
Published on Sep 04, 2026
Super Admin
How Cyber Threats Are Forcing Practices to Rethink Their RCM Tools
If you picked your RCM software five years ago, you probably picked it the same way most practices did. You wanted cleaner claims, fewer denials, decent integration with your EHR, and a price that worked. Security was somewhere on the checklist, usually satisfied by the vendor saying, "Yes, we're HIPAA compliant."
That is not enough anymore.
It stopped being enough after Change Healthcare. It got worse when ransomware crews started openly hunting small practices. And with the HIPAA Security Rule overhaul about to close the "we'll get to it later" loopholes, the whole conversation around RCM tool selection has slipped beneath most practice owners' radar.
What follows is not another scary-threats list. It's a look at why billing teams are being pushed to re-evaluate their RCM tools right now, and what smarter selection criteria looks like today.
The wake-up call nobody wanted: Change Healthcare and what came after
In February 2024, a ransomware attack on Change Healthcare froze billing and claims processing for a huge chunk of the U.S. healthcare system. Small practices could not submit claims. Pharmacies could not verify coverage. Some clinics went weeks without cash flow. The number of Americans whose health data was exposed reached roughly 193 million by the time notifications finished, making it the largest healthcare breach ever recorded.
That event did something the HIPAA training videos never did. It made practice owners realize their RCM vendor is a single point of failure for their entire business. If the vendor goes dark, so does the practice's ability to get paid.
Two years on, the ripple effect is still there.
Practices are asking vendors questions they used to skip. Cyber insurance carriers are demanding evidence. And regulators are moving to close the gaps that let one breach cascade through hundreds of clinics.
The 2026 threat picture, in plain numbers
The attack pattern has changed, and the people writing checks for RCM tools should know why.
Ransomware crews hit healthcare organizations 410 times in the first half of 2026 alone, per Comparitech tracking. What's more telling is where the growth came from: attacks on the businesses supporting providers, meaning billing firms, wholesalers, and healthcare tech vendors, rose almost 35% compared to the previous half-year. In other words, the attackers stopped bothering with the hospital and started going for the vendor that serves fifty hospitals.
Q1 2026 saw more than 200 ransomware attacks on healthcare, and small practices were the fastest-growing target segment. The reasoning is simple to understand. Small practices have weaker defenses and zero tolerance for downtime, so they pay faster.
That’s why the average cost of a healthcare data breach now sits at around $7.42 million. Roughly 40% of organizations take more than a month to fully recover from a ransomware event. And even a clean backup no longer saves you from the fallout, because double extortion is standard now. Attackers steal the data first, encrypt the systems second, and threaten to release it publicly if the ransom does not arrive.
The uncomfortable takeaway is that hospitals with 24/7 security teams are no longer the softest target. A three-doctor practice running an RCM tool from a vendor with a lean IT team is. Attackers know this equation.
Why the old RCM buying criteria is no longer valid
The 2026 threat model is different because attackers now target the vendor. They breach one RCM platform and cascade into every clinic that uses it. This is called a business associate cascade, and it is exactly what Change Healthcare demonstrated.
So the questions that used to matter (features, denial rates, price per claim) still matter, but they cannot be the whole conversation. A cheap tool with a weak security posture will cost you more in one bad quarter than five years of a premium tool would.
Here is what changed underneath the RCM buying decision:
The BAA is no longer enough on its own
A Business Associate Agreement tells you who is liable after a breach. It does not stop one from happening. What actually matters now is what security controls the vendor has in place before you sign anything.
"HIPAA compliant" is the new floor
HIPAA is roughly 20 years old. The Security Rule was written before cloud RCM platforms, before AI-driven phishing, and before ransomware was a business model. Vendors saying they meet HIPAA are meeting the bare minimum.
Cyber insurance carriers now audit you
Most policies now require documented MFA, endpoint detection, tested backups, and phishing training. Practices that cannot produce evidence get their claims denied after an attack. Your RCM tool has to produce that evidence for you.
The HIPAA Security Rule overhaul is coming
The proposed updates, published in late 2024, remove the "addressable" loophole practices used to bypass encryption, MFA, and formal risk analysis. Once finalized, covered entities get roughly 180 to 240 days to comply. If your current RCM tool cannot support those controls, you have a much bigger problem coming your way.
The five questions billing teams should ask before renewing
If you are going into vendor selection or renewal in the next 12 months, five questions will separate a serious RCM partner from a good marketing website.
- First, ask what certifications the vendor holds and whether you can see the actual reports. SOC 2 Type II is the baseline these days. HITRUST r2 is stronger, and it's increasingly what cyber insurers want to see before they underwrite you. "We're working on it," or a generic "we're HIPAA compliant" without paperwork is a red flag.
- Second, ask how fast the vendor will notify you if they have a breach, and what will be in that notification. You're looking for a specific timeframe (24 to 72 hours is the current bar) and a commitment to share scope, affected records, and remediation steps. Vague language here means slow answers when something goes south.
- Third, ask who has access to your patient data, including subcontractors. Many modern RCM platforms rely on offshore billing teams, cloud infrastructure providers, and third-party clearinghouses. Ask for the sub-processor list. If the vendor cannot produce one, they do not know their own attack surface, which is not a great foundation for trusting them with yours.
- Fourth, ask what their MFA, encryption, and backup architecture looks like. You want to hear about MFA enforced for everyone, including admins; encryption at rest and in flight; immutable backups tested on a regular schedule; and role-based access built around least privilege. If what you get back is marketing language, keep asking until you get specifics or the vendor gives up.
- Fifth, ask how the tool will help your practice pass a cyber insurance audit. Audit logs, user activity reports, access reviews, and phishing training records should be available to you on demand. If you have to file a support ticket and wait a week for that data, the tool is not doing its job.
Print those five. Take them to every vendor call. The good vendors will have answers ready. The rest will start hedging within the first two.
What a modern, secure RCM platform looks like
The RCM tools worth considering in late 2026 share a common shape. They still do the boring, essential work well: eligibility checks, claim scrubbing, denial management, patient statements, and reporting. What separates them is what sits underneath.
A serious platform gives you a full audit trail of who touched what and when. It enforces MFA without letting anyone opt out. It uses role-based access, so a front-desk staffer cannot access the entire patient database. It encrypts data at rest and in flight. It backs itself up somewhere the attackers cannot reach. And it publishes clear security documentation without making you sign an NDA to read it.
For small and independent practices, the cleaner path is often to choose a vendor that combines practice management, EHR, and revenue cycle on a single platform with a single security posture. Fewer integrations mean fewer vendor connections that attackers can exploit. Modern healthcare revenue cycle management software for independent practices are built around this idea, keeping the security controls, the billing workflows, and the clinical documentation under one roof rather than stitched together across three vendors and four APIs.
While that single-platform approach does not automatically make you secure, it reduces the number of doors an attacker can knock on, which is a meaningful chunk of the risk equation.
The cost of doing nothing, in real numbers
For a small practice, the math on delaying is worse than most owners assume.
- Two to four weeks is typical downtime during a ransomware event. For a practice billing $80,000 to $150,000 a month, that is $40,000 to $150,000 in delayed revenue, not counting the overtime and IT recovery costs.
- If you cannot show MFA logs, backup tests, or a documented incident response plan, the insurer can walk away. That turns a covered loss into a full out-of-pocket loss.
- HIPAA fines have historically ranged from $141 to $71,162 per violation, with annual caps in the millions. The updated security rules tighten enforcement.
- Patient churn after a breach notification is very hard to measure. However, practices that have been through it consistently report a drop in book of business in the six months after the letters go out.
Set that against the incremental cost of a more secure RCM platform, which is usually a few hundred dollars a month more than the low-end option, and the answer stops being interesting.
Final Thoughts
Cybersecurity used to be a checkbox on the RCM buying process. Now it is “The” process. The threat model has changed, the regulations are catching up, and the vendors who took security seriously five years ago are already years ahead of the ones who didn't.
Practices that come through the next 24 months in decent shape will be the ones that stopped treating their billing platform as a back-office tool. When Change Healthcare went dark, it stopped being a back-office tool for everyone. That was the moment it became critical infrastructure, and most owners I talk to have not forgotten.
All of which is to say, rethinking your RCM tool is not paranoia. It is just what someone who wants to still have a practice in three years should already be doing.