Healthcare Cybersecurity & Compliance Solutions
Unbreakable Cybersecurity for Healthcare

See how VikingCloud helps covered entities and business associates protect patient data, meet HIPAA Security Rule requirements, and keep care delivery uninterrupted.

Intro

When you handle PHI on behalf of a covered entity, HIPAA Security Rule requirements follow the data directly to you. A security gap in your environment can trigger breach notification obligations for every covered entity client whose data was involved. We give business associates the testing, advisory, and platform expertise needed to protect PHI, satisfy Business Associate Agreement obligations, and demonstrate a defensible security posture to clients who are increasingly scrutinizing their partners.

Security

Our security testing helps business associates identify and close vulnerabilities in the systems, integrations, and data pipelines that handle covered entity PHI, so a gap in your environment doesn’t become a breach notification obligation for your clients.

Asgard Platform®

Our patented, purpose-built platform provides real-time insight and oversight of your cybersecurity status across clinical systems, connected devices, and third-party integrations, with predictive analysis so you can address threats before they escalate.

External Vulnerability Scanning (EVS)

Our cloud-based scanner assesses your internet-facing systems from an attacker’s vantage point, identifying external exposures before they become entry points to covered entity PHI.

Internal Vulnerability Scanning (IVS)

Deployed via virtual or hardware appliance inside your environment, our internal scanning inspects network segments and the systems handling covered entity PHI, with authenticated scans that surface risks perimeter-only scanning misses.

Intrusion Detection & Prevention (IDS/IPS)

VikingCloud monitors networks for malicious activity and policy violations, feeds data to SIEM, and generates HIPAA-ready reports, providing a continuous detection layer between your systems and threat actors.

Managed Next-Generation Firewall

Centralized firewall configuration, rule setting, and patching to prevent unauthorized network access to systems that handle covered entity PHI.

Managed Security Services (MSS)

24x7 monitoring and threat detection. Our security operations team acts as an extension of your staff, watching for threats, correlating events, and responding so your team stays focused on serving your clients.

Penetration Testing

Network, segmentation, and web application testing by our Cyber Threat Unit, certified ethical hackers who scope engagements to maximize coverage while minimizing disruption to care operations.

Security Info & Event Management (SIEM)

VikingCloud collects, analyzes, and correlates security logs across your environment to identify threats and anomalous activity in real time, with outputs that support HIPAA audit requirements.

Threat Detection & Response

Endpoint detection and managed detection & response (MDR) for environments that handle PHI. Engineered to catch sophisticated, fileless, and lateral-movement threats that bypass traditional controls, with rapid containment before they spread.

Compliance

Our compliance and risk services help business associates meet HIPAA Security Rule obligations, satisfy Business Associate Agreement requirements, and demonstrate a defensible security posture to the covered entity clients who increasingly scrutinize their partners.

Asgard Platform®

Our patented, purpose-built platform gives compliance teams real-time visibility, tracks remediation progress, surfaces gaps, and provides the audit-ready documentation HIPAA Security Rule compliance requires.

Breach Notification & Incident Response Support

When a potential PHI breach occurs, our team supports forensic investigation, breach determination under the HIPAA Breach Notification Rule, and required notifications to affected individuals, HHS OCR, and media outlets where applicable.

HIPAA Advisory & Compliance Program Support

Ongoing advisory for business associates building or maturing HIPAA compliance programs. Covers policy development, subcontractor and sub-business-associate agreement management, security safeguards, workforce training, and preparation for the compliance assessments client covered entities increasingly require.

HIPAA Gap Assessment & Remediation Planning

For organizations that have a risk assessment but need help closing the gaps. Our advisors work through your control environment, identify deficiencies against Security Rule requirements, and build a prioritized remediation roadmap.

HIPAA Risk Assessment

A structured evaluation of your security posture against the HIPAA Security Rule’s implementation specifications. We identify gaps, prioritize risk, and produce the documented risk analysis HHS OCR requires across all facilities and systems in scope.

Intro

Protecting complex, distributed environments is our specialty. We give your team a single, real-time view across clinical systems, connected devices, third-party integrations, and remote access infrastructure, with 24x7 access to our security and compliance professionals so clinical and IT teams stay focused on patient care.

Security

Our security testing helps covered entities identify and close vulnerabilities in clinical environments, distributed infrastructure, and third-party integrations before attackers can exploit them.

Asgard Platform®

Our patented, purpose-built platform provides real-time insight and oversight of your cybersecurity status across clinical systems, connected devices, and third-party integrations, with predictive analysis so you can address threats before they escalate.

External Vulnerability Scanning (EVS)

Our cloud-based scanner assesses internet-facing systems like patient portals, web applications, and remote access points from an attacker’s vantage point, identifying external exposures before they become entry points.

Internal Vulnerability Scanning (IVS)

Deployed via virtual or hardware appliance inside your environment, our internal scanning inspects network segments, clinical systems, and connected medical devices, with authenticated scans that surface risks perimeter-only scanning misses.

Intrusion Detection & Prevention (IDS/IPS)

VikingCloud monitors networks for malicious activity and policy violations, feeds data to SIEM, and generates HIPAA-ready reports, providing a continuous detection layer between your systems and threat actors.

Managed Next-Generation Firewall

Centralized firewall configuration, rule setting, and patching to prevent unauthorized network access, including the clinical/administrative segmentation HIPAA’s technical safeguards require.

Managed Security Services (MSS)

24x7 monitoring and threat detection. Our security operations team acts as an extension of your staff, watching for threats, correlating events, and responding so your clinical and IT teams stay focused on patient care.

Penetration Testing

Network, segmentation, and web application testing by our Cyber Threat Unit, certified ethical hackers who scope engagements to maximize coverage while minimizing disruption to care operations.

Security Info & Event Management (SIEM)

VikingCloud collects, analyzes, and correlates security logs across your environment to identify threats and anomalous activity in real time, with outputs that support HIPAA audit requirements.

Threat Detection & Response

Endpoint detection and managed detection & response (MDR) for healthcare environments. Engineered to catch sophisticated, fileless, and lateral-movement threats that bypass traditional controls, with rapid containment before they spread.

Compliance

Our compliance and risk services help covered entities meet HIPAA Security Rule requirements for risk analysis, risk management, and security program documentation, building a defensible posture that holds up to HHS OCR scrutiny.

Asgard Platform®

Our patented, purpose-built platform gives compliance teams real-time visibility, tracks remediation progress, surfaces gaps, and provides the audit-ready documentation HIPAA Security Rule compliance requires.

Breach Notification & Incident Response Support

When a potential PHI breach occurs, our team supports forensic investigation, breach determination under the HIPAA Breach Notification Rule, and required notifications to affected individuals, HHS OCR, and media outlets where applicable.

HIPAA Advisory & Compliance Program Support

Ongoing advisory for covered entities building or maturing HIPAA compliance programs. Covers policy development, administrative safeguards, Business Associate Agreement review, workforce training, and HHS OCR audit preparation.

HIPAA Gap Assessment & Remediation Planning

For organizations that have a risk assessment but need help closing the gaps. Our advisors work through your control environment, identify deficiencies against Security Rule requirements, and build a prioritized remediation roadmap.

HIPAA Risk Assessment

A structured evaluation of your security posture against the HIPAA Security Rule’s implementation specifications. We identify gaps, prioritize risk, and produce the documented risk analysis HHS OCR requires across all facilities and systems in scope.

Headquarters
Remote Sites

Healthcare Cybersecurity

Unbreakable Cybersecurity for Healthcare

VikingCloud’s healthcare cybersecurity and compliance services work alongside your team to identify vulnerabilities, strengthen HIPAA Security Rule readiness, and keep your environment protected, so you can focus on what matters most: your patients and customers.

Your trusted cybersecurity defense partner.

#1

most expensive industry for data breaches, 12 consecutive years.

270+ million

patient records exposed in reported breaches.

$7.42 million

average cost of a healthcare data breach.

Cybersecurity for Healthcare

Protecting patients. Preserving trust.

Cybersecurity & compliance that simply works.

Healthcare manages some of the most sensitive data, across an ecosystem that grows more complex every year. From EHR platforms and revenue cycle systems to remote patient monitoring and third-party cloud services, every connection creates exposure. The numbers reflect it: healthcare has led every industry in data breach costs for more than a decade.

VikingCloud helps covered entities and business associates identify vulnerabilities, strengthen security posture, and navigate HIPAA Security Rule requirements, all from one expert partner. So your clinical and IT teams can stay focused on patient care while we focus on keeping it protected.

Key cybersecurity threats healthcare organizations can’t ignore:

  • Exposed electronic protected health information (ePHI) across EHR systems, patient portals, telehealth platforms, and connected medical devices.
  • Ransomware attacks that disrupt operations, delay care, compromise patient safety, and trigger mandatory HHS OCR breach notification.
  • Third-party and business associate risk introduced through billing platforms, cloud hosting providers, EHR integrations, and other vendors that touch your data.
  • Growing HIPAA Security Rule obligations include proposed updates to risk analysis, access controls, and incident response requirements that covered entities and business associates must prepare for now.

VikingCloud closes the gaps so you can protect your systems, your patients’ data, and your ability to deliver care.

Who we serve across the healthcare industry.

VikingCloud's healthcare cybersecurity and compliance services are calibrated for the distinct risk and regulatory profiles of every segment of the healthcare ecosystem.

Hospitals & health systems.

Multi-facility environments with thousands of clinical workstations, connected medical devices, and third-party integrations. We help health systems validate segmentation between clinical and administrative networks, improve visibility into the security and compliance status, and maintain a defensible HIPAA Security Rule posture across every facility in scope.

Ambulatory & physician practices.

Outpatient clinics, specialty practices, and physician groups face the same HIPAA obligations as large health systems with a fraction of the in-house security resources. We deliver right-sized risk assessments, vulnerability management, and penetration testing services that meet OCR requirements without overwhelming clinical staff.

Health insurers & payers.

Health plans hold some of the largest concentrations of PHI in the healthcare industry and are subject to both HIPAA and state-level insurance regulations. Our services support risk analysis, privacy data mapping, safeguards and control reviews, as well as continuous security testing across the claims processing, member portal, and broker-facing systems that handle member data.

Pharma & biotech.

Pharmaceutical and biotech organizations sit at the intersection of HIPAA, FDA cybersecurity guidance, and intellectual property protection. We help organizations build a program to protect clinical trial data, research environments, and patient-facing programs while supporting the HIPAA obligations that apply when handling protected health information.

Healthtech & digital health.

Digital health platforms, telehealth providers, RPM vendors, and healthcare SaaS companies are almost always business associates, and their covered entity clients are increasingly scrutinizing their security posture. We help HealthTech companies build, mature, and document the security program required by business associate agreements and that are increasingly demanded for customer due diligence and SOC 2 assessments.

Medical device manufacturers.

Connected device makers face cybersecurity requirements across the full product lifecycle, including FDA pre and post market guidance, SBOM expectations, and vulnerability disclosure obligations. We support advisory, assessments, and security testing for organizational risk evaluation and to validate the effectiveness of HIPAA security programs that device manufacturers need when their products handle or transmit PHI.

Healthcare industry cybersecurity & compliance infographics.

See how VikingCloud helps covered entities and business associates protect patient data, meet HIPAA Security Rule requirements, and keep care delivery uninterrupted.

Intro

When you handle PHI on behalf of a covered entity, HIPAA Security Rule requirements follow the data directly to you. A security gap in your environment can trigger breach notification obligations for every covered entity client whose data was involved. We give business associates the testing, advisory, and platform expertise needed to protect PHI, satisfy Business Associate Agreement obligations, and demonstrate a defensible security posture to clients who are increasingly scrutinizing their partners.

Security

Our security testing helps business associates identify and close vulnerabilities in the systems, integrations, and data pipelines that handle covered entity PHI, so a gap in your environment doesn’t become a breach notification obligation for your clients.

Asgard Platform®

Our patented, purpose-built platform provides real-time insight and oversight of your cybersecurity status across clinical systems, connected devices, and third-party integrations, with predictive analysis so you can address threats before they escalate.

External Vulnerability Scanning (EVS)

Our cloud-based scanner assesses your internet-facing systems from an attacker’s vantage point, identifying external exposures before they become entry points to covered entity PHI.

Internal Vulnerability Scanning (IVS)

Deployed via virtual or hardware appliance inside your environment, our internal scanning inspects network segments and the systems handling covered entity PHI, with authenticated scans that surface risks perimeter-only scanning misses.

Intrusion Detection & Prevention (IDS/IPS)

VikingCloud monitors networks for malicious activity and policy violations, feeds data to SIEM, and generates HIPAA-ready reports, providing a continuous detection layer between your systems and threat actors.

Managed Next-Generation Firewall

Centralized firewall configuration, rule setting, and patching to prevent unauthorized network access to systems that handle covered entity PHI.

Managed Security Services (MSS)

24x7 monitoring and threat detection. Our security operations team acts as an extension of your staff, watching for threats, correlating events, and responding so your team stays focused on serving your clients.

Penetration Testing

Network, segmentation, and web application testing by our Cyber Threat Unit, certified ethical hackers who scope engagements to maximize coverage while minimizing disruption to care operations.

Security Info & Event Management (SIEM)

VikingCloud collects, analyzes, and correlates security logs across your environment to identify threats and anomalous activity in real time, with outputs that support HIPAA audit requirements.

Threat Detection & Response

Endpoint detection and managed detection & response (MDR) for environments that handle PHI. Engineered to catch sophisticated, fileless, and lateral-movement threats that bypass traditional controls, with rapid containment before they spread.

Compliance

Our compliance and risk services help business associates meet HIPAA Security Rule obligations, satisfy Business Associate Agreement requirements, and demonstrate a defensible security posture to the covered entity clients who increasingly scrutinize their partners.

Asgard Platform®

Our patented, purpose-built platform gives compliance teams real-time visibility, tracks remediation progress, surfaces gaps, and provides the audit-ready documentation HIPAA Security Rule compliance requires.

Breach Notification & Incident Response Support

When a potential PHI breach occurs, our team supports forensic investigation, breach determination under the HIPAA Breach Notification Rule, and required notifications to affected individuals, HHS OCR, and media outlets where applicable.

HIPAA Advisory & Compliance Program Support

Ongoing advisory for business associates building or maturing HIPAA compliance programs. Covers policy development, subcontractor and sub-business-associate agreement management, security safeguards, workforce training, and preparation for the compliance assessments client covered entities increasingly require.

HIPAA Gap Assessment & Remediation Planning

For organizations that have a risk assessment but need help closing the gaps. Our advisors work through your control environment, identify deficiencies against Security Rule requirements, and build a prioritized remediation roadmap.

HIPAA Risk Assessment

A structured evaluation of your security posture against the HIPAA Security Rule’s implementation specifications. We identify gaps, prioritize risk, and produce the documented risk analysis HHS OCR requires across all facilities and systems in scope.

Intro

Protecting complex, distributed environments is our specialty. We give your team a single, real-time view across clinical systems, connected devices, third-party integrations, and remote access infrastructure, with 24x7 access to our security and compliance professionals so clinical and IT teams stay focused on patient care.

Security

Our security testing helps covered entities identify and close vulnerabilities in clinical environments, distributed infrastructure, and third-party integrations before attackers can exploit them.

Asgard Platform®

Our patented, purpose-built platform provides real-time insight and oversight of your cybersecurity status across clinical systems, connected devices, and third-party integrations, with predictive analysis so you can address threats before they escalate.

External Vulnerability Scanning (EVS)

Our cloud-based scanner assesses internet-facing systems like patient portals, web applications, and remote access points from an attacker’s vantage point, identifying external exposures before they become entry points.

Internal Vulnerability Scanning (IVS)

Deployed via virtual or hardware appliance inside your environment, our internal scanning inspects network segments, clinical systems, and connected medical devices, with authenticated scans that surface risks perimeter-only scanning misses.

Intrusion Detection & Prevention (IDS/IPS)

VikingCloud monitors networks for malicious activity and policy violations, feeds data to SIEM, and generates HIPAA-ready reports, providing a continuous detection layer between your systems and threat actors.

Managed Next-Generation Firewall

Centralized firewall configuration, rule setting, and patching to prevent unauthorized network access, including the clinical/administrative segmentation HIPAA’s technical safeguards require.

Managed Security Services (MSS)

24x7 monitoring and threat detection. Our security operations team acts as an extension of your staff, watching for threats, correlating events, and responding so your clinical and IT teams stay focused on patient care.

Penetration Testing

Network, segmentation, and web application testing by our Cyber Threat Unit, certified ethical hackers who scope engagements to maximize coverage while minimizing disruption to care operations.

Security Info & Event Management (SIEM)

VikingCloud collects, analyzes, and correlates security logs across your environment to identify threats and anomalous activity in real time, with outputs that support HIPAA audit requirements.

Threat Detection & Response

Endpoint detection and managed detection & response (MDR) for healthcare environments. Engineered to catch sophisticated, fileless, and lateral-movement threats that bypass traditional controls, with rapid containment before they spread.

Compliance

Our compliance and risk services help covered entities meet HIPAA Security Rule requirements for risk analysis, risk management, and security program documentation, building a defensible posture that holds up to HHS OCR scrutiny.

Asgard Platform®

Our patented, purpose-built platform gives compliance teams real-time visibility, tracks remediation progress, surfaces gaps, and provides the audit-ready documentation HIPAA Security Rule compliance requires.

Breach Notification & Incident Response Support

When a potential PHI breach occurs, our team supports forensic investigation, breach determination under the HIPAA Breach Notification Rule, and required notifications to affected individuals, HHS OCR, and media outlets where applicable.

HIPAA Advisory & Compliance Program Support

Ongoing advisory for covered entities building or maturing HIPAA compliance programs. Covers policy development, administrative safeguards, Business Associate Agreement review, workforce training, and HHS OCR audit preparation.

HIPAA Gap Assessment & Remediation Planning

For organizations that have a risk assessment but need help closing the gaps. Our advisors work through your control environment, identify deficiencies against Security Rule requirements, and build a prioritized remediation roadmap.

HIPAA Risk Assessment

A structured evaluation of your security posture against the HIPAA Security Rule’s implementation specifications. We identify gaps, prioritize risk, and produce the documented risk analysis HHS OCR requires across all facilities and systems in scope.

Covered Entity
Business Associate

Designed specifically for the healthcare industry.

VikingCloud's cybersecurity and compliance solutions are built for the complexity of healthcare, giving covered entities and business associates the expertise, testing, and compliance services they need to protect patient data and meet HIPAA Security Rule requirements.
Expert HIPAA advisory and risk assessment services that build a defensible, audit-ready compliance posture.
Privacy data mapping to document how PHI moves across systems, integrations, and business associate relationships, giving you the visibility your risk analysis requires.
Gap assessments that identify where your controls fall short of HIPAA Security Rule requirements, with a prioritized remediation roadmap to close them.
External and internal vulnerability scanning calibrated to healthcare environments, identifying and prioritizing weaknesses across clinical systems, patient portals, and connected infrastructure.
Penetration testing across internal networks, external perimeters, and segmentation boundaries, validating the controls separating your clinical and administrative environments hold.
Access our unified, AI-powered Asgard Platform® for real-time visibility across your security posture and compliance status, without requiring extensive in-house cybersecurity expertise.
ON DEMAND WEBINAR

NIS2 & The Travel Industry
What you need to Know

Discover how the EU’s new cybersecurity rules are reshaping how travel companies operate across Europe.

Hosted by
In Partnership
with VikingCloud

Securing connected medical devices and the IoMT footprint.

The Internet of Medical Things has expanded the attack surface of every healthcare organization. Infusion pumps, imaging systems, patient monitors, and bedside diagnostic devices increasingly run on outdated firmware, legacy operating systems, and protocols that were never designed for a hostile network. When these devices share infrastructure with clinical, administrative, and patient-facing systems, a single compromised device can become the entry point to your entire environment.

VikingCloud helps covered entities and business associates identify, segment, and protect connected medical devices in a way that aligns with HIPAA Security Rule technical safeguards and reduces the risk of clinical disruption.

Network segmentation testing.

Segmentation between clinical, administrative, and biomedical networks is one of the most important controls in a healthcare environment, and one of the most frequently misconfigured. Our segmentation testing validates that the boundaries separating connected medical devices from the rest of your infrastructure actually hold under attacker conditions.

Vulnerability scanning for clinical networks.

External scanning identifies exposures on internet-facing assets like patient portals, telehealth platforms, and vendor remote-access points. Internal scanning, authenticated and unauthenticated, finds exposures across the network segments where medical devices live, including legacy systems that can't be patched and vendor-managed equipment that often sits outside IT's direct control.

Penetration testing for healthcare infrastructure.

Our Cyber Threat Unit scopes engagements specifically for clinical environments, validating that an attacker with initial network access can't pivot to medical devices, EHR systems, or patient data. Engagements are designed to maximize coverage while minimizing disruption to active care delivery.

Continuous monitoring and detection.

Managed Detection & Response, SIEM, and IDS/IPS extend visibility into the network segments where medical devices operate, surfacing the lateral movement, command-and-control activity, and anomalous device behavior that indicate compromise.

Case Studies

Read our case studies to find out how VikingCloud helps businesses across diverse industries to overcome Cybersecurity and PCI Compliance challenges.

Our case studies showcase real-world success—where proactive protection meets seamless operations—keeping businesses secure, compliant, and uninterrupted.

Why VikingCloud?

Industry expertise.

Decades of experience in delivering tailored cybersecurity solutions for the healthcare sector.

Proven results.

Trusted by leading brands to safeguard their digital and physical assets.

Cutting-edge technology.

Leveraging AI and machine learning for smarter threat detection and response.

Compliance support.

Ensure adherence to regulations like HIPAA and PCI DSS while simplifying audits and assessments.

End-to-end protection.

Comprehensive solutions covering every aspect of healthcare cybersecurity.

Partnership approach.

Dedicated experts to guide you through every step of securing your business.
A GLOBAL LEADER

Our unbeatable capabilities.

One-stop partner.

Streamlined cybersecurity & compliance protection in one integrated solution.

Leading AI-powered platform.

Asgard Platform®: The industry’s largest AI-powered cybersecurity & compliance data repository designed to help make informed, predictive, & cost-effective risk mitigation decisions - faster.

Fast & specialized 24x7 support.

Speed matters in cybersecurity & compliance.

Discover why millions of businesses choose VikingCloud.

We just finished our annual compliance audit and confirmed that all high-priority risks from the last year had been mitigated. We owe much of this successful transformation to VikingCloud.
,
Cybersecurity Lead
California-based Regional Health Care System

Datasheets

Get more details on VikingCloud’s suite of cybersecurity and compliance services.

Healthcare FAQs

What is healthcare cybersecurity?

Healthcare cybersecurity is the practice of protecting patient data, clinical systems, connected medical devices, and the infrastructure healthcare organizations rely on to deliver care. It combines technical controls like vulnerability scanning, penetration testing, and threat detection with regulatory compliance work tied to the HIPAA Security Rule and, for organizations that handle payment data, PCI DSS.

Why is cybersecurity so important in healthcare?

Healthcare has been the most expensive industry for data breaches for thirteen consecutive years, with an average breach cost of $10.3 million. Beyond financial loss, a successful attack can disrupt clinical operations, delay treatment, and put patient safety at direct risk — which is why cybersecurity in healthcare is treated as a patient safety issue, not just an IT issue.

What does the HIPAA Security Rule require?

The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Core requirements include a documented risk analysis, a risk management process, access controls, audit logging, transmission security, and incident response capabilities. Proposed updates to the rule are expanding requirements around encryption, multi-factor authentication, and asset inventory.

What's the difference between a covered entity and a business associate?

A covered entity is a healthcare provider, health plan, or healthcare clearinghouse that handles protected health information directly. A business associate is any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity — including billing services, cloud hosting providers, EHR integrators, analytics platforms, and many other third-party vendors. Both are directly liable for HIPAA compliance, and both must sign a Business Associate Agreement (BAA) defining their respective responsibilities.

How often should a HIPAA risk assessment be done?

HHS OCR requires covered entities and business associates to conduct a risk analysis on a regular basis, with most healthcare cybersecurity practitioners recommending an annual cadence at minimum. A new risk assessment should also be triggered by material changes to the environment: new systems, mergers and acquisitions, significant infrastructure migrations, new business associate relationships, or following any reportable security incident.

What are the most common cybersecurity threats facing healthcare organizations?

Ransomware remains the most disruptive, frequently entering through phishing, exposed remote access, or compromised business associates. Other recurring threats include exposed ePHI across patient portals and telehealth platforms, attacks against connected medical devices, third-party and supply chain compromise, and insider threats from workforce members with broad access to clinical systems.

How can hospitals and health systems prevent ransomware attacks?

Effective ransomware prevention combines vulnerability management, network segmentation, endpoint detection and response, managed security monitoring, immutable backups, and a tested incident response plan. Because most ransomware attacks begin with a phishing email or an exposed remote access point, ongoing workforce training and continuous external attack surface monitoring are critical complements to the technical controls.

Do business associates need their own cybersecurity program?

Yes. The HIPAA Security Rule applies directly to business associates, and a security gap in a business associate's environment can trigger breach notification obligations for every covered entity client whose data was involved. Covered entities are also increasingly requiring evidence of a mature security program — including independent risk assessments and pen testing — before signing or renewing a BAA.