
Downtime Resilience Doesn’t Have to Cost Billions
The new HIPAA rules demand a 72-hour recovery the industry says is impossible. There’s a cheaper answer: stay running, and make the data unstealable. Hospitals are bracing for the biggest overhaul of HIPAA’s Security Rule since 2013, and most of the conversation is about the price tag. The proposed rule would mandate multi-factor authentication, encryption, threat scanning, and written procedures to restore critical systems within 72 hours, at an estimated $9 billion in the first year and roughly $6 billion a year after, with $68,000 in civil penalties per violation. More than 100 organizations have asked the administration to withdraw it. We understand the pushback on cost and timelines. But we think the loudest objection actually points at the answer.