Skip to Content FinThrive logo FinThrive logo
  • How We Help
    • Outcomes
      • Modernize Patient Engagement
      • Denial & Underpayment Prevention
      • Maximize Yield
      • Workforce Effectiveness
      • Lower Total Cost of Ownership
    • Markets
      • Hospitals and Health Systems
      • Ambulatory and Physician Practices
      • Payers
      • Partners and Resellers
      • Life Sciences
    • Solutions
      • AI and Automation
      • Analytics
      • Patient Access
        • Access Coordinator
        • Virtual Intake
      • Revenue Integrity
        • CDM Management
      • Revenue Optimization
        • Contract Manager
        • Insurance Discover
        • Denials Prevention Manager
        • Claims Manager
        • A/R Optimizer
        • Government Reimbursement
      • FinThrive Learn
    • Trending Topics
      • One Big Beautiful Bill Act (OBBBA)
      • Community Advantage
      • Cyber Resilience
      • Embrace Disruption
  • Our Platform
  • Resources
      • All Resources
      • Blogs
      • Case Studies
      • Events & Webinars
      • Guides
      • Infographics
      • Reports
      • Speakers Bureau
      • Testimonials
      • Videos
      • Webinars On Demand
  • About Us
      • Why FinThrive
      • Customer Success
      • Leadership Team
      • Press Releases
      • Media Coverage
      • Security
      • Careers
        • Careers - U.S.
        • Careers - India
    • We're here to help!

      Have a question or want to learn more?

      Contact Us
Contact Us
  • Community Portal
  • Partner Portal
  • Product Login
  • How We Help
    • Outcomes
      • Modernize Patient Engagement
      • Denial & Underpayment Prevention
      • Maximize Yield
      • Workforce Effectiveness
      • Lower Total Cost of Ownership
    • Markets
      • Hospitals and Health Systems
      • Ambulatory and Physician Practices
      • Payers
      • Partners and Resellers
      • Life Sciences
    • Solutions
      • AI and Automation
      • Analytics
      • Patient Access
        • Access Coordinator
        • Virtual Intake
      • Revenue Integrity
        • CDM Management
      • Revenue Optimization
        • Contract Manager
        • Insurance Discover
        • Denials Prevention Manager
        • Claims Manager
        • A/R Optimizer
        • Government Reimbursement
      • FinThrive Learn
    • Trending Topics
      • One Big Beautiful Bill Act (OBBBA)
      • Community Advantage
      • Cyber Resilience
      • Embrace Disruption
  • Our Platform
  • Resources
      • All Resources
      • Blogs
      • Case Studies
      • Events & Webinars
      • Guides
      • Infographics
      • Reports
      • Speakers Bureau
      • Testimonials
      • Videos
      • Webinars On Demand
  • About Us
      • Why FinThrive
      • Customer Success
      • Leadership Team
      • Press Releases
      • Media Coverage
      • Security
      • Careers
        • Careers - U.S.
        • Careers - India
    • Contact Us
  • Community Portal
  • Partner Portal
  • Product Login
Contact Us
Home Blog Current

When Threat Intelligence Disappears, Some Hospitals Pay a Much Higher Price

Originally Published: Aug 19, 2026

split screen showing federal level impact and provider level impact
Federal Cybersecurity Funding Cuts Are Reshaping Healthcare Security | FinThrive
13:44

 

Key Takeaways

  • Federal cybersecurity support for healthcare is shrinking fast. MS-ISAC, which supplied 90% of local threat intelligence for 21 years, lost federal funding on October 1, 2025, cutting off free threat data for more than 19,000 state, local and healthcare organizations.
  • CISA has lost roughly a third of its workforce. Cuts since September 2025 have scaled back threat hunting, vulnerability scanning and advisory support right as ransomware activity keeps climbing.
  • The impact isn't even. Peer-reviewed research in JAMA Health Forum found 84% of ransomware attacks on rural hospitals caused operational disruption, and rural hospitals are far less likely than urban ones to belong to a larger system that can absorb the hit.
  • Healthcare remains the costliest industry for data breaches. IBM's 2025 Cost of a Data Breach Report puts the average incident at $7.42 million, the highest of any sector for the 14th consecutive year.
  • Resilience doesn't require an enterprise budget. Risk-based prioritization, offline backups, peer information-sharing and targeted grant programs can meaningfully close the gap for resource-constrained organizations. 


TLDR

Federal programs that once gave hospitals free access to shared threat intelligence, including MS-ISAC and CIPAC, have lost funding or dissolved in 2025, and CISA has lost roughly a third of its staff. Every hospital feels this shift, but the impact concentrates hardest on smaller and rural hospitals that are less likely to belong to a larger system and less likely to have the internal security resources to compensate. The fix isn't a bigger budget. It's smarter prioritization, stronger peer networks and knowing which cost-effective programs and partnerships already exist to help close the gap. 

Healthcare Security Is Entering a New Era of Self-Reliance

For 21 years, the Multi-State Information Sharing and Analysis Center (MS-ISAC) gave hospitals, local governments and other public entities free access to shared threat intelligence, covering an estimated 90% of local threat data nationwide. That partnership with the Department of Homeland Security ended on October 1, 2025, and the loss now touches more than 19,000 state and local government entities, including many of the hospitals and health systems that relied on it most.

Every hospital feels this shift. But the impact is not distributed evenly. For a large health system with an in-house security operations center, the loss of shared federal intelligence is a budget line to work around. For a smaller or rural hospital running lean on IT staff, it's a blind spot. And in cybersecurity, blind spots are where attackers live.

What's Actually Changed

Three shifts are converging at once:

  • CISA workforce reductions: The Cybersecurity and Infrastructure Security Agency has lost roughly one-third of its workforce since September 2025, scaling back threat hunting, vulnerability scanning and sector-specific support.

  • CIPAC dissolution: The Critical Infrastructure Partnership Advisory Council, which enabled information sharing between government and industry, was dissolved in early March 2025.

  • MS-ISAC defunding: The center that supplied 90% of local threat intelligence lost federal funding, and services once free to healthcare organizations have moved to paid or reduced-scope models.

These changes stem in part from P.L. 119-21, commonly known as OBBBA (the One Big Beautiful Bill Act), a sweeping federal budget reconciliation law enacted in mid-2025 that reduced federal spending across multiple sectors, including cybersecurity support programs. The broader pullback in federal cybersecurity funding extends beyond any single piece of legislation, but OBBBA accelerated the timeline. Individually, each of these shifts is a policy story. Together, they represent something bigger: healthcare is losing its early warning system at the exact moment ransomware and supply-chain attacks keep climbing.

The Real Story Isn't Funding. It's Inequity.

Most cybersecurity coverage stops at “budgets are shrinking.” The more important story is who absorbs that shrinkage.

Federal cybersecurity funding has historically supported rural hospitals, safety-net providers and public health infrastructure more than any other segment of the industry. When that funding disappears, it doesn't create an even playing field. It creates a widening gap between organizations that can self-fund advanced security and those that can't, and the data backs this up.

A peer-reviewed JAMA Health Forum study found that 84% of ransomware attacks on rural hospitals caused operational disruptions, including electronic system downtime (81%), delayed or canceled care (42%) and ambulance diversion (33%). A follow-up analysis of that research found that only 41.9% of ransomware-attacked rural hospitals were part of a larger health system that could help absorb the disruption, compared to 79.5% of urban hospitals, and that patients at attacked rural hospitals had to travel an average of 29.5 miles to reach the next open facility, compared to just 6.1 miles in urban areas.

Layer on the fact that healthcare remains the costliest industry for data breaches, averaging $7.42 million per incident and taking longer than any other sector to detect and contain, and the math gets harder every year for the organizations with the least room to absorb it. Smaller hospitals often lack segmentation, multi-factor authentication and continuous monitoring, so when an attack hits, it persists longer before containment simply because there are fewer people watching for it. The result is a patient safety impact that concentrates in the communities where care access is already the most fragile.

When Defense Gets Weaker, Patient Care Gets Riskier

It's tempting to file this under IT risk. It isn't. Reduced threat intelligence and slower incident response translate directly into clinical consequences, including:

  • Longer EHR outages and a return to manual charting, which introduces its own error risk

  • Delayed labs, imaging and medication administration during active incidents

  • Ambulance diversion, canceled surgeries and emergency department slowdowns, all of which have followed real-world healthcare ransomware events

Patient safety sits alongside funding cuts, degraded controls and operational disruption as part of the same chain reaction. Treating cybersecurity as purely a technology conversation misses where the actual harm shows up.

icon-water-ripple

The Healthcare Cybersecurity Ripple Effect

  • Reduction in Federal Support
  • Fewer Shared Resources
  • Less Threat Intelligence
  • Greater Burden on Internal Teams
  • Increased Need for Security Visibility
  • Potential Impact on Revenue Cycle Operations


Why “Just Increase the Budget” Isn't a Realistic Answer

Most resource-constrained hospitals can't out-spend this problem, and they shouldn't need to. Resilience at this stage depends less on tools and more on risk-based prioritization, strong governance and preparedness that doesn't require an enterprise budget. That includes steps like:

  • Prioritizing internet-facing systems and known exploited vulnerabilities instead of scanning everything

  • Maintaining offline, physically disconnected backups and testing restores quarterly

  • Building peer relationships through regional hospital alliances and state associations, which often surface warnings faster than formal channels

  • Applying for programs built specifically for this gap, including the Google Rural Healthcare Cybersecurity Initiative, the Microsoft Rural Health Resiliency Program and CISA's State and Local Cybersecurity Grant Program

None of these require a seven-figure security budget. They require knowing they exist and building the habit of using them.

Closing the Gap: Where FinThrive Fits

FinThrive can't replace what MS-ISAC or CIPAC provided at a federal level, but a few things we already do map directly onto this gap:

The FinThrive Security Council

A peer forum where healthcare security and compliance leaders share threat intelligence, supply-chain risk practices and disaster recovery strategies directly with one another. It's the same kind of informal, trusted information-sharing that helps resource-constrained organizations stay ahead of threats, and it's already built.

Revenue Continuity

When prevention fails, recovery speed becomes the story. FinThrive's standby and rapid deployment model is built to restore eligibility verification and claims operations in hours or days rather than the weeks some organizations have faced after a major incident, helping protect cash flow and continuity of care while systems are restored.

Community Advantage

For community and rural hospitals managing a large, disconnected vendor stack, Community Advantage bundles the full revenue cycle onto a single platform, reducing the number of third-party connections and handoffs that create additional exposure in the first place.

Together, these give resource-constrained organizations what federal cuts have taken away: a place to hear about threats early, a smaller attack surface to defend, and a way to keep operating if a threat gets through anyway.

Ready to Close the Gap?

Join the FinThrive Security Council to connect with peer healthcare security leaders, or talk to our team about Revenue Continuity and Community Advantage solutions built for the moment prevention isn't enough.


greg surla

About the Author
Greg Surla is SVP and Chief Information Security Officer at FinThrive, bringing more than 30 years of experience protecting mission-critical systems. A U.S. Army veteran who served in Operation Desert Storm, Greg has led cybersecurity and technology programs in highly regulated environments, holding multiple CISO roles across healthcare, technology, manufacturing and other critical infrastructure industries.



question and answer speech bubbles icon

Healthcare Cybersecurity Funding FAQs

A quick reference from FinThrive on the questions healthcare security and finance leaders ask most about the federal cybersecurity funding shift.

What is MS-ISAC and why does it matter for healthcare cybersecurity?
MS-ISAC (Multi-State Information Sharing and Analysis Center) supplied roughly 90% of local threat intelligence to state, local and healthcare organizations for 21 years before losing federal funding on October 1, 2025. Its defunding removes a major source of free, shared threat data for more than 19,000 government and healthcare entities nationwide.

What is OBBBA and how does it relate to healthcare cybersecurity?
OBBBA, or the One Big Beautiful Bill Act (P.L. 119-21), is a federal budget reconciliation law enacted in mid-2025 that reduced federal spending across multiple sectors. It contributed to funding reductions affecting cybersecurity support programs like CISA and MS-ISAC, though the broader pullback in federal cybersecurity funding extends beyond this single piece of legislation.

Why are rural hospitals more vulnerable to cyberattacks?
Rural hospitals and safety-net providers have historically relied more heavily on federal cybersecurity funding and support programs than larger health systems. Research published in JAMA Health Forum found that ransomware-attacked rural hospitals are far less likely to belong to a larger system that can absorb the disruption, and their patients travel nearly five times farther on average to reach the next open hospital.

What happened to federal cybersecurity funding for healthcare?
Since early 2025, CISA has lost roughly one-third of its workforce, the Critical Infrastructure Partnership Advisory Council (CIPAC) has dissolved and MS-ISAC has lost federal funding, ending a 21-year DHS partnership. Together, these changes have reduced threat intelligence sharing, advisory support and federal coordination available to healthcare organizations of every size.

How can resource-constrained hospitals improve cyber resilience without a large budget?
Hospitals can prioritize internet-facing systems and known exploited vulnerabilities, maintain offline backups with quarterly restore testing, build peer relationships through regional hospital alliances, and apply for targeted programs like the Google Rural Healthcare Cybersecurity Initiative, the Microsoft Rural Health Resiliency Program and CISA's State and Local Cybersecurity Grant Program.

What is the FinThrive Security Council?
The FinThrive Security Council is a peer forum where healthcare security and compliance leaders share best practices on threat intelligence, supply-chain risk and disaster recovery, helping fill the information-sharing gap left by reduced federal cybersecurity programs.

How does Community Advantage help reduce cybersecurity risk?
Community Advantage consolidates the revenue cycle onto a single platform for community and rural hospitals, reducing the number of disconnected third-party vendors and integration points that can create additional supply-chain and cybersecurity exposure.

View all blogs


  • Share
  • Share
  • Share

What Should Healthcare Leaders Expect From a Modern Healthcare Clearinghouse?
08/10/26 Read
The 2027 Maternity Coding Reset Is Coming. Is Your Team Ready?
08/05/26 Read
The Performance Illusion: Why Healthy Revenue Cycle Metrics Can Hide Revenue Leakage
07/28/26 Read

Imagine revenue cycle management without the friction

See how it’s possible with FinThrive

phone-icon

Password resets /
critical issues
800-390-7459

For non-critical issues
or requests, visit our
Community Portal

  • Quick Links
    • Outcomes
    • Our Platform
    • Patient Access
    • Revenue Integrity
    • Revenue Optimization
    • AI and Automation
  • Resources
    • Blogs
    • Events & Webinars
    • Press Releases
  • About Us
    • Why FinThrive
    • Leadership Team
    • Careers
    • Accreditations
    • Sustainability Report
    • Code of Ethics
  • Customer Support
    • Contact
    • Community Portal
    • Partner Portal
    • Product Login
FinThrive logo
© 2026, FinThrive. All Rights Reserved.
  • Transparency in Coverage
  • Privacy Policy
  • Terms and Conditions
  • CCPA Privacy Notice
Return to Top