In 2024, the Centers for Medicare & Medicaid Services (CMS) proposed a significant change: adding cybersecurity and patient safety requirements to the Conditions of Participation for hospitals, critical access hospitals and other Medicare- and Medicaid-participating providers. If finalized, these requirements would become binding conditions for payment eligibility, not optional guidance.
For chief executives, chief compliance officers and boards at participating institutions, the proposed rule presents a clear question: who inside the organization will own the strategy, governance and risk decisions necessary to achieve and sustain compliance?
Why This Matters to Hospital and Health System Leadership
Conditions of Participation define the minimum health and safety standards organizations must meet to participate in Medicare and Medicaid programs. Failure to meet these conditions can result in termination of the provider agreement, effectively ending an institution's ability to serve Medicare and Medicaid patients.
The proposed cybersecurity requirements would elevate information security from an operational IT concern to a compliance prerequisite with direct consequences for revenue, accreditation status and patient access. Leadership is now accountable for a security outcome that most organizations have not formally integrated into their governance, risk management or compliance structures.
Unlike voluntary frameworks, Conditions of Participation are enforceable. CMS conducts surveys—either directly or through state agencies and accrediting organizations—to verify compliance. An institution found deficient must submit a plan of correction and demonstrate remediation within specified timeframes.
What the Proposed Rule Would Require
At the time of this writing, the proposed rule has not been finalized, and the specific technical and administrative requirements remain subject to public comment and revision. What is clear is the direction: CMS intends to establish baseline cybersecurity practices as a condition of payment eligibility.
When finalized, the rule is expected to require participating organizations to implement specific cybersecurity controls, document those controls, assign accountability for cybersecurity governance, and demonstrate ongoing compliance through auditable evidence. The rule may reference or align with established frameworks such as the [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework), which provides a common language for managing and reducing cybersecurity risk across sectors.
The timeline for implementation will depend on the final rule's publication date and the compliance period CMS establishes. Historically, CMS has provided transition periods for new Conditions of Participation, but these periods can be shorter than institutions expect, particularly when patient safety is the stated rationale.
The Accountability Gap: Who Owns Cybersecurity Governance?
Most hospitals and health systems lack a senior executive formally accountable for cybersecurity strategy and risk decisions. IT directors manage technology. Compliance officers manage regulatory programs. Legal counsel manages contracts and disclosures. Information security staff manage controls. But cybersecurity governance—the responsibility for deciding what risks to accept, what controls to prioritize, how to allocate limited resources, and how to report risk position to the board—often has no clear owner.
This gap becomes critical under a regulatory framework that holds the organization accountable for outcomes, not effort. CMS does not ask whether your institution tried to implement a control. It asks whether the control exists, whether it is documented, whether it is effective, and who is accountable for its maintenance.
Adequate ownership at this level requires a combination of technical literacy, regulatory knowledge, risk judgment and executive authority. The role is strategic, not operational. It sits above the IT function and intersects with compliance, legal, finance and clinical leadership.
How This Relates to Regulatory and Framework Readiness
The proposed CMS rule is part of a broader pattern: regulators across sectors are converting voluntary cybersecurity frameworks into enforceable requirements. Healthcare organizations already navigate HIPAA Security Rule obligations, state breach notification laws, and in some cases additional requirements under state-specific health information privacy statutes.
The CMS Conditions of Participation would add a new compliance layer with direct financial consequences. Organizations that have already aligned their cybersecurity programs with the NIST Cybersecurity Framework or similar recognized standards will find themselves better positioned to demonstrate compliance. Those that have not will face a compressed timeline to establish governance structures, document controls, assign accountability and produce auditable evidence.
Regulatory and framework readiness is not a technical project. It is a governance decision that requires executive sponsorship, cross-functional coordination and a clear understanding of what the organization is being asked to prove.
What Leadership Should Do Next
First, assign executive accountability for cybersecurity governance. This does not mean hiring a full-time CISO if the institution's size or complexity does not warrant one. It means designating a senior leader—or engaging [virtual CISO leadership](/vciso/)—who can make risk decisions, represent cybersecurity at the executive level, coordinate across departments, and report to the board.
Second, conduct a structured readiness assessment against the requirements most likely to appear in the final rule. This assessment should identify gaps in controls, documentation, policies and governance structures. It should also clarify what evidence the organization can produce today if asked to demonstrate compliance.
Third, establish a cross-functional working group that includes compliance, IT, legal, finance and clinical leadership. Cybersecurity compliance under the Conditions of Participation will require coordination across all these functions. The group should meet regularly, report to executive leadership, and have a defined timeline for closing identified gaps.
Fourth, monitor the status of the proposed rule. CMS publishes proposed rules in the Federal Register and provides public comment periods. Final rules include effective dates and compliance deadlines. Institutions that wait for the final rule to begin preparation may find themselves operating under compressed timelines with limited flexibility.
Fifth, document the decisions you make and the rationale behind them. Regulatory compliance is ultimately about demonstrating that your organization has a defensible process for managing risk. Auditors and surveyors will ask not only what controls you have implemented, but how you decided which controls to implement, how you measure their effectiveness, and who is accountable when they fail.
The Role of Virtual CISO Leadership
Many hospitals and health systems—particularly those outside large integrated delivery networks—lack the volume or complexity to justify a full-time chief information security officer. But the accountability requirement does not scale with organizational size. A critical access hospital participating in Medicare faces the same Conditions of Participation as a 500-bed academic medical center.
[Virtual CISO (vCISO) leadership](/vciso/) provides the executive function these organizations need without the overhead of a permanent hire. A vCISO establishes governance structures, makes risk decisions, coordinates regulatory readiness, represents cybersecurity to the board and executive team, and provides the documented accountability that regulators and surveyors will expect.
This is not a staff augmentation model. It is executive leadership delivered on a flexible basis, calibrated to the institution's risk profile, regulatory obligations and operational constraints.
Moving Forward
The proposed CMS cybersecurity Conditions of Participation represent a fundamental shift in how healthcare organizations will be held accountable for information security. Leadership can no longer delegate cybersecurity to IT and assume the problem is being managed. The question CMS will ask is not whether your institution has technology in place, but whether it has governance, accountability and evidence.
Institutions that establish executive ownership now—whether through a permanent hire or through [virtual CISO leadership](/vciso/)—will be positioned to meet the final rule's requirements on schedule. Those that wait will face compressed timelines, emergency remediation efforts, and the risk of survey findings that threaten their ability to participate in Medicare and Medicaid.
If your institution lacks a senior executive formally accountable for cybersecurity strategy and regulatory readiness, or if you are uncertain whether your current governance structure will satisfy the proposed Conditions of Participation, a confidential consultation can clarify your options. Heights Consulting Group provides virtual CISO leadership to hospitals and health systems that need executive cybersecurity accountability without a full-time hire. To discuss your institution's position in confidence, contact [email protected].
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.