
The City of Hamilton did almost everything right. When ransomware took down 80 percent of its network in February 2024, the city refused the $18.5 million ransom, brought in outside experts, protected its backups, and rebuilt. Then it filed a claim with its cyber insurer for the recovery costs, and the insurer denied all of it. Roughly $5 million, gone, over a single unfinished security control the city had known about since fall 2022.
That denial is worth an executive’s full attention, because it reveals who is actually enforcing healthcare security requirements right now. It isn’t who you’d expect.
Behavioral health organizations should keep a quarterly evidence file of MFA enforcement exports, access review sign-offs, backup test results, training records, and BAA inventory, turning insurance renewal from a scramble into retrieval. The rest of this piece is the case for why that file needs to exist before your next renewal, and why the federal rulemaking process is the wrong clock to set it by.
Your Carrier Has Better Data Than Your Regulator
Healthcare has posted the highest average breach cost of any industry for 14 consecutive years. The 2025 figure is $7.42 million per incident, with 279 days on average to identify and contain it (IBM, 2025). Insurers price against those losses every day, and an underwriter pricing real risk stops accepting attestations. The renewal questionnaire that used to be a paperwork formality is now a controls examination. The carrier wants MFA enforcement it can see, backup tests with dates on them, training records with names attached, and a BAA inventory that matches reality.
The insurer is now the fastest-moving enforcer of the HIPAA Security Rule.
A Known Gap Is the Worst Kind
Hamilton’s policy required multi-factor authentication as of fall 2022. Staff knew. A pilot rollout began the following year and reached a handful of departments. When the attack came in February 2024, the policy’s own language settled the question: no coverage for losses where absent MFA was the root cause (CBC News, 2025). A third-party legal review confirmed the denial was sound, and the city didn’t pursue it further (City of Hamilton, 2025).
Notice what the insurer never asked. Not whether the city took security seriously. Not whether the rollout was in progress. Not whether the attack was sophisticated (it was). The only question was whether the named control was fully deployed on the day it mattered, and the answer was no. For an organization holding behavioral health data, where the same controls satisfy carriers, auditors, and grant funders alike, an eighteen-month gap between knowing and finishing is an exposure with a dollar figure attached. Hamilton’s figure was $5 million.
The Rule You’re Waiting For Isn’t Coming on Schedule
If your security roadmap is paced to federal regulation, look at where that regulation actually stands. The proposed HIPAA Security Rule update would make MFA and encryption mandatory, ending two decades of the required-versus-addressable distinction (HHS Office for Civil Rights, 2024). HHS published it January 6, 2025. Comments closed March 7, 2025. OCR’s own regulatory agenda targeted a final rule for spring 2026, and that window has passed with nothing published. More than 100 hospital systems and provider organizations have asked HHS to withdraw the proposal entirely (Healthcare IT News, 2025), and the American Hospital Association has urged the same in its own comments (AHA, 2026).
So the mandate is stalled, contested, and possibly headed for the shelf. Meanwhile your carrier already requires what the rule only proposes, checks it at renewal, and enforces it at claim time. The enforcement gap everyone expected OCR to close got closed from the other direction.
Put the Evidence Ahead of the Question
The renewal habit most organizations still run is attestation-era: answer the questionnaire, file it, move on. Hamilton is what happens when that habit meets a carrier that verifies. The replacement habit is cheap by comparison. A quarterly evidence file means the proof of every control your policy names already exists, current within 90 days, in one place, before anyone asks. Renewal stops being a two-week reconstruction project and becomes retrieval.
Every organization eventually finds out whether its controls hold up under a carrier’s scrutiny. The only variable is whether that happens during a renewal review or a claim denial. If your insurer examined your MFA deployment tomorrow the way Hamilton’s did, what would it find still open?
At Xpio Health,we help behavioral health organizations build renewal-ready evidence before the carrier asks for it. Reach out before your next renewal deadline.
#CyberInsurance #HIPAASecurityRule #BehavioralHealth #RiskManagement #PeopleFirst #XpioHealth
References
- IBM. Cost of a Data Breach Report 2025. IBM. 2025. https://www.ibm.com/reports/data-breach
- City of Hamilton. Cybersecurity Update: City provides more incident details, including ransom amount. City of Hamilton. 2025. https://www.hamilton.ca/city-council/news-notices/news-releases/cybersecurity-update-city-provides-more-incident-details
- CBC News. Insurance won’t cover $5M in City of Hamilton claims for cyberattack, citing lack of log-in security. CBC. 2025. https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713
- HHS Office for Civil Rights. HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information. HHS.gov. 2024. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
- Healthcare IT News. HHS should withdraw OCR’s proposed HIPAA Security Rule, healthcare organizations say. Healthcare IT News. 2025. https://www.healthcareitnews.com/news/hhs-should-withdraw-ocrs-proposed-hipaa-security-rule-healthcare-organizations-say
- American Hospital Association. AHA Response to HHS RFI on AI in Health Care. AHA. 2026. https://www.aha.org/lettercomment/2026-02-23-aha-response-hhs-rfi-ai-health-care