美国农村医疗卫生面临网络安全问题——CMS资金可以帮助解决那些无人关注的部分
Rural US Healthcare Has A Cybersecurity Problem — CMS Funding Can Help Fix the Part No One Sees
无论你是拥有50名IT员工的大型医疗卫生系统,还是一家小型农村独立医院,勒索软件都可能造成毁灭性后果——窃取记录、转移救护车、延误治疗和日常护理。区别在于能否有效应对。
通过
Rural Health Transformation Program Centers for Medicare & Medicaid Services(CMS)将在五年内向各州拨款500亿美元,其中从2026财年至2030财年每年可提供100亿美元。今年,全部50个州都获得了第一年度拨款,平均约2亿美元,金额从1.47亿美元到2.81亿美元不等。CMS还将技术纳入该项目的设计,包括为数据安全、网络安全、远程护理、互操作性和其他数字健康工具提供资金。
这对农村医疗服务提供者很重要,因为网络安全差距很少是意识问题。大多数农村医院都知道自己面临暴露风险。农村医疗机构面临着许多与大型医疗卫生系统相同的威胁,但它们通常预算更少、IT员工更少、系统更老旧,也较难获得网络安全人才。
Rural Health Information Hub
指出了这些确切问题:资金不足、计算机系统过时、难以招聘网络安全工作人员、培训不均衡,以及难以及时掌握最新警报和响应规划信息。
presented by Sponsored Post Inside an Automated Healthcare Practice: Redesigning Care Around People, Not Paperwork通过减少行政负担并围绕人的需求重新设计工作流程,它为最重要的事情创造了空间:临床医生与患者之间的联系。
作者:Michael Blackman,MD、MBA,Greenway Health®首席医疗官American Hospital Association援引FBI’s 2025 Internet Crime Report称,Healthcare and Public Health是2025年遭受网络威胁攻击最多的关键基础设施行业,向FBI报告了460起勒索软件攻击和182起数据泄露事件。
仅靠资金并不能修补服务器,也不能为夜间警报队列配备人员。不过,资金可以用于农村医疗服务提供者往往难以独立建立的部分:风险评估、端点保护、员工培训、监控、事件响应规划,以及帮助将政策转化为已实施控制措施的支持。
有了CMS资金,各州可以将网络安全从“我们确实应该处理一下”清单中移出,纳入农村卫生投资计划。资金的最佳用途应当是务实的,例如共享网络安全服务、降低风险的准备度评估、人员支持、响应手册,以及实施得足够完善、能够经受压力考验的基本控制措施。这些可能听起来不像戏剧性的变化,但正是农村医院最需要开展的工作。
私营部门在建设这种能力方面发挥着重要作用。农村医院通常无法招聘一支完整的网络安全团队,也无法从零开始建立专业化网络安全项目。外部合作伙伴可以通过提供托管检测、端点保护、准备度评估、培训、手册开发和实施支持来帮助填补这些空缺。成功的衡量标准应当是:医院完成这项工作后,是否具备更强的基本网络安全卫生水平,以及更清晰的改进路径?
Sponsored Post
Where Will AI Deployment Benefit Payers the Most?
我们正在了解健康保险公司如何使用AI、定义成功并管理网络安全风险。请完成我们的简短匿名调查,告诉我们您的看法。
作者:MedCity News
各州的最佳实践重点在于农村卫生规划,将公共资金、私营部门网络安全能力和州属网络安全创新中心连接起来。重点是从准备度入手,衡量控制措施目前所处的状态,并在此基础上帮助组织逐步成熟。
农村医院可以通过采用标准网络安全框架来提升网络安全准备度。该框架从帮助医疗服务提供者了解其安全控制成熟度的准备度评估开始,有助于确定哪些控制措施缺失、哪些已部分到位、哪些可以快速修复,以及哪些需要资金或外部支持。
在这种情况下,获得认可的网络安全框架的价值在于其分级方法。组织可以从围绕基本网络安全卫生的基础准备度开始,随着项目成熟,再逐步迈向更高水平的保证度。全面且适应威胁的控制框架可以协调数十项既有标准和最佳实践。其评估层级通常涵盖基础保证度、适应威胁的保证度,以及更具针对性、控制要求更高的评估。
对于一家农村医院而言,路径是:开展评估,了解差距所在,优先弥补最严重的差距,再次检查,并在组织准备就绪后提升至更高的保证度。对于农村医疗卫生而言,这比将一项全面的安全强制要求直接施加给一家已经在应对人员短缺和基础设施老旧问题的医院,要现实得多。
控制措施还必须具备可执行性。告诉一家农村医院“改善网络安全”并不能让它了解任何具体事项。它们需要知道应保护哪些端点、应收紧哪些访问控制、应监控哪些系统、应正式确定哪些政策,以及如何衡量进展。适应威胁的框架之所以有用,是因为相关工作始终与医院面临的风险相联系,包括网络钓鱼、勒索软件、凭据滥用和系统中断。
证明依据同样重要。在获得认可的网络安全保证框架下运营的组织,其泄露率明显低于没有结构化控制措施的组织。对于任何正在努力提升网络安全准备度的人来说,这一统计数据可能令人振奋,但我们需要明确,这并不意味着每一家开展基础准备度评估的农村医院都会突然变得不可能遭受数据泄露,而是说明这一目标有证据支持。对于使用公共资金的州,应选择一条能够帮助医疗服务提供者衡量当前成熟度,并朝着具有公开成果的保证模型迈进的路径。
这仍然留下了大量艰苦工作。农村医院需要受过培训的人员、经过测试的备份、停机程序、临床连续性规划,以及在警报触发时知道该怎么做的员工。框架无法替代这些工作,但可以帮助组织这些工作,并使进展变得可衡量。
CMS资金为各州提供了帮助农村医院培养这种能力的机会。一次性评估无法让医院实现这一目标;目标应当是建立医院能够长期维持的安全实践。
我们现在的机会是提供这一基础,这也是我向寻求制定类似项目的各州所强调的内容。各州可以利用这笔资金帮助农村医院衡量自身所处的位置,并随着项目成熟,迈向更强的保证度。获得认可的框架为这项工作提供了结构和可衡量的路径。CMS资金为各州提供了一种帮助农村医疗服务提供者开始前进的方式。
农村医院需要能够实施的网络安全措施。它们需要一个起点、一条成熟度路径,以及能够反映小团队和紧张预算现实的支持。如果这笔资金能够帮助农村医疗服务提供者建立这些能力,就将有助于在社区最需要医疗服务时保持护理可及。
图片:marekuliasz,Getty Images Bimal Sheth Bimal Sheth HITRUST执行副总裁,负责标准开发与保证运营,领导HITRUST Framework(HITRUST CSF)和保证项目的开发。他的团队负责研究信息保护实践,通过纳入新的或更新的权威来源来强化该框架,确保HITRUST认证的可靠性,并向HITRUST社区介绍HITRUST Framework(HITRUST CSF)。Bimal的职业生涯一直致力于与组织合作,为其信息保护项目提供保证。
本文通过
MedCity Influencers发布计划。任何人都可以通过 MedCity Influencers 在 MedCity News 上发布自己对医疗卫生领域商业与创新的观点。
点击此处了解详情
Whether you are a large health system with a 50-person IT staff or a small rural independent hospital, ransomware can be devastating — stealing records, diverting ambulances, delaying treatments and day-to-day care. The difference is in the ability to respond effectively.
With the
Rural Health Transformation Program, the Centers for Medicare & Medicaid Services (CMS) is sending $50 billion to states over five years, with $10 billion available each year from fiscal year 2026 through 2030. All 50 states received first-year awards this year, averaging about $200 million and ranging from $147 million to $281 million. CMS also made technology part of the program’s design, including funding for data security, cybersecurity, remote care, interoperability, and other digital health tools.
For rural providers, that matters because the cybersecurity gap is rarely about awareness. Most rural hospitals know they are exposed. Rural facilities face many of the same threats as larger health systems, but they often have smaller budgets, fewer IT staff, older systems, and limited access to cybersecurity talent. The Rural Health Information Hub points to those exact problems: insufficient funding, outdated computer systems, difficulty hiring cyber staff, uneven training, and limited ability to stay current on alerts and response planning.
By Michael Blackman, MD, MBA Chief Medical Officer, Greenway Health® The American Hospital Association, citing the FBI’s 2025 Internet Crime Report, said Healthcare and Public Health was the top critical infrastructure sector targeted for cyberthreats in 2025, with 460 ransomware attacks and 182 data breaches reported to the FBI.
Funding alone won’t patch servers or staff an overnight alert queue. It can, however, pay for the pieces rural providers often struggle to build on their own: risk assessments, endpoint protection, staff training, monitoring, incident response planning, and help translating policy into controls that are implemented.
With the CMS funding, states can take cybersecurity off the “we should really get to that” list and into a rural health investment plan. The best use of the money will be practical, such as shared cybersecurity services, risk-reduction readiness assessments, workforce support, response playbooks, and basic controls that are implemented well enough to hold up under pressure. Those may not sound like dramatic changes, but they are the work rural hospitals need most.
The private sector has an important role in building that capacity. Rural hospitals often cannot hire a full cybersecurity team or build specialized cyber programs from scratch. Outside partners can help fill those gaps by providing managed detection, endpoint protection, readiness assessments, training, playbook development, and implementation support. The measure of success should be: does the hospital come out of the work with stronger basic cyber hygiene and a clearer path to improve?
Sponsored Post
Where Will AI Deployment Benefit Payers the Most?
We are taking a look at how health insurers are using AI, defining success, and managing cybersecurity risks. Give us your opinions by completing our brief, anonymous survey.
By MedCity News
The best practice among states centers around rural health planning connecting public funding, private-sector cyber capability, and state-affiliated cyber innovation centers. The focus is to start with readiness, measure where controls stand and help organizations mature from there.
This is where rural hospitals can improve their cyber readiness by employing a standard cybersecurity framework. Starting with a readiness assessment that helps the provider understand its security control maturity, this framework helps identify which controls are missing, which are partially in place, which can be fixed quickly, and which need funding or outside support.
The value of a recognized cybersecurity framework in this setting is the tiered approach. Organizations can start with foundational readiness around basic cyber hygiene, then move toward higher levels of assurance as their programs mature. A comprehensive, threat-adaptive control framework can harmonize dozens of established standards and best practices. Its assessment tiers typically span foundational assurance, threat-adaptive assurance, and a more tailored, higher-control assessment.
For a rural hospital, the path is: run an assessment, see where the gaps are, close the worst ones, check again, and move to higher assurance when the organization is ready. This is a much more realistic model for rural healthcare than dropping a full-scale security mandate on a hospital that is already fighting staffing shortages and old infrastructure.
The controls also need to be actionable. Telling a rural hospital to “improve cybersecurity” tells them nothing. They need to know which endpoints to protect, which access controls to tighten, which systems to monitor, which policies to formalize, and how progress will be measured. A threat-adaptive framework is useful because the work stays tied to the risks hospitals are facing, including phishing, ransomware, credential abuse, and system disruption.
The proof point matters too. Organizations operating within a recognized cybersecurity assurance framework r eport significantly lower breach rates than those without structured controls. While this statistic can be exciting for anyone grappling with cyber readiness, we need to be clear that it does not imply that every rural hospital doing a foundational readiness assessment is suddenly breach-proof, but rather the destination has evidence behind it. For a state spending public funds, choose a path that helps providers measure maturity today and move toward an assurance model with published outcomes.
That still leaves plenty of hard work. Rural hospitals need trained people, tested backups, downtime procedures, clinical continuity planning, and staff who know what to do when an alert fires. A framework won’t substitute for that work, but it helps organize it and makes progress measurable.
CMS funding gives states a chance to help rural hospitals build that muscle. A one-time assessment won’t get you there, but rather the goal is security practices a hospital can sustain over time.
Our opportunity now is to provide that foundation, which is what I have emphasized to the states looking to develop similar programs. States can use this funding to help rural hospitals measure where they are and move toward stronger assurance as their programs mature. A recognized framework gives that work a structure and a measurable path. The CMS funding gives states a way to help rural providers start moving.
Rural hospitals need cybersecurity they can implement. They need a starting point, a maturity path, and support that reflects the reality of small teams and stretched budgets. If this funding helps rural providers build those capabilities, it will help keep care available when communities need it most.
Photo: marekuliasz, Getty Images Bimal Sheth Bimal Sheth HITRUST Executive Vice President, Standards Development & Assurance Operations, leads the development of the HITRUST Framework (HITRUST CSF) and assurance program. His teams are responsible for conducting research on information protection practices, enhancing the framework by incorporating new or updated authoritative sources, ensuring the reliability of HITRUST certifications, and educating the HITRUST community about the HITRUST Framework (HITRUST CSF). Bimal has spent his career working with organizations to provide assurances over their information protection programs.
This post appears through the MedCity Influencers program. Anyone can publish their perspective on business and innovation in healthcare on MedCity News through MedCity Influencers.
Click here to find out how