Skip To Navigation Skip To Content Skip To Footer
    MGMA Stat
    Home > MGMA Stat > MGMA Stat
    Chris Harrop
    Chris Harrop

    No medical practice can eliminate cyber risk. What leaders can control is how well the practice keeps scheduling patients, submitting claims and paying staff when core systems go down.

    Asked how confident they are that their practice could recover quickly from a cyberattack, less than one in five (19%) medical group leaders said “very,” 61% said “somewhat,” and 21% said “not confident,” according to an Oct. 6, 2026, MGMA Stat poll with 238 applicable responses.

    The follow-ups suggest that confidence is driven primarily by tested recovery plans, backups and IT expertise, while lower-confidence respondents most often cited dependence on vendors, limited staffing and insufficient resources.

    What the results show

    Compared with a similar January 2025 poll,1 the share of leaders who were very confident slipped slightly from 20% to 19%, while the not-confident share declined from 27% to 21%. The biggest shift was an increase in the somewhat-confident group, from 54% to 61%, suggesting that more organizations believe they have some recovery capability but still see meaningful gaps in their preparedness.

    • Very confident (19%): Respondents who were very confident most often pointed to a combination of tested backups, documented incident response plans, experienced IT teams and strong vendor support. Several cited prior cyberattack experience as a reason for confidence, saying those incidents prompted stronger recovery processes and regular testing. Comments also frequently referenced cloud-based systems and ongoing readiness exercises. Representative comments included: “Tested backups, response plan, IT support resources,” and, “We experienced a ransomware attack five years ago and have quarterly reviews to review downtime procedures and test safeguards.”
    • Somewhat confident (61%): Among somewhat-confident leaders, vendor dependence emerged as the most frequently cited weak link. Many respondents said recovery would depend heavily on EHR, IT or other third-party vendors responding effectively during an incident. Staff capacity and incident response planning were the next most common concerns, followed by funding and uncertainty about whether backups would work as expected. Several respondents noted they would not know how well their preparedness measures perform until they experience a significant attack.
    • Not confident (21%): Leaders who were not confident most often cited the lack of dedicated IT or cybersecurity personnel, often coupled with concerns about funding. Others pointed to missing or inadequate incident response plans, insufficient backups or uncertainty about outsourced IT support. Several comments reflected concern that smaller independent practices lack the resources available to larger health systems.

    Why recovery time matters

    Ransomware made up 36% of the cyber threats reported to the FBI’s Internet Crime Complaint Center in 2025, more than 3,600 complaints, and healthcare was among the three critical sectors the top variants hit hardest.² The FBI’s own loss figure for those complaints, about $32 million, excludes lost business, staff time and third-party remediation.² Those costs still fall on the practice.

    The Change Healthcare outage showed what that bill looks like for a medical group that did nothing wrong. In an informal AMA survey of more than 1,400 respondents fielded in spring 2024, 80% reported lost revenue from unpaid claims, 85% had put extra staff time into revenue cycle work, and 55% had used personal funds to cover practice expenses; 78% of respondents came from practices with 10 or fewer physicians.³ The forensics belonged to a vendor yet the cash problem belonged to the practice.

    Medical groups have been spending on prevention: 72% increased cybersecurity spending in 2024.⁴ Preventing an attack and recovering from one require different investments, and federal recovery requirements are still evolving. The proposed HIPAA Security Rule would require written procedures to restore critical systems and data within 72 hours, plus 24-hour notice from business associates when they activate contingency plans.⁵ HHS has moved that rule to its long-term agenda with final action projected for July 2027,⁶ and MGMA has urged HHS to withdraw it, citing cost and the loss of flexibilities that let small groups scale safeguards to their size.⁷ Whether or not the proposal is finalized, many practices may find value in testing recovery timelines against ambitious restoration targets.

    Ransomware can also trigger breach-notification obligations while systems are still down. HHS’ Office for Civil Rights presumes a ransomware incident is a HIPAA breach unless the practice can document a low probability of compromise.⁸

    Before the attack: what shortens recovery

    The poll's follow-up questions point to seven areas practices can test before an incident. For each one, leaders should know who is responsible, when it was last tested and how long recovery is expected to take.

    1. Backups someone has actually restored. The FBI’s baseline is offline or offsite backups that are encrypted and immutable — meaning attackers cannot alter or delete them — covering the whole data environment, with restoration tested on a schedule.² The test that matters is specific: how many hours to bring the PM system and EHR back to a usable state, and who has watched it happen. If no one has tested restoring from a backup, the practice does not yet know whether it will work or how long recovery will take.
    2. An incident response plan with current contacts. The Health Sector Coordinating Council’s Operational Continuity-Cyber Incident checklist is built in role-based modules that scale down to a small practice: who declares the incident, who runs operations, who handles communications, who tracks costs.⁹ Keep a printed copy in case the systems storing the electronic version are unavailable.
    3. Downtime procedures that cover claims processing. Most medical groups (82%) reported having a plan for EHR or PM downtime in a July 2021 MGMA Stat poll.¹⁰ Change Healthcare exposed the gap in many of those plans: they covered the practice's own systems and assumed the clearinghouse and other claims-processing systems would remain available.¹⁰ A current plan covers paper encounter forms, a schedule printed each evening, eligibility phone scripts, charge-capture holding and a second route to payers (portals, a backup clearinghouse or paper claims).
    4. A list of critical vendors and dependencies. List every vendor that touches cash flow: PM, EHR, clearinghouse, patient payments, payroll, hosted phones. For each, note what the business associate agreement promises on contingency-plan notification and restoration time. Practices can ask vendors to spell out notification and restoration timelines in their contracts, regardless of what the final rule requires.⁵
    5. Cash reserves and insurance that match likely downtime. Size a cash reserve or line of credit to the practice's days in A/R and the recovery window the backup test produced, and confirm cyber insurance covers business interruption.
    6. A tabletop exercise, twice a year. Walk the plan with the billing lead, a clinical lead, the MSP and whoever would talk to patients. Use the exercise to identify tasks that have no clear owner or backup.

    During an attack: the first 72 hours and after

    These steps focus on practice operations. Technical containment belongs to the response firm and the MSP; the administrator keeps patients seen, keeps the record and keeps money moving.

    First hour.

    • Disconnect affected devices from the network; leave them powered on so the response firm can examine them.
    • Declare the incident and name the person running it.
    • Start a time-stamped log of every action, call and decision; the insurer, counsel and OCR will ask for it.

    First 24 hours.

    • Call the cyber insurer before engaging any outside help; many policies require the insurer's approved response firm and counsel.
    • Switch to downtime procedures across the front desk, clinic and billing.
    • Reach staff and physicians through channels outside the affected systems, such as a phone tree or personal text; email may be compromised.
    • Give the front desk a patient script: what is affected, what still works, when to expect an update.
    • Report to the FBI through IC3; law enforcement advises against paying a ransom, and the report opens a channel for help.²

    Days one through three.

    • Establish scope with the response firm before restoring anything; restoring onto a network the attacker still controls restarts the incident.
    • Set the restoration order based on patient safety, care continuity and revenue-cycle needs.
    • Rebuild compromised systems from known-clean system images; reset every credential; verify restored data against the most recent verified backup.
    • Begin the breach risk assessment under counsel; OCR's presumption means documentation starts now.⁸

    Week one and after.

    • Triage the revenue cycle: log every eligibility check, authorization and charge handled on paper so each is submitted once systems return, and ask payers for timely-filing and prior authorization accommodations in writing.
    • Track reporting obligations in one place: HIPAA breach notification runs on its own clock, state laws add others, and a federal CIRCIA reporting rule remained pending as of this writing;¹¹ MGMA has pressed CISA to keep it from becoming a second job during an outage.¹²

    What practices can control — and what they can't

    Several items on the readiness list are directly within a practice's control. Others depend on vendors, available funding and federal requirements. The responses suggest that preparedness is strongest where practices can directly control recovery planning, backup testing and staff training. Confidence declines when recovery depends on external vendors, specialized technical expertise or funding that may be difficult for smaller organizations to secure.

    That distinction also matters for MGMA's advocacy. Medical groups are being asked to meet prescriptive recovery requirements, including a proposed 72-hour restoration requirement,⁵ while the incentive concepts HHS floated with its cybersecurity performance goals targeted high-need hospitals rather than physician practices.¹³ MGMA's position has been consistent: flexibility and support scaled to practice size rather than unfunded mandates,⁷ incident reporting that does not become a second job during an outage,¹² and recovery commitments from the vendors that carry a practice's claims and records. Practices can test their own backups, but they have limited control over how quickly a clearinghouse recovers.

    Additional resources

    MGMA

    Health IT and federal

    Notes

    1. MGMA Staff Members. Medical practice leaders attuned to cyberattacks, recovery after a rocky 2024. MGMA Stat. January 22, 2025. Accessed October 1, 2026. https://www.mgma.com/mgma-stat/medical-practice-leaders-attuned-to-cyberattacks-recovery-after-a-rocky-2024
    2. Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 Internet Crime Report. April 2026. Accessed October 1, 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
    3. American Medical Association. Change Healthcare Cyberattack Impact: Key Takeaways From Informal AMA Survey. April 2024. Accessed October 1, 2026. https://www.ama-assn.org/system/files/change-healthcare-survey-results.pdf
    4. MGMA. Confronting the rising price tag of cybersecurity in medical practices. MGMA Stat. September 18, 2024. Accessed October 1, 2026. https://www.mgma.com/mgma-stat/confronting-the-rising-price-tag-of-cybersecurity-in-medical-practices
    5. US Department of Health and Human Services, Office for Civil Rights. HIPAA Security Rule notice of proposed rulemaking to strengthen cybersecurity for electronic protected health information: fact sheet. December 27, 2024. Accessed October 1, 2026. https://hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet
    6. Office of Information and Regulatory Affairs. HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22). Unified Agenda of Federal Regulatory and Deregulatory Actions. 2026. Accessed October 1, 2026. https://www.reginfo.gov/public/do/eAgendaMain. See also: McDermott Will & Schulte. Final action on HIPAA Security Rule modifications now projected for July 2027. July 16, 2026. https://www.mcdermottlaw.com/insights/final-action-on-hipaa-security-rule-modifications-now-projected-for-july-2027/
    7. Medical Group Management Association. MGMA urges HHS to rescind proposed update to HIPAA Security Rule. March 7, 2025. Accessed October 1, 2026. https://www.mgma.com/advocacy-letters/march-7-2025-mgma-urges-hhs-to-rescind-proposed-update-to-hipaa-security-rule
    8. US Department of Health and Human Services, Office for Civil Rights. Fact Sheet: Ransomware and HIPAA. July 2016. Accessed October 1, 2026. https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdf
    9. Health Sector Coordinating Council Cybersecurity Working Group. Operational Continuity-Cyber Incident (OCCI) Checklist. April 29, 2022. Accessed October 1, 2026. https://healthsectorcouncil.org/04-29-2022-occi-checklist-published/
    10. MGMA. Averting crisis with a well-documented plan for EHR, RCM downtime. MGMA Stat. 2024. Accessed October 1, 2026. https://www.mgma.com/mgma-stat/averting-crisis-with-a-well-documented-plan-for-ehr-rcm-dowtime
    11. CISA expects to finalize key cyber reporting rule by September. Nextgov/FCW. July 2026. Accessed October 1, 2026. https://www.nextgov.com/cybersecurity/2026/07/cisa-expects-finalize-key-cyber-reporting-rule-september/414607/
    12. Medical Group Management Association. MGMA comments on cyber incident reporting proposed rule. July 3, 2024. Accessed October 1, 2026. https://www.mgma.com/advocacy-letters/july-3-2024-mgma-comments-on-cyber-incident-reporting-proposed-rule
    13. Alston & Bird. HHS issues cybersecurity performance goals. February 5, 2024. Accessed October 1, 2026. https://www.alston.com/en/insights/publications/2024/02/hhs-issues-cybersecurity-performance-goals
    Chris Harrop

    Written By

    Chris Harrop

    Chris Harrop is a Senior Editor on MGMA's Training and Development team, helping turn data complexity, the steady flow of news headlines and frontline feedback into practical tools and advice for medical group leaders. He previously led MGMA's publications as Senior Editorial Manager, managing MGMA Connection magazine, the MGMA Insights newsletter, and MGMA Stat, and MGMA summary data reports. Before joining MGMA, he was a journalist and newsroom leader in many Denver-area news organizations.


    Explore Related Content

    More MGMA Stats

    An error has occurred. The page may no longer respond until reloaded. An unhandled exception has occurred. See browser dev tools for details. Reload 🗙