TRANSMISSION ACTIVE
// FREQ: HEALTHCARE EPISODE: 025 STATUS: SECURE

025 Data Extortion, Credential Attacks, and the New HIPAA Security Rule Every Executive Must Know

Ransomware evolved. Attackers stopped just encrypting your data and started stealing it first — which means your backups restore your operations while your patient records are already being sold. And they're not breaking in to do it. They're logging in, using credentials harvested at industrial scale and AI-written phishing that no longer has any of the tells you trained your staff to spot. Healthcare is absorbing 2.3 ransomware attacks a day and has carried the most expensive breaches of any industry for fourteen straight years. The government's response: the first major HIPAA Security Rule overhaul since 2013, which kills the word "addressable" and makes encryption, MFA, and segmentation mandatory. This transmission covers the threat shift, the basics that actually stop it, and what the new rule will require of every covered entity and business associate.

JUMP POINTS //

00:33

Ransomware Evolved: From Encrypt to Steal-and-Extort

The playbook changed. Attackers used to get in, encrypt your data, and collect a ransom — which is why backups and recovery were the answer. Now they steal the data first, then encrypt. You can pay, restore, and still watch your patient records get sold. Backups don’t protect you from a leak.

01:34

They Log In, They Don't Break In

The credential economy feeding the extortion: roughly 24 billion exposed credential records in a single database, and AI-assisted phishing appearing in 40–56% of sampled emails in June 2026. The perimeter isn’t failing — the login is.

03:06

The Lock on the Door — Why This Is Just Social Engineering

Actual draws the physical-security parallel: a lock keeps an honest person honest, but a determined attacker doesn’t pick it — they get your keycard, or they get someone to hold the door. Digital attackers reached the same conclusion. Why break the system when you can borrow a login?

04:25

Go Back to the Basics — What Actually Closes the Gap

Phishing-resistant MFA on every account touching sensitive data (hardware keys or platform authenticators — SMS is no longer sufficient). Know where your sensitive data lives and minimize it. Patch internet-facing systems on a compressed cycle. And the uncomfortable truth: organizations claiming a 30-day patch cycle are often patching every six months to a year.

06:36

The New HIPAA Security Rule — The First Overhaul Since 2013

Healthcare took 2.3 ransomware attacks per day in the first half of 2026 and has had the most expensive breaches of any industry for 14 straight years. Change Healthcare alone reached roughly 192.7 million people. HHS OCR responded with a proposed rule that kills the distinction between “required” and “addressable.”

09:16

What Becomes Mandatory — And Where the Floor Is Too Low

Encryption, MFA, segmentation, annual asset inventory and network map, vulnerability scanning every six months, annual pen testing, and 72-hour critical-system restoration. Our CISO’s honest take: scanning twice a year and testing once a year isn’t sufficient when attackers work daily — and tabletops don’t prove you can restore.

13:05

Three Things Healthcare Should Execute Now

Run the risk analysis and asset inventory — and map data flows, not just topology. Reopen every “addressable” gap you accepted and deferred. Re-paper and actually verify your business associates, including their subcontractors.

// INCOMING SITREP

The episode covers what's changing and why. The companion Sitrep is the readiness roadmap — how to build the data-flow network map everything depends on, how to re-triage the risks you accepted under 'addressable,' and how to verify business associates before the clock starts. Includes direct links to the OCR fact sheet and the full Federal Register text. Read the SITREP dossier.

ACCESS THE BRIEF »

TRANSMISSION LOG //

Two Threat Shifts and One Regulatory Response

This transmission covers two changes in how attackers operate — and the regulatory overhaul those changes provoked.

The first is that ransomware stopped being about ransomware. The second is that attackers largely stopped breaking into networks and started simply logging into them. Together they’ve made healthcare the most expensive target on the board, and they’re the direct reason HHS is rewriting a rulebook that hasn’t been meaningfully updated since 2013.

Ransomware Evolved: They Steal, Then They Extort

The evolution is straightforward, and it’s worth being precise about, because it invalidates a defense most healthcare organizations still rely on.

The old model: an attacker finds a way in, encrypts your data, sends the ransom demand, you pay or you restore, everyone moves on. In that world, backups and recovery capability were the answer. If you could restore, you had leverage.

The new model: they still encrypt — they’re experienced at it and it still works — but first they steal. They exfiltrate your data, and then they ransom you. Which means the backup that used to be your leverage now only solves half the problem. You can restore your systems perfectly and still be facing the threat of your patient data being published or sold.

For a healthcare organization, that distinction is everything. Restoring your EHR doesn’t un-leak 100,000 patient records. The operational recovery and the data breach are now two separate incidents, and only one of them is something you can back up your way out of.

They Log In, They Don’t Break In

The entry vector feeding that extortion machine is credentials.

The raw material is staggering. A single exposed database held roughly 24 billion credential records. That’s the fuel supply. On top of it, AI-assisted phishing appeared in an estimated 40 to 56% of sampled emails in June 2026 — messages with none of the tells that a decade of security awareness training taught your staff to catch. (We covered the AI phishing shift in depth in Episode 023.)

And compounding both: unpatched internet-facing systems. Microsoft’s June 2026 Patch Tuesday was its largest ever at roughly 200 vulnerabilities, including an actively exploited Exchange flaw hijacking Outlook Web Access sessions.

Harvested credentials, AI phishing, and unpatched external systems form what our CISO called the “log in, don’t break in” economy. Once inside, they exfiltrate and extort. Same machine, two doors.

Actual made the parallel that lands hardest for executives: this is physical social engineering, transplanted. A lock on a door keeps an honest person honest. A determined attacker doesn’t usually defeat the lock — as security systems get more sophisticated, they stop trying to break through and instead get your keycard, get your credentials, or get someone to hold the door open. Attackers have done this in the physical world forever. The digital version isn’t a new idea. It’s the same idea, finally applied at scale.

Closing the Gap: Go Back to the Basics

Our CISO’s position here is consistent and worth repeating: the organizations that get breached usually aren’t beaten by exotic techniques. They’re beaten because they never made the basics exceptional.

Phishing-resistant MFA on every account touching sensitive data.

Hardware keys or platform authenticators. SMS-based MFA is no longer sufficient. And the emphasis is on consistency — if you have MFA on most accounts but not all of them, you don’t have MFA. You have a hole with documentation around it.

Know where your sensitive data lives, and minimize it.

You can’t protect what you don’t know about. Inventory your data, discover it, classify it, delete what you don’t need, and encrypt what you keep. This is core data security management, and it does double duty: it shrinks your blast radius. Less data in fewer places means a smaller extortion payload when someone does get in.

Patch internet-facing systems on a compressed cycle.

Here’s the credibility gap our CISO keeps encountering: organizations that report a 30-day patch cycle and, on inspection, are patching every six months to a year. Exploit windows after disclosure are collapsing — the Exchange and PeopleSoft cases prove it. Prioritize anything reachable from the internet, and be honest about what your real cycle is versus your documented one.

The New HIPAA Security Rule: Why It Exists

Now the regulatory side, and the numbers explain the motive.

Healthcare absorbed an average of 2.3 ransomware attacks per day in the first half of 2026. It has carried the most expensive breaches of any industry for fourteen consecutive years — currently around $7.42 million per incident. And the Change Healthcare attack reached roughly 192.7 million individuals, with fallout that included congressional testimony.

At that scale, the government couldn’t keep operating on a rulebook written for a different era. The HIPAA Security Rule dates to the 2013 HIPAA Omnibus Rule and hasn’t been meaningfully modified since. In January 2025, HHS’s Office for Civil Rights published a Notice of Proposed Rulemaking — the first major update in over a decade.

The single most consequential change: the rule eliminates the distinction between “required” and “addressable” implementation specifications.

That word did enormous damage. “Addressable” was widely interpreted as optional — you could convene a meeting, discuss the control, document a decision not to implement it, and consider the obligation satisfied. Under the proposal, nearly everything becomes mandatory with only limited exceptions. You don’t get to address it. You have to do it.

And it reaches beyond providers and plans. Business associates — any vendor that wants to work with a healthcare organization — are squarely in scope.

What Becomes Mandatory

Under the proposal, these move from addressable or absent to required:

  • Encryption of ePHI — nothing new conceptually, but now mandatory
  • Multi-factor authentication — required
  • Network segmentation — required
  • Annual technology asset inventory and network map — maintained and kept current
  • Vulnerability scanning at least every six months
  • Annual penetration testing
  • 72-hour restoration of critical systems after an incident
  • Business associate verification — BAs must confirm safeguards are in place, and subcontractors are pulled directly into scope

Two places our CISO pushed back on the rule’s own floors, and they’re worth hearing:

Scanning twice a year and testing once a year is not enough.

Attackers work against you every day. Checking your systems for vulnerabilities every six months and running a pen test annually is not a continuous posture — it’s a compliance minimum. She advocates for continuous scanning and continuous penetration testing.

Tabletop exercises don’t satisfy a 72-hour restoration requirement.

A tabletop is a conversation. You need functional testing, and it has to be comprehensive — because restoring one system at a time isn’t real life. In an actual incident you’re restoring multiple systems simultaneously, which means you need to know your recovery order and your dependencies before you’re under pressure.

On the asset inventory and network map, one clarification that matters more than it sounds: a network map isn’t just a physical or logical diagram of your systems. You have to map your data flows. Where ePHI originates, travels, rests, and leaves. And yes — documentation is the least popular work in any technical organization, but the tooling exists now, including AI-assisted discovery. The requirement is that it stays current, not that it existed once.

The Bigger Pattern: Prove It, Don’t Just Claim It

This is HIPAA moving from a flexible, “figure out what’s reasonable” model to a prescriptive checklist that looks a lot like CMMC or the private-sector frameworks.

And it’s not just OCR. Every major regulator is heading the same direction — away from wish-based self-attestation, toward requiring actual verification and validation of controls. We covered the business associate agreement dimension back in Episode 019, and the “prove it, don’t just claim it” shift in Episode 023 with CMMC. Healthcare is now on the same trajectory the defense industrial base has been walking.

The reason is the same in both sectors: the gap between the security organizations documented and the security they actually ran turned out to be enormous, and adversaries were living in that gap.

Marching Orders for Healthcare

Run the risk analysis and asset inventory — now.

The new rule mandates an annual technology asset inventory. Do it, and verify it’s actually correct. Check when your network map was last updated and confirm it identifies all your systems and your network traffic — including data flows, not just topology. Tie a real risk analysis to it. This is the foundation everything else in the rule sits on.

Close the addressable gaps you’ve been deferring.

Go pull every risk you formally accepted and moved on from. If the underlying control is now required — encryption, MFA — you need to determine how to implement it, how long it will take, and what it will cost. You no longer have a choice. You have to fund it and get it done, so get the real number in front of finance before the clock starts.

Re-paper and verify your business associates.

This one runs through your contracts team as much as security. Know which BAAs are still active and which are inactive — and make sure the inactive ones are actually pulled from your systems. Then build genuine verification: understand your fourth parties (your BAs’ subcontractors), confirm safeguards, and build the process. Most programs just ask for a SOC 2 and file it. You have a right-to-audit clause — use it. Do a random audit of one of their controls. Something simple, just to see whether they can actually produce evidence when asked.

The Bottom Line

Attackers are choosing to log in rather than break in, stealing data and extorting on the leak. Healthcare happens to be the most expensive target on the board. And the government’s twenty-year-old playbook is being rewritten in response.

Addressable is becoming required. The gap between the security you documented and the security you actually run is no longer a judgment call.

Mission success starts with closing that gap before the rule makes you do it.

Go Deeper: The Readiness Roadmap

This episode covers what’s changing and why. Our companion Sitrep is how you get ready — the operational roadmap behind these marching orders: building the data-flow-level network map the entire rule depends on, the process for re-triaging every risk you accepted under “addressable,” how to run a business associate verification that survives scrutiny, and the current honest status of the rulemaking with direct links to the OCR fact sheet and the full Federal Register text.

Trust but verify your own posture. Run the risk analysis and asset inventory. Close the encryption, MFA, and segmentation gaps. Re-paper your business associates. Execute the standard.

// DECODED TRANSCRIPT

Access the full text logs of this transmission for compliance and review purposes.

SILENCE THE NOISE. AMPLIFY THE SIGNAL.

INTELLIGENCE IS USELESS IF YOU AREN'T LISTENING.

Join The Watch to receive New Episode Alerts, Strategic Breakdowns, and Guest Intel delivered to your inbox.