Guide · 12 pages · Published 2025

Healthcare Cybersecurity Guide, 2026

The healthcare breach landscape, Epic-specific security configuration, OCR audit readiness and a healthcare incident response runbook.

What this covers

The organizations that got breached were rarely the ones with no security program. They were the ones with documented gaps in basic controls that were not closed before an attacker found them. This guide works through the recent breach record, the Epic-native security capabilities most organizations under-configure, what OCR looks for in an audit, and a phase-by-phase incident response runbook with Epic-specific actions at each stage.

Key figures

$115M
Anthem settlement after a spear-phishing email exposed 78.8M records, the largest HIPAA settlement at the time
Reported February 2015
$10.22M
average cost of a healthcare data breach in 2025, highest of any industry for 15 years running
IBM Security
275M
healthcare records compromised in the US in 2024, more than 80% of the population
Reported breach totals, 2024
9 days
attacker dwell time before the Change Healthcare encryption event
Incident reporting
79.7%
of healthcare breaches trace to a small set of recurring root causes
Breach root-cause analysis

What is inside

Chapter 1 · The healthcare breach landscape
A dated table of major incidents with root cause, impact and the specific lesson each one carries.
Chapter 2 · Epic-specific security configuration
Maps CFR domains to the Epic-native capability that satisfies them, and names the gap organizations most often leave open.
Chapter 3 · OCR audit readiness
Document by document, what OCR is looking for and the weakness that most often appears in each.
Chapter 4 · Healthcare incident response
Contain, assess, notify, recover, review, with time targets, owners and the Epic-specific action at each phase.
Chapter 5 · Building the operational security program
Moving from a project to a standing program with defined ownership and cadence.

The point most teams miss

Interface trust is a recurring blind spot: if the source IP is trusted, the interface accepts the message. Most healthcare environments have more implicitly trusted inbound paths than their network diagram suggests.

Common questions

What single control gap causes the most damage in healthcare?

The recurring pattern is a known, preventable gap left open. The Change Healthcare breach, which affected an organization processing roughly 40% of all US healthcare claims, traces back to one Citrix portal without multi-factor authentication, with no anomaly detection and no network segmentation to stop lateral movement.

Does Epic provide the security controls needed for HIPAA compliance?

Partly. Epic enforces TLS 1.2 and above for client connections, and HL7 and FHIR API traffic is subject to transport encryption and authentication. The guide maps each CFR domain to the Epic-native capability that addresses it and names the gap organizations most often leave open, which is usually at the third-party interface boundary.

Why are interface connections a recurring blind spot?

Because trust is often implicit: if the source IP is trusted, the interface accepts the message. Most healthcare environments have more implicitly trusted inbound paths than their network diagram suggests.

Get the full document

This page summarizes the guide. The full 12-page PDF includes the complete tables, checklists and worked detail.