Healthcare Cybersecurity: US Amps Up Data Protection with Proposed HIPAA Changes

July 22, 2026

The US Department of Health and Human Services (HHS) is proposing the first major update to the HIPAA Security Rule in over a decade. This move comes in response to a dramatic rise in cyberattacks targeting healthcare systems, including ransomware incidents that have disrupted patient care and exposed millions of sensitive records. The proposed changes aim to strengthen how healthcare organizations protect electronic health information—with new requirements for encryption, multi-factor authentication, and network security controls.

The proposal, published in the Federal Register in January 2025, reflects the reality that the healthcare sector is now one of the most targeted industries for cybercrime. If finalized in 2027, the new rule would require covered entities and their business associates to implement modern cybersecurity practices, including annual penetration testing, incident response planning, and regular audits. These measures are designed to close the gap between outdated security protocols and today’s sophisticated cyber threats.

How Cybercriminals Attack Healthcare Systems

Cyberattacks on healthcare systems often involve ransomware, phishing, and data exfiltration. Ransomware from unpatched software vulnerabilities, network infection, or compromised websites can lock up critical systems often until a ransom is paid, resulting in halted hospital operations and delay of patient care. Phishing attacks trick employees via spam emails to reveal login credentials, which attackers then use to access sensitive systems. Once inside, hackers can steal personal health information, insurance data, and even Social Security numbers.

These attacks can also result in patients being unable to fill prescriptions, access test results, or receive timely care. In some cases, hospitals have had to divert ambulances or cancel surgeries due to system outages caused by cyberattacks.

How Major Cyberattacks Affect the Healthcare Industry

Over the past several years, the healthcare sector has experienced a significant increase in the frequency and severity of data breaches and cyberattacks, underscoring the growing need for robust cybersecurity measures. The February 2024 Change Healthcare ransomware attack is still widely regarded as the most disruptive cyberattack in U.S. healthcare history. In terms of patient data, this attack is also the largest healthcare data breach in US history, affecting approximately 192.7 million individuals. The breach cost the company over $1.6 billion in damages and recovery.

In another major incident, HCA Healthcare suffered a breach in July 2023 that exposed the data of 11 million patients, including appointment details, contact information, and service locations. The stolen data was later posted on a hacking forum, raising concerns about identity theft and fraud.

Kaiser Permanente reported a breach in April 2024 after an employee’s email account was compromised in a phishing attack. The breach affected 13.4 million individuals, exposing sensitive data such as lab results, diagnoses, and insurance information.

Perry Johnson & Associates, a medical transcription service provider, was also targeted in 2024, with hackers accessing the records of 9 million patients across multiple healthcare clients. The breach included names, birthdates, medical histories, and insurance details, highlighting the risks posed by third-party vendors.

In 2025, the US dialysis provider, DaAvita, suffered a ransomware attack that disrupted portions of its operations. The incident ultimately affected approximately 2.69 million individuals, making it one of the largest healthcare data breaches reported that year.

The financial and reputational damage from healthcare data breaches is staggering, as the average 10-year cost of a healthcare data breach has been approximately $7.8 million, the highest of any industry. These costs include ransom payments, legal fees, regulatory fines, lost customers, and the expense of restoring systems and notifying affected individuals.

Beyond the financial toll, breaches erode public trust. Patients expect their health information to be private and secure. When that trust is broken, it can take years to rebuild.

The Cybersecurity Professionals Preventing Healthcare Data Cyberattacks

Although the proposed updates to the HIPAA Security Rule have not yet been finalized, they are intended to significantly strengthen healthcare organizations' ability to prevent, detect, and respond to cyberattacks. The proposed rule would require more robust cybersecurity safeguards, including mandatory multi-factor authentication (MFA), encryption of electronic protected health information (ePHI), regular risk assessments, vulnerability scanning, network segmentation, and comprehensive incident response and disaster recovery plans. 

It would also require healthcare organizations to maintain detailed inventories of technology assets and document how sensitive health data moves throughout their networks. By establishing clearer, more prescriptive cybersecurity requirements, the proposed rule aims to reduce the risk of ransomware attacks, data breaches, and other cyber threats while improving the resilience of healthcare systems and better protecting patient information.

As these proposed changes would take effect, the demand for highly trained cybersecurity professionals in healthcare would also become essential. These professionals help develop and implement comprehensive security strategies that safeguard electronic health records (EHRs), connected medical devices, cloud-based healthcare applications, and hospital networks from evolving threats such as ransomware, phishing, insider threats, and advanced persistent attacks. They conduct vulnerability assessments and risk analyses to identify security gaps, implement layered defenses, and continuously monitor systems to detect suspicious activity before it escalates into a major incident.

Equally important, they promote a culture of cybersecurity awareness by educating physicians, nurses, administrators, and support staff to recognize phishing attempts, protect sensitive information, and follow secure technology practices. Their responsibilities also include ensuring compliance with healthcare regulations and industry standards, conducting security audits, managing third-party vendor risks, and adapting security programs to address emerging technologies such as artificial intelligence, telehealth, cloud computing, and the Internet of Medical Things (IoMT). By combining technical expertise, strategic planning, and proactive risk management, cybersecurity professionals play a vital role in protecting patient privacy, maintaining public trust, and ensuring healthcare organizations can deliver safe, reliable, and uninterrupted patient care in an increasingly complex digital environment.

Cybersecurity Education at Capitol Tech

As threats grow more complex, the healthcare industry faces a shortage of skilled cybersecurity professionals. Implementing the proposed HIPAA changes will require not only new technology but also trained personnel to manage and monitor these systems.

Proudly designated as a National Center of Academic Excellence in Cyber Defense (NCAE-CD) by the NSA, Capitol Technology University is leading the way in cybersecurity education and workforce development. Our BS in Cybersecurity program prepares you to address real-world cyberattacks and develop innovative defense strategies in our evolving, cyber-focused world.

To learn more, contact our Admissions team or request more information.