The 2026 Microsoft Digital Defense Report, Read for a Health Care IT Shop
Microsoft's 2026 Digital Defense Report is not a health care study. It is a vendor threat report built from Microsoft's own telemetry: more than 165 trillion security signals a day, about 31 million identity risk detections a day, and about 5.2 billion emails screened a day, covering July 2025 through June 2026. That vantage point is real, and it is also narrow. It sees Entra ID, Microsoft 365, Defender, and the customers who send that data. It sees a lot less of the firewall in the network closet, the biomedical VLAN, and the EHR vendor portal that never touches a Microsoft control plane.
Read it that way. The useful part for a health care IT shop is not the policy section and not the AI forecast. It is the access path. Intrusions still start with a person, a reused credential, or an internet-facing box that did not get patched. AI is making those same paths faster. The controls that matter have not changed. The time you have to apply them has.
What the report actually measures
The report is organized around four themes: AI, the threat landscape, cybercrime, and resilience. Year-over-year comparisons use July 2024 through June 2025 as the prior period. The headline figures Microsoft leads with:
- 63 percent of intrusions involved data theft.
- Exposed cloud workloads were attacked within 5.3 hours. In the body of the report, that is the median time from an exposed container starting to its first exploit attempt.
- 93 percent of voice-phishing attacks kept the victim on the line long enough to begin social engineering.
- More than 46 million business contact impersonation attacks were detected over the past 12 months.
- 89 to 95 percent of email phishing attachments led to a credential theft effort.
The United States accounted for 25.5 percent of observed customer impact in Microsoft's January 2026 through June 2026 country ranking, ahead of Israel (7.6 percent) and Ukraine (4.8 percent). That reflects target density and Microsoft's customer footprint. It is not a ranking of which country's hospitals are least prepared.
Health care and public health does not appear in the top sectors for general threat-actor impact. Government, IT, and research and academia lead that list at 27, 17, and 14 percent. Health care does surface in Microsoft's nation-state notification data, as the tenth most targeted sector for China-linked actors (2 percent) and eighth for North Korea (4 percent). North Korea's remote IT worker scheme is the reminder there: verify who you are onboarding, especially for remote IT roles with privileged access. Microsoft's explanation for why those sectors get hit fits a hospital anyway: high-value data, extensive personally identifiable information, sprawling and often under-monitored infrastructure, and a low tolerance for downtime. The report also says plainly that small and medium-sized organizations outside the critical sectors remain at high risk from cybercriminal activity, from ransomware to business contact impersonation. That is the bucket most Critical Access Hospitals and rural clinics live in. The threat is not bespoke nation-state tooling. It is commodity crime that works.
How intrusions start, in two datasets that do not match
Microsoft publishes two initial-access pictures, and they should not be averaged together.
Incident response (IR) findings, 2026 reporting period against the prior year:
| Vector | 2025 period | 2026 period |
|---|---|---|
| Exploit of a public-facing application | 15% | 24% |
| Phishing | 7% | 23% |
| None identified | 25% | 14% |
| Valid accounts | 17% | 13% |
| Social engineering | 15% | 7% |
| External remote services | 8% | 5% |
| Drive-by compromise | 6% | 4% |
| Trusted relationship | 2% | 4% |
| Supply chain compromise | 2% | 4% |
Phishing more than tripled and public-facing exploitation jumped in the IR set. Valid accounts stayed in the top tier. Trusted relationship and supply chain compromise both doubled from a small base, which matters for any organization whose EHR, PACS, or billing vendor holds a standing connection into the network.
Microsoft Defender Experts data tells a more human story. User execution accounted for 30 percent of observed initial access. Valid accounts were another 20 percent. Malicious copy-and-paste was 13 percent, phishing 11 percent, drive-by 6 percent, and exploitation of a public-facing application 5 percent. In Microsoft's words, user execution and valid accounts together accounted for over half of observed activity, and phishing plus malicious copy-and-paste made up roughly another quarter.
The difference is the lens. IR engagements are the cases that got far enough to bring in responders. Defender Experts notifications catch activity earlier. For a health care shop, both matter. The help desk tech who pastes a command, and the VPN appliance that has been exposed since the last firmware window, are both live paths.
Once a user executed something, follow-on activity was malware in 60.3 percent of cases, an infostealer in 12.3 percent, and credential theft in 9.4 percent. PowerShell and cmd.exe were the usual execution vehicles. Once a valid account was in play, 52.2 percent of those intrusions involved follow-on credential theft, and 18.4 percent involved an active password-spray campaign. Lateral movement ran over SMB, WMI, and RDP. One compromised clinic account is not one compromised clinic account. It is the start of a credential harvest.
ClickFix, Teams vishing, and the payroll Monday
ClickFix-style attacks, where a fake error or CAPTCHA tells the user to paste a command into Run, Terminal, or PowerShell, were the leading initial access method in last year's report. This year malicious copy-and-paste was 12.8 percent of observed intrusions, which looks like a decline until you read the volume. ClickFix waned in late 2025 and then grew about 23 times between December and May. From February through early May 2026, Defender observed attacker-supplied ClickFix commands executed on more than 1.1 million unique devices, roughly an eightfold increase. Follow-on was malware in 96.3 percent of cases. A "FileFix" variant pushes the same command through the File Explorer address bar, which slips past shops that only alert on PowerShell.
Picture who gets that prompt: a registration clerk, a billing specialist, a traveling provider on a personal laptop. Application control and a block on users launching script hosts will do more than another annual phishing module. In Intune or Configuration Manager, that means attack surface reduction (ASR) rules in block mode, plus App Control for Business or AppLocker policy that keeps standard users out of PowerShell and other script hosts. If Group Policy is the tool you have, it can push AppLocker and remove the Run dialog for users who never need it.
Voice phishing over Microsoft Teams maps directly onto hospital operations. Weekly confirmed malicious volume rose 502 percent year over year. More than 90 percent of Teams-based attackers in the studied set used voice. Across the attacks Microsoft studied, 93 percent of attackers succeeded at least once in keeping a target on the line for 20 seconds or longer, which is the point where a social engineering script can start. Nearly half of all calls (48 percent) ran longer than 20 seconds, and 30 percent ran past a minute. Calls land on workdays, during business hours. "Help Desk" and "IT Support" display names used to dominate. A majority now use personal-looking usernames that match employee naming conventions, and invisible characters, emojis, and deliberate misspellings get them past exact-match filters. When the call works, the next step is a remote monitoring and management (RMM) tool, then reconnaissance in two minutes or less.
Microsoft's containment list is usable as written:
- Keep external-user warnings on for Teams federation.
- Turn on Safe Links time-of-click evaluation, without a user override.
- Restrict RMM and remote-assist tools to IT groups through endpoint management policy.
- Put ASR rules in block mode for script and Office macro execution.
- Run EDR with behavioral blocking or logging, so the call and the endpoint compromise land in one timeline.
- Hunt for a Teams call followed by a remote-management process launch inside 30 minutes.
Business contact impersonation (BCI) is the renamed cousin of business email compromise, and Microsoft is right to split them. BCI is the social-engineering conversation. Account takeover is a different chain. More than 46 million BCI attacks were detected, and volume spiked 121 percent in April 2026. Most first-contact messages ask for nothing. "Are you at your desk?" is the tell. Explicit money or document requests in the first message fell from 17 percent in October 2025 to 3 percent by June 2026. Payroll diversion peaks Monday and Tuesday (51 percent of those attacks) and goes quiet on weekends. Around 25 percent of impersonation attacks mimic the target's own organization, and HR, payroll, and benefits themes drive 77 percent of those. One in four impersonation emails pushes the victim to a phone call.
For a hospital, the practical control is a callback rule that does not depend on the email looking wrong. Payroll and bank-detail changes get an out-of-band confirmation to a number already on file. So do vendor payment changes. So does any request to install a remote tool, even when the caller sounds like your MSP.
Identity is the control plane, including the service account
Password attacks are down 26 percent year over year. That is the good news, and it is incomplete. In the first six months of 2026, adversary-in-the-middle (AiTM) phishing and token theft more than doubled as a share of the attacks Microsoft detected. Microsoft is careful to note that the share is still comparatively small. The direction is what matters. Within phishing, AiTM was 44.6 percent of identified techniques, against 33.6 percent for standard-URL phishing and 12.9 percent for traditional attachments. Downstream, 87.7 percent of phishing intrusions involved credential or session harvesting, and another 6.3 percent were business contact impersonation. A push notification or an SMS code does not stop a kit that proxies the real sign-in page and walks away with the session cookie. Microsoft and law enforcement disrupted the Tycoon2FA phishing service in March 2026, and its activity fell 95 percent from the November 2025 peak by June. The technique did not go with it.
Cloud identity abuse is no longer a nation-state technique. In Defender XDR incidents from December 2025 through June 2026, password spray accounted for over 99 percent of observed cloud initial-access efforts (124,146,529 alerts). AiTM credential phishing was second at 151,168 alerts, about 0.15 percent, and Microsoft notes it is the more efficient path because it captures the MFA response and the token in the same flow. Device code phishing registered only 896 alerts in that window, which is small until you remember what it does. The user authenticates to a real Microsoft page. The attacker receives the OAuth tokens. Around February 2026, actors abused a legitimate platform to host device-code lures dressed up as DocuSign requests, voicemails, and bid documents. No malware. No fake login page. Persistent access that looks like the user.
Post-compromise, actors add credentials to service principals, replay tokens, abuse Microsoft Graph, and exfiltrate mail with forwarding rules and Power Automate. Workload identities cannot satisfy MFA, and they often carry broad permissions. The pattern Microsoft's Detection and Response Team (DART) keeps seeing is blunt: compromise a human, find a non-human credential, escalate, then exfiltrate through a trusted workflow so the activity looks like the tenant operating normally.
Against critical infrastructure, cloud identity abuse made up 78 percent of observed attack techniques in Microsoft Threat Intelligence data from March 1 through June 30, 2026. In the same window it was 62 percent against state and local government and education. Neither is a full-year rate, and neither is a health care rate, but the direction is the point. Information stealers and commodity tooling then cascade across the vendors and shared services that connect a water utility to a hospital. Rural health care IT teams should not skim that one. The vendor that supports your EHR interface, your phone system, and the county's dispatch center is part of your identity perimeter whether your risk analysis says so or not.
Passkeys and phishing-resistant MFA are the controls Microsoft puts in front of this, and they appear by name in the report's top takeaways. A passkey will not complete on a lookalike site. FIDO2 security keys, passkeys in Microsoft Authenticator, and Windows Hello for Business all qualify in Entra ID. Put device-bound methods on admins, EHR privileged accounts, and break-glass holders first. Then do the step most shops skip: take the phishable methods off those accounts. SMS and email one-time codes left on for recovery, or for the new-hire flow, put the bypass right back. For device code phishing, Conditional Access has an authentication flows condition that can block device code flow outright, and Microsoft's own guidance is to block it wherever possible. Allow it only for a named workflow, scoped to the accounts and devices that need it.
This is also a Security Rule problem, not only a Microsoft problem. Person or entity authentication is a standard at 45 CFR 164.312(d), and it has no addressable implementation specifications underneath it. Unique user identification is required at 45 CFR 164.312(a)(2)(i). Audit controls are a standard at 45 CFR 164.312(b). Password management, at 45 CFR 164.308(a)(5)(ii)(D), is addressable. Addressable does not mean optional. It means you implement it, or you document why it is not reasonable and appropriate and implement an equivalent alternative. A shared front-desk login, a domain admin account used for daily work, and an EHR service account whose password has not rotated since go-live all fail those tests regardless of which MFA method you prefer.
HHS proposed Security Rule changes in January 2025 that would, among other things, eliminate the addressable designation and make MFA an explicit requirement. That rule has not been finalized, and the current Unified Agenda lists July 2027 for final action, which is an estimate rather than a deadline. Until it is final, the current text is what you are measured against, and the current text still requires the decision and the documentation.
Edge devices, RMM, and the patch window you do not have
Attackers have pivoted back to the network edge, and Microsoft lists edge device attacks among the biggest threats for the coming year. Firewalls, VPNs, and gateways now enforce authentication, hold sessions, and talk to cloud identity. Compromising one is not a beachhead on the way to the domain. It is control of the trust boundary. Microsoft names campaigns across Fortinet, Cisco, Ivanti, Citrix, Palo Alto Networks, and Juniper aimed at exposed management interfaces and pre-authentication bugs. Persistence sits in configuration, added accounts, and in some cases firmware or memory implants that a reboot does not clear. A defining signal is a network device behaving like an endpoint: scanning, pulling credentials, or starting lateral movement.
The vulnerability data in Defender alerting is a warning about backlog, not about novel exploits. From July 2025 through June 2026, CVE-2020-1472 (Zerologon) accounted for 58 percent of detections tied to the five leading CVEs. Behind it were CVE-2022-22954 (VMware Workspace ONE), CVE-2021-40444 (MSHTML), CVE-2023-28231 (Windows DHCP Server), and CVE-2020-0601 (Windows CryptoAPI spoofing). Detection is not confirmed exploitation, and plenty of scanning noise lands in those counts. The point stands. A six-year-old domain controller bug is still the top alert. If a DC in your environment is generating it, find out whether that is an unpatched server or someone probing, and do not assume the answer.
Speed is the other half. CISA added more than 110 CVEs to the Known Exploited Vulnerabilities (KEV) catalog from November 2025 to May 2026, most within a week of disclosure. Microsoft says the median time from discovery in the wild to weaponization is now well under 24 hours. Storm-1175 went from a web-facing exploit to Medusa ransomware in as little as 24 hours. In September 2025, Microsoft tracked a four-week surge of Akira ransomware across more than 50 organizations, mostly small and midsize, tied to CVE-2024-40766 on SonicWall SSL VPN. Earlier that summer, in July 2025, two Chinese state actors and Storm-2603 all exploited the same on-premises SharePoint vulnerabilities (CVE-2025-49704 and CVE-2025-49706). The state actors were after access. Storm-2603 deployed Warlock ransomware. Same n-day, espionage and ransomware, within days of each other.
Against that, enterprise remediation for critical external vulnerabilities still runs 30 to 60 days in the research Microsoft cites. CISA's binding directive for federal agencies generally allows two weeks for newer KEV entries. Microsoft's recommendation for internet-facing and identity systems is 72 hours, plus a 90-day lookback for exploitation that started before the patch went on.
Ransomware's fast lanes, in Microsoft's list, are RMM platforms (SimpleHelp, ScreenConnect, BeyondTrust) and file-transfer and identity products (Oracle Identity Manager, SmarterMail, GoAnywhere MFT, SolarWinds Web Help Desk). If any of those are in your environment, or in your MSP's toolkit pointed at your environment, they belong in the same maintenance window as the VPN, not in the application backlog.
For a Critical Access Hospital, this is an inventory problem before it is a patching problem. End-of-life gear widens the gap. So does the firewall whose management interface is reachable from guest wireless, and the VPN profile that still allows local accounts. Isolate what you cannot patch. Export and alert on admin logins, configuration changes, and new accounts on edge devices. If the only log you have is a syslog server nobody reads, you do not have detection.
Ransomware: do not misread the health care row
Microsoft Defender saw a 15.8 percent year-over-year increase in ransom detonations against enterprises. The United States remains the most impacted country in the victim table, rising from 724 to 1,087 cases, an increase of roughly 50 percent. Leak-site rankings and Defender rankings disagree, which is worth knowing before you brief a board on a family name. Public leak sites put Qilin first at 16 percent, then Akira at 8 percent, Play at 7 percent, Gentlemen at 6 percent, and INC at 5 percent. Qilin was fourth last year. Its affiliates keep 80 to 85 percent of ransom payments, and Qilin ships encryptors for Windows and for Linux and ESXi. Defender enterprise detections put Akira first at 22 percent, up 150 percent, and Qilin second at 14 percent, up 111 percent. Leak sites advertise. Telemetry counts what detonated in instrumented tenants. Use the second number for your own risk discussion, and remember that ESXi encryptors mean your hypervisor hosts are in scope.
The industry table is easy to misuse. The heading says percent. The figures are counts. Health care and public health fell from 122 in the 2025 period to 78 in the 2026 period. The bigger story is the "unknown" row: 7,100 of 8,749 events in 2025 and 5,819 of 8,521 in 2026. Most events are not attributed to any sector. The table's own total dipped slightly, from 8,749 to 8,521, while Microsoft separately reports a 15.8 percent rise in ransom detonations against enterprises and US victims up by half. A lower health care count in this table is not evidence that hospitals got safer. It is evidence that Microsoft could attribute fewer events to that sector.
Paying does not reliably return operations, and it does not reliably stop publication. The Security Rule's contingency plan standard at 45 CFR 164.308(a)(7) requires a data backup plan, a disaster recovery plan, and an emergency mode operation plan. Testing and revision of those plans, at 45 CFR 164.308(a)(7)(ii)(D), is addressable, and against this threat data it is hard to document a reasonable alternative to actually testing a restore. Security incident procedures at 45 CFR 164.308(a)(6) require you to identify and respond to incidents, mitigate harmful effects to the extent practicable, and document what happened. That response path needs to assume the identity plane and the backup console may both be in the attacker's hands.
AI is a new place ePHI can leak, and a faster version of the old attack
Microsoft's AI chapter is the one most likely to be briefed without being operationalized. The operational pieces are specific.
Attackers are using AI to find vulnerabilities, generate custom malware, and shorten data exfiltration, secret discovery, and lateral movement from days to minutes. CVE volume is on track for a record of roughly 72,000 in 2026, and Microsoft expects a multi-year period where the number of known but unpatched vulnerabilities spikes because remediation is inherently slower than discovery. That is an argument for exposure management on internet-facing and identity systems. It is not an argument for an AI purchasing project.
Early cases of AI inside the attack are already named. LAMEHUG, first seen in a July 2025 campaign targeting Ukraine, calls a remote model to generate its commands at runtime. The August 2025 s1ngularity malware, delivered through trojanized Nx npm packages, hunted for locally installed AI command-line tools and ran them with permissive overrides to find secrets. It leaked roughly 2,000 secrets and 20,000 files across 225 victims. PromptLock, an experimental ransomware prototype, shipped only prompts and received Lua scripts from an open-weights model at runtime. In early July 2026, Sysdig documented JADEPUFFER, the first automated ransomware extortion attack on record. Microsoft says it has seen related AI-orchestrated intrusions at low volume, and initial access has consistently come from internet-exposed services running known-vulnerable software. Volumes are low. The access path is not new.
The health care-specific exposure is the prompt. In December 2025, Microsoft found a malicious browser extension with more than 600,000 installs harvesting ChatGPT and DeepSeek conversation history. It affected almost 10,000 organizations before it was mitigated. A broader campaign of fake AI assistant extensions reached nearly 900,000 installs across more than 20,000 enterprise tenants. Microsoft notes those chat histories now routinely hold source code, architecture details, customer data, and leaked credentials. In a clinic, they also hold discharge summaries, denial appeal language, and "rewrite this note" drafts that are ePHI. Shadow AI in a browser extension is a disclosure path that will never show up in the EHR audit log.
Agentic tools add to that. Microsoft groups the agent attack surface into five risk classes: prompt and intent manipulation, sensitive data exposure, identity and privilege compromise, excessive agency, and operational integrity (tampering with configuration, memory, or logs). Model Context Protocol (MCP) servers are called out for being deployed exposed and unauthenticated, running on their developer's credentials. Self-hosted agent runtimes that install "skills" from public marketplaces are, in Microsoft's words, untrusted code execution with persistent credentials. Microsoft says it has observed 88 percent of enterprises already experimenting with agents. That is an adoption figure. The companion number, 82 percent of leaders planning broader rollouts within 12 to 18 months, is a forecast. Treat both as pressure, not as a maturity benchmark.
If staff are already pasting into a consumer chatbot, the control is not a policy PDF. It is an approved-tool list, a block on unapproved browser extensions, a ban on ePHI in any tool that is not covered by a business associate agreement, and DLP that inspects outbound prompts where you can see them. A vendor that creates, receives, maintains, or transmits ePHI on your behalf is a business associate, and 45 CFR 164.308(b)(1) and 45 CFR 164.314(a) require the contract before the data moves. A free chatbot with no BAA is not a gray area. Access control under 45 CFR 164.312(a)(1) and minimum necessary under 45 CFR 164.502(b) still apply to whatever AI system you do allow.
Microsoft also says organizations using Security Copilot report summarizing threats 60 to 70 percent faster. That is a vendor outcome metric reported by the vendor's customers about the vendor's product. It does not replace telemetry you do not have.
What to do this quarter
The report's ten priorities are written for a board. A solo admin at a 25-bed Critical Access Hospital, or a three-person team at a rural health system, needs a shorter list. These track the findings above and the Security Rule work you already owe, not a product bundle.
- Put phishing-resistant authentication on every admin, every remote-access account, and every EHR privileged account. Remove SMS and email one-time codes from those accounts, including as recovery methods. Block device code flow in Conditional Access unless a named workflow needs it. This is 45 CFR 164.312(d) and 164.312(a)(2)(i), implemented in a way that matches how the attacks in this report actually work.
- Inventory non-human identities: service principals, API keys, EHR interface accounts, backup service accounts, and RMM service accounts. Apply least privilege, use short-lived credentials where the platform allows it, and give every one an owner. Alert on new credentials added to an application.
- List every internet-facing system: VPN, firewall management, remote desktop gateways, file transfer, on-premises SharePoint, mail gateways, hypervisor management. Patch identity and edge vulnerabilities inside 72 hours of a credible exploitation report. If you cannot, pull the management interface off the internet the same day.
- Restrict RMM and remote-assist tools to IT. Alert when one launches outside that group, especially after a Teams call or other voice contact.
- Block the ClickFix path. Users should not be able to run PowerShell, cmd, or a downloaded script host because a web page told them to. Application control beats another poster in the break room.
- Add an out-of-band check for payroll changes, vendor payment changes, and any request to install software or share a one-time code. Make sure it is staffed on Monday, which is when the payroll diversion mail lands.
- Confirm backups are offline or immutable, and that the identity that can delete them is not the identity that reads email. Test a restore of an EHR-adjacent system, not a file share.
- Decide where AI is allowed. Name the tools. Ban ePHI everywhere else. Review browser extensions on managed endpoints. If you are piloting an agent, scope its identity the way you would scope a vendor interface account, and log what it reads.
- Update the risk analysis to these paths. Risk analysis and risk management at 45 CFR 164.308(a)(1)(ii)(A) and (B) are both required. A risk analysis that still treats "hackers" as the threat, and never mentions session theft, edge appliance compromise, or staff use of consumer AI, is out of date relative to this reporting period.
- Measure exposure, not patch count. Microsoft makes the same argument in its takeaways. Three numbers will do: internet-facing assets with a known exploited vulnerability older than 72 hours, privileged accounts without phishing-resistant MFA, and RMM tools allowed outside IT. Those are enough for a board slide, and they are enough for an OCR conversation.
Three numbers for the board slide
Microsoft argues for measuring exposure reduced instead of patches deployed. For a small health care IT team, these three counts cover most of what this year's report describes. The goal for each one is zero.
Edge exposure
Internet-facing assets with a known exploited vulnerability older than 72 hours.
Identity exposure
Privileged accounts without phishing-resistant MFA, or with SMS or email codes still registered.
Remote tool exposure
RMM and remote-assist tools that can run outside the IT group.
What this report does not settle
It does not tell you which EHR is safer. It does not measure biomedical devices, imaging modalities, or the HL7 interface engine. The industry ransomware counts leave most events in "unknown." The Copilot speed claims are Microsoft customers reporting on a Microsoft product. And everything in it is seen through Microsoft telemetry, which means environments with thin Microsoft instrumentation are underrepresented by design.
Use the report for the access pattern. A person executes something, or a valid account walks in, or an edge device is already behind on patches. Data leaves in the same week, often through a feature you turned on so staff could get work done. AI shortens the middle of that chain and adds a new place for the chart to leak. The work is still identity, the edge, and a restore you have actually performed.
This article is for informational purposes only and does not constitute legal or compliance advice. Covered entities and business associates should consult qualified legal counsel or compliance professionals before making decisions pertaining to HIPAA or IT infrastructure.
Sources
- Microsoft, 2026 Microsoft Digital Defense Report (full report, PDF), October 1, 2026
- Microsoft, 2026 Microsoft Digital Defense Report executive summary
- Microsoft, Microsoft Digital Defense Report 2026 landing page and key figures
- Microsoft Security Insider, 2026 Digital Defense Report
- Microsoft Security Blog, Insights from the 2026 Microsoft Digital Defense Report, October 1, 2026
- Microsoft Security Blog, Disrupting active exploitation of on-premises SharePoint vulnerabilities, July 22, 2025
- Microsoft Learn, Conditional Access: Authentication flows
- BleepingComputer, Microsoft says threat actors are ahead in the early AI race, October 1, 2026
- CISA, BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities
- eCFR, 45 CFR Part 164, Subpart C (Security Rule)
- eCFR, 45 CFR 164.502(b), Minimum necessary
- Federal Register, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (NPRM), January 6, 2025
- Clark Hill, HIPAA Security Rule Update Delayed Until 2027