Home HealthRural US Healthcare Has A Cybersecurity Problem — CMS Funding Can Help Fix the Part No One Sees

Rural US Healthcare Has A Cybersecurity Problem — CMS Funding Can Help Fix the Part No One Sees

by Staff Reporter
0 comments

Whether you are a large health system with a 50-person IT staff or a small rural independent hospital, ransomware can be devastating — stealing records, diverting ambulances, delaying treatments and day-to-day care. The difference is in the ability to respond effectively. 

With the Rural Health Transformation Program, the Centers for Medicare & Medicaid Services (CMS) is sending $50 billion to states over five years, with $10 billion available each year from fiscal year 2026 through 2030. All 50 states received first-year awards this year, averaging about $200 million and ranging from $147 million to $281 million. CMS also made technology part of the program’s design, including funding for data security, cybersecurity, remote care, interoperability, and other digital health tools.

For rural providers, that matters because the cybersecurity gap is rarely about awareness. Most rural hospitals know they are exposed. Rural facilities face many of the same threats as larger health systems, but they often have smaller budgets, fewer IT staff, older systems, and limited access to cybersecurity talent. The Rural Health Information Hub points to those exact problems: insufficient funding, outdated computer systems, difficulty hiring cyber staff, uneven training, and limited ability to stay current on alerts and response planning.

The American Hospital Association, citing the FBI’s 2025 Internet Crime Report, said Healthcare and Public Health was the top critical infrastructure sector targeted for cyberthreats in 2025, with 460 ransomware attacks and 182 data breaches reported to the FBI.

Funding alone won’t patch servers or staff an overnight alert queue. It can, however, pay for the pieces rural providers often struggle to build on their own: risk assessments, endpoint protection, staff training, monitoring, incident response planning, and help translating policy into controls that are implemented.

With the CMS funding, states can take cybersecurity off the “we should really get to that” list and into a rural health investment plan. The best use of the money will be practical, such as shared cybersecurity services, risk-reduction readiness assessments, workforce support, response playbooks, and basic controls that are implemented well enough to hold up under pressure. Those may not sound like dramatic changes, but they are the work rural hospitals need most.

The private sector has an important role in building that capacity. Rural hospitals often cannot hire a full cybersecurity team or build specialized cyber programs from scratch. Outside partners can help fill those gaps by providing managed detection, endpoint protection, readiness assessments, training, playbook development, and implementation support. The measure of success should be: does the hospital come out of the work with stronger basic cyber hygiene and a clearer path to improve?

​The best practice among states centers around rural health planning connecting public funding, private-sector cyber capability, and state-affiliated cyber innovation centers. The focus is to start with readiness, measure where controls stand and help organizations mature from there.

This is where rural hospitals can improve their cyber readiness by employing a standard cybersecurity framework. Starting with a readiness assessment that helps the provider understand its security control maturity, this framework helps identify which controls are missing, which are partially in place, which can be fixed quickly, and which need funding or outside support.

The value of a recognized cybersecurity framework in this setting is the tiered approach. Organizations can start with foundational readiness around basic cyber hygiene, then move toward higher levels of assurance as their programs mature. A comprehensive, threat-adaptive control framework can harmonize dozens of established standards and best practices. Its assessment tiers typically span foundational assurance, threat-adaptive assurance, and a more tailored, higher-control assessment.

For a rural hospital, the path is: run an assessment, see where the gaps are, close the worst ones, check again, and move to higher assurance when the organization is ready. This is a much more realistic model for rural healthcare than dropping a full-scale security mandate on a hospital that is already fighting staffing shortages and old infrastructure.

The controls also need to be actionable. Telling a rural hospital to “improve cybersecurity” tells them nothing. They need to know which endpoints to protect, which access controls to tighten, which systems to monitor, which policies to formalize, and how progress will be measured. A threat-adaptive framework is useful because the work stays tied to the risks hospitals are facing, including phishing, ransomware, credential abuse, and system disruption.

The proof point matters too. Organizations operating within a recognized cybersecurity assurance framework report significantly lower breach rates than those without structured controls. While this statistic can be exciting for anyone grappling with cyber readiness, we need to be clear that it does not imply that every rural hospital doing a foundational readiness assessment is suddenly breach-proof, but rather the destination has evidence behind it. For a state spending public funds, choose a path that helps providers measure maturity today and move toward an assurance model with published outcomes.

That still leaves plenty of hard work. Rural hospitals need trained people, tested backups, downtime procedures, clinical continuity planning, and staff who know what to do when an alert fires. A framework won’t substitute for that work, but it helps organize it and makes progress measurable.

CMS funding gives states a chance to help rural hospitals build that muscle. A one-time assessment won’t get you there, but rather the goal is security practices a hospital can sustain over time.

Our opportunity now is to provide that foundation, which is what I have emphasized to the states looking to develop similar programs. States can use this funding to help rural hospitals measure where they are and move toward stronger assurance as their programs mature. A recognized framework gives that work a structure and a measurable path. The CMS funding gives states a way to help rural providers start moving.

Rural hospitals need cybersecurity they can implement. They need a starting point, a maturity path, and support that reflects the reality of small teams and stretched budgets. If this funding helps rural providers build those capabilities, it will help keep care available when communities need it most.

Photo: marekuliasz, Getty Images


Bimal Sheth, HITRUST Executive Vice President, Standards Development & Assurance Operations, leads the development of the HITRUST Framework (HITRUST CSF) and assurance program. His teams are responsible for conducting research on information protection practices, enhancing the framework by incorporating new or updated authoritative sources, ensuring the reliability of HITRUST certifications, and educating the HITRUST community about the HITRUST Framework (HITRUST CSF). Bimal has spent his career working with organizations to provide assurances over their information protection programs.

This post appears through the MedCity Influencers program. Anyone can publish their perspective on business and innovation in healthcare on MedCity News through MedCity Influencers. Click here to find out how.

You may also like

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More