the vendor to disclose its own downstream BAs in writing.


Cloud platforms you did not configure

Cloud exposure in healthcare is rarely a platform failure. It is misread shared responsibility: storage buckets left open, ambiguous identity and access management policies, and service accounts carrying far more privilege than the workflow requires. Your EHR host secures its infrastructure. What runs inside your tenant, who has administrative rights, how backups are isolated, and whether legacy authentication is disabled are yours, whether or not anyone at your practice knows it. Cloud security services worth paying for start by drawing that line explicitly for each platform you use, in writing.


Devices you are not allowed to patch

Connected medical devices are a compensating-controls problem, not a patching backlog. A March 2026 HIMSS survey found that 60 percent of healthcare organizations cannot adequately protect unpatchable medical devices with their current tools, and between 50 and 70 percent cannot install security agents on them at all. Many run Windows XP, Windows 7, Windows CE, or embedded Linux builds long past end of life. FDA clearance is issued against a specific firmware configuration, so pushing an unqualified patch can take a cleared device outside its certified state.

Treating that as an IT backlog produces a backlog. Treating it as a segmentation and monitoring problem produces a defensible position: isolate the devices, control what they can reach, log what they do, and document the compensating controls in the risk analysis. That documentation is what an OCR investigator or a cyber underwriter will actually ask to see.


What does AI in the exam room change about your risk?


AI documentation tools create a consent exposure that HIPAA compliance does not cover. On April 8, 2026, three California patients filed a proposed class action in the U.S. District Court for the Northern District of California, Washington et al. v. Sutter Health, naming Sutter Health, Memorial Health Services, and MemorialCare Medical Foundation. The complaint alleges an ambient AI scribe captured patient-clinician conversations and transmitted audio to external systems for processing without meaningful informed consent.


The claims run under state law, not HIPAA: California's Confidentiality of Medical Information Act (CMIA) and the California Invasion of Privacy Act (CIPA), the state wiretap statute. That distinction is the whole lesson. A signed BAA and encrypted transport do not resolve a claim that you recorded someone without permission. Any healthcare organization operating across multiple states now has a consent question in every one of them, and the answer is not uniform.


Adoption is outrunning governance. Ambient scribes from Abridge, Nuance DAX, Suki, Nabla, and Ambience Healthcare are in exam rooms across the country, and Athenahealth began offering its ambient scribe free to all customers in February 2026, removing the last cost barrier for hundreds of thousands of providers. Each encounter generates far more PHI than the note that reaches the chart: a live audio stream of the entire visit, an interim transcript, a machine-generated draft, and metadata about the clinician, patient, and visit.


The proposed Security Rule never mentions AI, but its asset inventory and network data-flow mapping requirements land directly on these tools. Practically, AI security in healthcare right now is a governance and contracting discipline rather than a model-security one. A provider handling it competently maintains a living inventory of every AI system touching PHI, holds contract language confirming your data will not train foundation models, and has your patient consent posture reviewed by counsel in each state you operate. Treating the signed BAA as the finish line is the most common failure we see.


What does healthcare incident response require that generic IR does not?


Clinical downtime procedures. An incident response plan that covers only forensics, containment, and breach notification skips the part that determines patient safety: how the organization delivers care with the EHR offline. Average US healthcare ransomware downtime runs roughly 17 to 24 days depending on the dataset, and estimates of downtime cost range from about $900,000 to $1.9 million per day.


Two 2026 incidents show what that means operationally. A ransomware attack on the University of Mississippi Medical Center in February 2026 forced the closure of roughly three dozen clinics and the cancellation of elective procedures for multiple days, according to Associated Press reporting. On April 6, 2026, a cyberattack on Brockton Hospital put its emergency room on ambulance diversion, cancelled chemotherapy infusions at the Greene Cancer Center the next day, and left staff working on paper under downtime procedures for roughly two weeks.


The tactic shift underneath those numbers is what most incident response plans have not caught up to. Sophos found that encryption rates in US healthcare incidents fell to 34 percent in 2025 from 74 percent the prior year, while extortion-only attacks tripled to 12 percent of cases. If the attacker never encrypts anything and simply leaves with the data, your backups are irrelevant to the extortion. Immutable backups solve the availability problem, and availability is increasingly not the problem you have. Your exposure becomes notification timelines, OCR scrutiny, state attorney general filings, class action risk, and the call to your largest referral partner.


The tabletop exercise almost nobody runs is the one worth running: we have all of our systems, and they have all of our data. Who decides whether to pay when there is nothing to decrypt? Who notifies, and on what clock? Which contract governs your forensics firm, and does your incident response retainer actually cover an extortion-only event? Answer those in a conference room now, on a Tuesday, rather than at two in the morning.


Frequently asked questions


Do I need a vCISO if I already pay a managed IT provider?

Usually yes, and for a structural reason rather than a quality one. A managed IT provider is accountable for the systems it operates. A vCISO is accountable for deciding what should be secured, in what order, and for signing the risk analysis that OCR will ask to see. When the same firm both operates and grades your environment, you have a self-review rather than an assessment, and OCR settlements in 2026 turned on the quality of that assessment.


How much do fractional CISO services cost for a healthcare practice?

Mid-market retainers commonly run $3,000 to $12,000 a month depending on hours, scope, and how many entities are covered. Smaller single-site practices often start lower with a scoped risk analysis plus a limited monthly advisory block. For comparison, a full-time healthcare CISO costs $250,000 to $600,000 or more in total compensation. Ask any provider to quote hours per month and named deliverables, not just a monthly figure.


Does HIPAA require my practice to appoint a CISO?

The HIPAA Security Rule requires you to designate a security official responsible for developing and implementing your policies and procedures under 45 CFR 164.308(a)(2). It does not require a full-time CISO or any particular title, and it does not require the person to be an employee. That is exactly the requirement fractional CISO services and vCISO services are built to satisfy for organizations that cannot justify a full-time executive hire.


Will a HIPAA risk analysis satisfy our cyber insurance renewal?

It helps considerably but it is not sufficient on its own. Carriers in 2026 want documented evidence, not attestations: multi-factor authentication enforced across privileged accounts, remote access, email, cloud consoles, and backup interfaces; endpoint detection and response deployed; tested backups; and a written incident response plan. Misrepresentation on the application is grounds for claim denial, and MFA gaps between what was attested and what forensics found remain a leading denial cause. Have the same person who runs your risk analysis review the application before you sign it.


What should I do first if we have never done any of this?

Build an inventory of every system, vendor, cloud service, and device that touches ePHI, including the AI tools your clinicians started using without asking. That inventory is the input to everything else, it is the first thing any competent assessor will request, and it is the requirement most organizations discover they cannot satisfy. Give it two weeks and a named owner before you talk to a single provider.


If you are working out where to start, or comparing vCISO services against a managed provider who has offered to handle security as an add-on, the seven questions above are a reasonable filter to run on your own. Purple Shield Security works with healthcare organizations as an independent security leader with no product resale, no managed service contracts, and no vendor referral fees, which means the recommendation you get is the one we would make if we earned nothing from it. If a second set of eyes on your risk analysis or your vendor exposure would help, that is a conversation worth having.


Sources

 
 
bottom of page