Nursing Home Cybersecurity: Notable Incidents and a 2026 Action Plan
Why nursing homes need cybersecurity in 2026: real breach incidents, HIPAA enforcement, and a practical MDR and incident response action plan.
By CyberReplay Security Team
TL;DR: Nursing homes hold the same protected health information as hospitals but with a fraction of the security staff, making them a top 2026 ransomware target. The fix is multi-factor authentication on every privileged account, endpoint detection and response, segmented networks, and a tested incident response runbook - not more compliance paperwork.
Table of contents
- What you will learn
- Quick answer
- When this matters
- Definitions
- The complete guide to nursing home cybersecurity
- Notable incidents
- What regulators now expect
- The 10 controls (HHS HICP)
- A 90-day implementation plan
- Handling the most common objections
- Common mistakes
- What should we do next?
- How much does nursing home cybersecurity cost?
- Is HIPAA enough to stop ransomware?
- Can a small facility afford managed detection and response?
- References
- Get your free security assessment
- Next step
- FAQ
What you will learn
- Why nursing homes are now a preferred ransomware target in 2026.
- The real cost of inaction, using 2024 and 2025 incident data.
- The 10 HHS HICP controls that reduce breach likelihood and impact.
- A 90-day implementation plan a small facility can actually execute.
- How to handle the objections that stall security programs.
Quick answer
Nursing home cybersecurity means protecting resident protected health information, medical devices, and business systems from ransomware and data theft. The highest-impact first moves are phishing-resistant MFA on every privileged and remote account, EDR on every endpoint, network segmentation, offline or immutable backups, and a tested incident response runbook. Facilities that implement these controls can shrink detection from months to hours and avoid the average $9.77 million healthcare breach cost.
When this matters
Nursing homes are covered entities under HIPAA and hold the same protected health information as hospitals - names, Social Security numbers, dates of birth, diagnoses, and treatment records. They run 24/7 clinical operations on thin IT teams, shared nursing stations, and connected medical devices. That combination of high-value data and low defensive capacity is exactly what ransomware groups exploit.
The numbers make the risk concrete. The average healthcare breach cost reached $9.77 million in 2024, making healthcare the costliest sector for the 14th straight year, according to the IBM Cost of a Data Breach Report 2024. The World Economic Forum reported healthcare cyberattacks up 22% in early 2023, averaging 1,684 attacks per week. Black Kite found roughly 4% of healthcare ransomware victims are nursing homes or assisted living providers, and HHS reports a 264% increase in large ransomware breaches since 2018.
If your facility has not updated its risk analysis in the last 12 months, has shared logins at nursing stations, or keeps backups on the same domain as production, you are in the most common breach profile.
Definitions
- PHI (Protected Health Information): Identifiable health information a covered entity creates, receives, or stores. Nursing homes hold large volumes per resident.
- HIPAA Security Rule: The federal standard for safeguarding electronic PHI, requiring risk analysis, access controls, audit controls, and incident response.
- MDR (Managed Detection and Response): A 24/7 service that monitors endpoints, identities, and cloud accounts, then triages and contains threats before they spread.
- EDR (Endpoint Detection and Response): Sensor software on workstations, servers, and kiosks that records activity and supports isolation, investigation, and rollback.
- HICP (Health Industry Cybersecurity Practices): The HHS-endorsed set of 10 cybersecurity practices for healthcare, scaled for small and large organizations.
- Ransomware: Malware that encrypts systems and exfiltrates data for double-extortion - attackers demand payment to decrypt and to withhold stolen records.
- BAA (Business Associate Agreement): The HIPAA-required contract between a covered entity and any vendor that handles PHI, including EHR, billing, and IT providers.
The complete guide to nursing home cybersecurity
Nursing home cybersecurity is not a compliance exercise. It is a clinical safety program. When EHR, medication administration records, or connected medical devices go offline, resident care is directly affected. A ransomware event at a skilled nursing facility is not an IT outage - it is a patient safety event that triggers diversion protocols, paper charting, and regulatory notification duties.
The threat landscape in 2026 is unchanged in pattern but worse in volume. Attackers still exploit identity, endpoint, and backup hygiene gaps rather than zero-days. They exfiltrate data before encrypting systems, which means a decryptor does not end the incident. Detection gaps still stretch across weeks and months, and multi-state breach notification obligations still drive legal cost.
A defensible program rests on three pillars: prevent the common entry points, detect and contain quickly, and recover without paying. The 10 HHS HICP controls below operationalize all three.
Notable incidents
These 2024 and 2025 incidents show the pattern that defines nursing home cybersecurity risk.
HCF Management (Ohio, 24+ skilled nursing, rehab, and home health sites). Roughly 70,000 individuals were affected. The organization learned of the incident on October 3, 2024. The RansomHub group claimed 250 GB of stolen data, and more than 25 breach reports followed. Read the DataBreachtoday coverage.
Memorial Hospital and Manor (rural Georgia, 107-bed long-term care). 120,000 people were notified after a November 2024 incident. The Embargo group claimed 1.15 TB of data, including names, Social Security numbers, dates of birth, and treatment information. See the DataBreachtoday report.
Carespring Health Care Management. 67,000 residents were affected, and an active lawsuit followed. The NoEscape group claimed 364 GB of stolen data. The discovery-to-notification delay ran roughly 10 months. See Skilled Nursing News coverage and the follow-up report.
The common pattern across these incidents: identity, endpoint, and backup hygiene gaps - not zero-days. Data is exfiltrated before encryption. Detection gaps stretch across weeks and months. Multi-state notification duties multiply legal cost.
What regulators now expect
HHS Office for Civil Rights enforcement in 2024 and 2025 shows a consistent set of findings. Recent actions include:
- Cascade Eye and Skin Centers: $250,000 civil monetary penalty for no risk analysis and no monitoring.
- Providence Medical Institute: $240,000 settlement, the fifth OCR ransomware action.
- Plastic Surgery Associates of South Dakota: $500,000 settlement.
- Bryan County Ambulance Authority: $90,000 settlement for a missing risk analysis.
The recurring findings are the same: no current risk analysis, no vulnerability management, and no tested incident response. OCR favors organizations that can show a current risk analysis and recognized security practices in the prior 12 months. A stale risk analysis is treated as a missing one. See HHS Security Rule Guidance Material, TechTarget coverage, and Healthcare Dive coverage.
The 10 controls (HHS HICP)
The HHS Health Industry Cybersecurity Practices give a defensible, recognized baseline. Treat this as a checklist. See the HHS Cyber Gateway HICP page.
- Email protection - Deploy a filtering gateway, rewrite URLs, quarantine macros, run realistic training, and block external auto-forwarding.
- MFA - Require phishing-resistant MFA on admin, remote, email, and EHR accounts. Prefer FIDO2 or passkeys. CISA reports MFA users are up to 99% less likely to be compromised. See CISA MFA guidance.
- Identity and access - Remove former staff and contractors promptly, run quarterly privileged access reviews, and enforce unique accounts with audit trails.
- Endpoint protection - Install EDR on all workstations, servers, and kiosks. Force shared nursing stations to auto screen lock and require per-session sign-in.
- Data protection and DLP - Encrypt laptops and mobile devices, restrict USB storage, and monitor bulk PHI exports.
- IT asset management - Maintain a live inventory that includes medical devices. Flag unsupported operating systems for replacement or isolation.
- Network management - Segment clinical, administrative, and guest networks. Place IoT and medical devices on a restricted VLAN with east-west controls.
- Vulnerability management - Run monthly authenticated scans, prioritize the CISA KEV catalog, and patch internet-facing systems within 14 days.
- Security operations and incident response - Retain an MDR provider and maintain a written, tested incident response runbook.
- Governance - Name a security owner at the leadership level, report monthly metrics, and brief the board or owner quarterly.
A 90-day implementation plan
Sequencing matters more than scope. Do the highest-impact, lowest-effort controls first.
Days 1-30 - Stop the bleeding. Enable MFA on every admin, remote, email, and EHR account. Inventory internet-facing systems and confirm backups are offline and immutable. Run a current risk analysis if one is more than 12 months old.
Days 31-60 - Detect and contain. Deploy EDR across all workstations and servers, and onboard an MDR provider for 24/7 monitoring. Segment guest Wi-Fi from the clinical network and place medical devices on a restricted VLAN.
Days 61-90 - Harden and rehearse. Run authenticated vulnerability scans, patch internet-facing systems to the 14-day standard, and execute a tabletop incident response exercise with the MDR provider, IT, and clinical leadership.
A quick PowerShell snippet to check MFA enrollment status for privileged accounts in Microsoft 365:
Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All"
Get-MgUser -Filter "accountEnabled eq true" -ConsistencyLevel eventual -CountVariable c |
Select-Object DisplayName,UserPrincipalName,
@{n='MfaMethods';e={(Get-MgUserAuthenticationMethod -UserId $_.Id).AdditionalType}}
A quick PowerShell snippet to isolate a compromised host through Microsoft Defender for Endpoint:
Connect-MgGraph -Scopes "Device.Read.All"
$device = Get-MgDevice -Filter "displayName eq 'NURSE-STATION-07'"
Invoke-MgDeviceIsolate -DeviceId $device.Id -Comment "Ransomware containment - IR runbook step 4"
Handling the most common objections
“We are too small to be a target.” Attackers do not profile by revenue; they profile by data value and recovery pressure. A 107-bed rural facility lost 1.15 TB of data. Size is not a defense.
“HIPAA compliance is enough.” HIPAA is a baseline. The recent settlements show that even compliant organizations are fined when the risk analysis is stale or incident response is untested. Layer modern controls on top of compliance.
“MDR is too expensive.” A realistic MDR subscription for a single facility is a low five-figure annual investment. The average healthcare breach costs $9.77 million. The math is not close.
“We cannot take systems offline for patching.” Segment and schedule. Patch internet-facing systems within 14 days and clinical systems during scheduled maintenance windows. Unpatched internet-facing systems are the most common entry point.
“Our EHR vendor handles security.” Your EHR vendor is a business associate, not your security team. Under HIPAA, the covered entity retains responsibility for risk analysis, access controls, and incident response. Get a current BAA and verify their controls, but do not outsource accountability.
Common mistakes
- Stale risk analysis. An analysis older than 12 months is treated as missing during enforcement. Refresh annually and after major changes.
- Shared login accounts at nursing stations. Shared accounts destroy audit trails and make incident investigation impossible. Enforce per-session sign-in.
- Backups on the same domain as production. Domain-joined backups are encrypted alongside production during ransomware events. Keep at least one offline or immutable copy.
- No vulnerability management. Monthly authenticated scans and CISA KEV prioritization catch the issues attackers actually exploit.
- Untested incident response plan. A runbook that has never been exercised fails under stress. Run a tabletop at least annually with IT, clinical, and legal stakeholders.
What should we do next?
Start with a current risk analysis and MFA on every privileged and remote account, then layer EDR, segmentation, and a tested incident response runbook. If you lack in-house capacity, engage an MSSP or MDR service for 24/7 monitoring. For a structured starting point, run the CyberReplay security scorecard and review the managed security service provider offering.
How much does nursing home cybersecurity cost?
A realistic range for a single facility is a low five-figure annual investment for MDR plus baseline tooling, versus an average healthcare breach cost of $9.77 million. Exact pricing varies by region, bed count, and scope, so treat this as a planning range, not a quote. Most facilities cannot absorb a seven-figure breach, which is exactly why prevention is the cheaper path.
Is HIPAA enough to stop ransomware?
No. HIPAA is a baseline compliance framework. Ransomware defense also requires modern endpoint detection, identity hardening, network segmentation, and tested recovery, as outlined in HHS HICP. Compliance and security overlap, but they are not the same.
Can a small facility afford managed detection and response?
Yes. MDR providers spread 24/7 monitoring across many clients, making it cheaper than hiring one full-time security engineer and far less costly than the average 258-day breach lifecycle. If a breach is detected and contained in hours instead of months, the savings dwarf the subscription cost.
References
- Georgia Hospital, Nursing Home Notifying 120,000 of Hack - DataBreachtoday
- Nursing Home, Rehab Chain Says Hack Affects Nearly 70,000 - DataBreachtoday
- Nursing Home Provider Carespring Health’s Data Breach Impacted 67,000 Residents - Skilled Nursing News
- Data Breaches at Nursing Home Chain Impacted 70,000 Residents - Skilled Nursing News
- IBM Cost of a Data Breach Report 2024
- More than a Password - CISA Multifactor Authentication
- HHS Cyber Gateway - Health Industry Cybersecurity Practices (HICP)
- HHS Security Rule Guidance Material
- HHS settles 2 investigations under HIPAA Security Rule - TechTarget
- HHS settles 2 ransomware investigations as attacks rise - Healthcare Dive
Get your free security assessment
If nursing home cybersecurity is a live priority for your team, schedule your assessment for a focused review. We will map the biggest gaps, assign the first actions, and turn the article into a practical 30-day plan. For broader help, see CyberReplay’s cybersecurity services and the email security for company guidance.
Next step
If this is still unresolved in your environment, book a free security assessment. We will validate the first fixes, pressure-test the response path, and map the next 30 days. If you are actively responding to an incident, use the help I’ve been hacked page or the my company has been hacked page. Browse more CyberReplay blog content or visit the CyberReplay home.
FAQ
How much does nursing home cybersecurity cost? A realistic range for a single facility is a low five-figure annual investment for MDR plus baseline tooling, versus an average healthcare breach cost of $9.77 million. Exact pricing varies by region, bed count, and scope, so treat this as a planning range, not a quote. Most facilities cannot absorb a seven-figure breach, which is exactly why prevention is the cheaper path.
Is HIPAA enough to stop ransomware? No. HIPAA is a baseline compliance framework. Ransomware defense also requires modern endpoint detection, identity hardening, network segmentation, and tested recovery, as outlined in HHS HICP. Compliance and security overlap, but they are not the same.
Can a small facility afford managed detection and response? Yes. MDR providers spread 24/7 monitoring across many clients, making it cheaper than hiring one full-time security engineer and far less costly than the average 258-day breach lifecycle. If a breach is detected and contained in hours instead of months, the savings dwarf the subscription cost.
What is the first action a nursing home should take? Run a current risk analysis and enable phishing-resistant MFA on every privileged, remote, email, and EHR account. These two steps close the most common entry points attackers exploit and satisfy the controls OCR most frequently cites as missing during enforcement.