Smaller healthcare organizations often face additional challenges such as smaller budgets, smaller IT teams, and less operational downtime. During a cyberattack that locks users out of electronic health records (EHRs), scheduling applications, billing software, and email, healthcare organizations may need the same employees to recover access to maintain patient care and manage the organization’s response.

A Paubox survey about rural healthcare cybersecurity revealed that 50% of rural healthcare IT decision makers cited budget constraints as a top obstacle when implementing HIPAA compliant email. 73% stated they faced challenges keeping up with HIPAA compliance due to limited staff and budget.

Because of this, smaller healthcare organizations may have difficulty remediating the attack, recovering systems, communicating with patients and complying with regulations simultaneously. HIPAA compliant email can help organizations meet these needs by allowing for a secure, documented form of communication, if it’s been verified that the email environment is secure following the attack.

 

What cyberattack recovery involves

Cyberattack recovery includes limiting the scope of the incident, restoring information technology systems and data, maintaining patient care and business operations, conducting an internal investigation, and fulfilling any resulting privacy and compliance requirements. Recovery may involve clinical staff and administrators, as well as information technology providers, legal counsel, insurance carriers, law enforcement, and impacted vendors.

A systematic literature review of 70 cybersecurity studies found five common vulnerabilities specific to healthcare: “Human error, lack of investment, complex network-connected endpoint devices, old legacy systems, and technology advancement.” These issues can increase the probability of a cyberattack and can impact how quickly the organization detects affected systems and restores services to normal.

The Department of Health and Human Services (HHS) ransomware guidance notes that HIPAA covered entities and business associates must have security incident procedures in place. They also must implement reasonable and appropriate security incident response and reporting processes. When ransomware is detected, the organization should follow those procedures.

 

Limited staffing and budgets create response delays

Many larger healthcare enterprises will have entire teams dedicated to security, privacy, legal, communications and business-continuity functions. At rural hospitals and clinics, one IT employee may be responsible for several of these tasks, as may a general office manager. Outside resources may also be employed, such as a managed service provider.

In fact, the Paubox rural healthcare report found that when questioned about advanced email security, 85% of surveyed rural healthcare IT leaders said their current infrastructure was not equipped to support it. Rural healthcare organizations fell 22% behind urban healthcare organizations in adoption of AI-driven threat detection.

A lack of resources can cause bottlenecks at every stage of the recovery process. Not only do your teams need to identify which accounts were compromised, contain the breach by disabling compromised accounts, preserve any evidence, restore data from backups, review any exposed data, and respond to patient inquiries, but they also need to complete their day-to-day tasks.

 

Downtime affects patient care and administration

Clinical and administrative systems can be unavailable to staff as a result of a cyberattack even if attackers have not manipulated any patient data. Medical staff may be unable to access medication lists, laboratory test results, schedules for appointments and referrals, billing records, or contact information. One JAMA Health Forum study evaluated 374 ransomware attacks affecting US-based healthcare delivery organizations and found that 44.4% of these attacks resulted in disruption of healthcare delivery. This included downtime of electronic systems in 41.7% of attacks and cancellation of scheduled care in 10.2% of those attacks.

Smaller healthcare organizations may lack alternate facilities, redundant clinical or administrative systems, or additional employees to take on the workload when these disruptions occur. If organizations keep manual charts or have phone-based communication systems, those may be unavailable or ineffective if call volume increases or staff are unable to access up-to-date patient information.

 

Recovery costs can accumulate quickly

Revenue loss from a cyberattack can come from canceled clinical activity, postponed billing, overtime expense, forensic investigation, legal fees, system remediation, patient notification, and other increased security efforts. For organizations that operate on thin margins, such as some smaller providers, these costs can be devastating.

A study from JMIR examined the economic burden that a hospital cyberattack could have on a facility. The study measured varying levels of inactive activity at a public hospital in Portugal. Over a maximum total of five business days, the modeled direct-cost estimates ranged from about €116,000 to €2.3 million, based on the number of days and percentage of services impacted. The costs above aren't meant to serve as a definitive range small US providers can expect to incur but show how varying levels of inactivity can affect the bottom line.

 

Vendor-related attacks can lead to increased complications during recovery

Smaller providers often rely on third-party vendors for EHRs, practice billing, labs, cloud storage, email, cybersecurity, and IT support. A covered entity can still be impacted by a breach if a vendor is attacked, even if the attack didn’t come through their network.

The 2026 Paubox report on healthcare email security examined 170 email-related healthcare breaches reported in 2025. In Paubox’ data brief covering that report, vendor email exposure was found to be the leading pattern among all breaches reported last year.

Vendor compromise can make it more difficult to determine breach scope, affected individuals, and estimated recovery time. Smaller practices can also have less leverage or insight into a vendor’s security and/or recovery protocols.

Under HIPAA, a vendor can be considered a business associate if they create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity. As such, covered entities are generally required to obtain satisfactory assurances, typically in the form of a contract, that their business associates will protect that information.

 

Breach notification adds another workload

If PHI was unsecured as part of a cyberattack, the HIPAA Breach Notification Rule may require the organization to provide notification of the breach to affected individuals. In order to provide that notification, an organization will need to determine what was taken during the attack and how to find out who was affected.

HIPAA’s breach notification guidance from the HHS requires that affected individuals be notified without unreasonable delay and no later than 60 days following a breach of unsecured PHI. Breaches of unsecured PHI affecting 500 or more individuals must also be reported to HHS within 60 days. Notification to HHS for breaches affecting fewer individuals must occur, but within a different timeframe.

The Paubox report indicated that 20% of small and midsized organizations they surveyed weren’t archiving email or using an audit trail. If your organization can’t rely on email archives to help recreate conversations, it may have more difficulty proving how it responded.

 

How smaller healthcare organizations can improve recovery

Organizations can start with a narrow recovery plan that focuses on the most critical clinical and administrative functions. From there, the plan should detail who has authority to make decisions about what systems need to be restored first, how vendors will be notified and how staff will be alerted if normal communications channels go down.

HIPAA requires data backup and disaster-recovery plans as implementation specifications under its Security Rule's contingency planning standard. Backups must be available for recovery as well. Just because something is scheduled for backup does not mean that it can be recovered after an attack.

 

FAQs

Does every cyberattack trigger HIPAA breach notification?

No, an attempted attack that does not compromise PHI may remain a security incident rather than a reportable breach. The organization must still investigate and document what happened.

 

Does ransomware automatically count as a HIPAA breach?

Ransomware affecting ePHI is generally presumed to be a breach unless the organization demonstrates a low probability that the information was compromised. This determination requires a documented assessment of the specific incident.

 

Does notification apply when attackers encrypted data but did not steal it?

Yes, HHS explains that encrypting ePHI can constitute acquisition because the attacker has taken control of the information. The absence of confirmed exfiltration does not, by itself, remove the need for a breach assessment.