Healthcare IT leaders are heading into the back half of 2026 facing a collision of pressures: a looming overhaul of HIPAA’s Security Rule, breach costs that keep setting records, and a workforce gap that most organizations openly admit they can’t close on their own.
The compliance clock is ticking
The Office for Civil Rights is moving toward finalizing long-anticipated updates to the HIPAA Security Rule this year. The direction is clear: system-level, continuous risk analysis is becoming the baseline expectation, not a once-a-year checkbox exercise. Organizations that treat their last risk assessment as “done” are exactly where regulators are expected to look first.
That’s a meaningful operational shift for provider organizations that have historically run security reviews as an annual project rather than a standing discipline.
The cost of getting it wrong keeps climbing
According to IBM’s Cost of Data Breach Report, healthcare organizations incur the highest cost for data breaches of any industry, averaging $9.8 million per incident, more than 1.5 times the financial services industry’s $6.1 million. There is also a notable shift in attacker motivation, with espionage-driven attacks (actors after intellectual property and patient research data rather than a ransom payout) accounting for a much larger share of incidents than in prior years. Those actors are harder to catch because they aren’t trying to draw attention to themselves.
The healthcare IT gap
Healthcare organizations continue to report a lack of in-house cybersecurity expertise. Mid-sized hospitals, ambulatory networks, and behavioral health providers are especially exposed; they hold the same high-value patient data as large health systems but rarely have the budget for round-the-clock monitoring or a fully built-out security team.
The increased need for healthcare IT staffing is driven by ongoing EHR upgrades, AI adoption, data analytics buildouts, and cybersecurity hiring all competing for the same limited pool of specialized talent.
Where ClearBridge fits in
This is the exact intersection ClearBridge works in every day. Healthcare has been a core vertical for our team, and we’ve built our bench specifically around the roles provider organizations are struggling to fill right now: security engineers who understand HIPAA-regulated environments, infrastructure specialists who can support EHR system upgrades without disrupting clinical operations, and compliance-minded IT talent who can help stand up the kind of continuous risk-analysis process regulators are about to require.
We’re not asking healthcare clients to choose between “get compliant” and “keep the lights on.” Our job is closing the staffing gap fast enough that both happen at once, whether that’s a short-term surge team for a security risk assessment, a longer-term infrastructure engagement tied to an EHR migration, or ongoing staff augmentation for a security function that’s currently running on too few people.
If your organization is looking at the incoming HIPAA Security Rule changes and doing the honest math on whether your current team can absorb the work, that’s a conversation worth having now, not after the rule finalizes.
Let’s talk about what your team actually needs to close the gap.
Recent Comments