← Back to W² Advisory
Field Notes · Healthcare · COO to COO

The resilience that moved

A companion note asked how four jurisdictions regulate resilience in finance. The obvious next question: does healthcare look the same? It does not. Healthcare regulates resilience in two accents — the US as continuity of patient care, the EU as cyber and data security — and over the last decade the field has quietly rewritten what “resilience” means, from the loading dock to the server room.

We mapped 290 in-force healthcare-resilience obligations — United States (220), European Union (54), Canada (16) — onto the same eight-principle framework used for finance, so the two are directly comparable. (A further 17 proposed obligations sit in the pipeline; we hold them out of the in-force picture and take them up at the end, because they are the clearest signal of where this is heading.) Going in, the working assumption was that healthcare would mirror finance. The data says otherwise, in two ways. First, the volume of resilience rulemaking is not a rising trend — it is anchored on a handful of landmark rules, above all the 2016 CMS Emergency Preparedness Rule. Second, and more usefully, the character of that rulemaking has migrated — decisively — from physical, all-hazards preparedness to cyber, health-IT and data continuity. So the honest answer to “is resilience taking precedence?” is not “more rules every year.” It is: the definition of resilience is widening, and going digital.

The eight principles came from the rules, not from us. Each principle was surfaced bottom-up from the vocabulary of the obligations themselves — the words the regulators actually use — then reconciled to one spine shared with the finance notes. Shares are within-column (each cell is a % of that region’s own obligations), so the small EU corpus and the larger US one compare fairly.

What “taking precedence” actually looks like

United States only — each bar is the US healthcare-resilience obligations issued in that era, split by what the rule is about (the classifier’s own domain tags). The EU and Canada were cyber-first from the start, so only the US has a physical-to-digital migration to show. Read left to right: the field is being redefined.
≤ 2018 foundation · n=189 85% emergency preparedness (physical) 2019–2021 n=14 100% cyber / health-IT / data 2022–2025 n=13 in force 92% cyber / health-IT / data Emergency preparedness (physical) Cyber, health-IT & data (incl. HIPAA backup) Supply chain

The physical foundation was built once and has barely been touched since: US emergency-preparedness obligations were 85% of everything issued through 2018 — and 0% of everything issued after. Every US healthcare-resilience obligation written since 2019 is cyber, health-IT or data. (The small digital seed was already there in the foundation era — the 2005 HIPAA Security Rule’s data-backup and contingency requirements — it simply took over the whole stream once the physical rulebook was finished.) The last big physical-preparedness rule was the 2016 CMS Emergency Preparedness Rule; since then the US stream has moved indoors. That is the “over time” signal — not a taller bar each year, but a regulator re-pointing its definition of continuity from “keep the hospital running through the hurricane” to “keep the systems, devices and data running through the outage and the ransomware.”

Why volume is the wrong yardstick here. Healthcare resilience law is front-loaded. Six CMS Conditions of Participation issued together in 2016–17 carry about 160 of the 290 in-force obligations — well over half — and the 2005 HIPAA Security Rule carries another cluster. One landmark rule can outweigh a decade of incremental activity, so a year-by-year count measures when the big rules happened to land, not whether attention is rising. The theme migration is the trustworthy trend; the volume line is not.

Two accents: how the US and EU each encode “resilience”

Share of each region’s in-force healthcare-resilience obligations touching each principle. Darker = heavier emphasis. Read down a column for its centre of gravity; read across a row to see where the two split.
United States 220 obl. (in force) European Union 54 obl. Governance & accountability 10% 4% Risk & resilience assessment 16% 17% Business continuity & op. resilience 51% 11% Disaster recovery & backup 3% 2% Third-party & supply-chain risk 5% 4% Incident detection / response / reporting 11% 19% Testing & exercises 13% 6% Technical & cyber security controls 4% 72% SHARE OF EACH REGION'S IN-FORCE HEALTHCARE-RESILIENCE OBLIGATIONS TOUCHING EACH PRINCIPLE · DARKER = HEAVIER EMPHASIS SAME EIGHT PRINCIPLES, TWO ACCENTS · HEALTHCARE VERTICAL, IN-SCOPE ONLY · PRINCIPLES SURFACED FROM THE CORPUS

The two columns are near mirror images. The United States concentrates over half its in-force healthcare-resilience obligations in business continuity and operational resilience (51%) — continuity of patient care — and puts just 4% into enumerated cyber controls. The European Union does the opposite: 72% of its obligations are technical and cyber security controls, and just 11% touch business continuity. Same word, opposite centre of gravity. The US healthcare regulator’s instinct is “can the hospital keep treating patients when something goes wrong?”; the EU’s is “are the systems, devices and data secure and available?” Canada’s 16 obligations are read as directional only, but they point the same way as the EU — they are entirely medical-device cybersecurity, via Health Canada.

The same field, two accents

Read the two regimes side by side on the principles where they diverge, and the difference in technique is unmistakable. Every quote is from an in-force instrument.

PrincipleUnited StatesEuropean Union
Business continuity & continuity of care “Develop arrangements with other hospitals and providers to receive patients in the event of limitations or cessation of operations, to maintain the continuity of care.”CMS · 42 CFR 482.15(b)(7) Light — continuity is 11% of the EU corpus; NIS2 frames continuity as an outcome of cyber risk-management measures rather than a care-delivery standard.
Technical & cyber security controls “Data backup plan (Required): establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.”HHS/OCR · 45 CFR 164.308(a)(7)(ii)(A) (HIPAA Security) “Manufacturers shall set out minimum requirements concerning hardware, IT-network characteristics and IT-security measures, including protection against unauthorised access, necessary to run the software as intended.”EU · MDR Annex I §17.4 / MDCG 2019-16
Incident detection, response & reporting “Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence — for example, fire, vandalism, system failure and natural disaster — that damages systems containing ePHI.”HHS/OCR · 45 CFR 164.308(a)(7)(i) “Ensure that essential and important entities notify, without undue delay, the CSIRT or competent authority of any incident that has a significant impact on the provision of their services.”EU · NIS2 Directive 2022/2555 Art. 23
Risk & resilience assessment “Address the patient population, the type of services the facility can provide in an emergency, and continuity of operations — including delegations and succession plans.”CMS · 42 CFR 482.15(a)(3) “Establish and operate a risk-management system across the entire lifecycle of the medical device, as a continuous, iterative process requiring regular systematic updating.”EU · MDR Annex I §3 / MDCG 2019-16
Testing & exercises “Conduct exercises to test the emergency plan at least twice per year, including participation in an annual full-scale, community-based exercise.”CMS · 42 CFR 482.15(d)(2) “Apply a ‘defense-in-depth’ strategy and threat-modelling techniques across the product lifecycle to identify, enumerate and prioritise vulnerabilities.”EU · MDCG 2019-16 §3.1–3.4

Canada, for reference: “The manufacturer should consider design controls that will allow the device to detect, resist, respond and recover from cybersecurity attacks.” — Health Canada, Pre-market Requirements for Medical Device Cybersecurity §2.1.1. A pure device-cyber posture, like the EU’s.

Why they diverge

The split is not disagreement about what resilience is; it is two starting points. The United States built its healthcare-resilience regime around the hospital as a physical community anchor that must keep treating patients through hurricanes, wildfires and pandemics — so the 2016 CMS Emergency Preparedness Rule, an all-hazards continuity-of-care standard enforced through Medicare Conditions of Participation, is the backbone, with HIPAA’s contingency-planning standard beside it. The European Union arrived through product-safety and cyber law: medical-device security under the MDR, network-and-information-system security under NIS2, and health-data governance under the new European Health Data Space — so its healthcare-resilience obligations read as cyber controls and data requirements. Neither is wrong; they grade different evidence.

But the US is now moving toward the EU’s ground — visibly. In force, just 4% of US healthcare-resilience obligations are enumerated cyber controls. The direction of travel, though, is set: the FDA gained explicit medical-device cybersecurity authority under FD&C Act §524B in 2023, and a proposed 2025 overhaul of the HIPAA Security Rule would import prescriptive cyber controls into a frame that has been physical-continuity-first for two decades. How far that moves the needle is the subject of the next section.

What’s coming — and how it moves the needle

The in-force picture is only half the story. The pipeline of proposed and phasing-in rules is entirely cyber, health-IT and data — there is no physical-preparedness rulemaking anywhere in it. Here is what is coming, and where it points.

The clearest single signal is the one we deliberately held out of the in-force numbers: the proposed 2025 HIPAA Security Rule overhaul adds 17 obligations, 12 of them enumerated cyber controls — multi-factor authentication, a technology-asset inventory, encryption, and mandatory (no longer merely “addressable”) access, audit and integrity controls. On its own, if finalised, it would roughly double the share of the US corpus that is cyber controls, from 4% to about 8% — the first enumerated cyber-control regime in US healthcare. It would still sit far below the EU’s 72%, but the gap would visibly narrow.

Enumerated technical / cyber security controls — share of each corpus US · in force 4% US · if HIPAA overhaul finalised 8% (projected) EU · in force (for scale) 72% DASHED BAR = PROJECTION IF THE PROPOSED 2025 HIPAA SECURITY RULE IS FINALISED AS DRAFTED · NOT YET LAW

Zoom out to the whole pipeline and the pattern is consistent across all three jurisdictions:

JurisdictionWhat’s comingStatus & timingEffect on the needle
United StatesHIPAA Security Rule overhaul — MFA, technology-asset inventory, encryption, mandatory access / audit / integrity controls, annual risk analysis.Proposed rule (NPRM), Jan 2025; comment period closed; not yet finalised.Roughly doubles US cyber-control emphasis (4% → ~8% of the US corpus) — the first enumerated cyber-control regime in US healthcare.
United StatesFDA medical-device cybersecurity under FD&C §524B (secure-by-design, SBOM, coordinated vulnerability disclosure).In force since 2023; premarket obligations accreting with each device cycle.Steady growth of device-cyber duties; reinforces the digital tilt rather than shifting it.
European UnionEuropean Health Data Space (EHDS) — EHR-system requirements, secure processing environments, cross-border and secondary-use data rules.In force 2025; core requirements apply Mar 2027; priority data exchange & secondary use Mar 2029.Deepens the EU’s already-dominant cyber/data corpus; most operative obligations are still ahead of it.
United KingdomCyber Security and Resilience Bill — NIS2-style duties extended to the NHS and health sector.Introduced Nov 2025; Royal Assent expected 2026.Would create a UK healthcare-resilience corpus where none exists today — and it would be all cyber.
The needle only moves one way. Every item in the pipeline — US, EU and UK — is cyber, health-IT or data. There is no physical-preparedness rule anywhere in it. If the proposals land, the migration the first chart shows does not just continue; it accelerates, and the US closes part of the distance to the EU’s cyber accent without coming close to matching it. Read the pipeline as direction and magnitude, not certainty: an NPRM can change or be withdrawn, EHDS’s phase-in obligations are milestone-dated rather than enumerated in this corpus yet, and the UK bill has no operative text so far.
What this means — COO to COO

Build for continuity of care and continuity of code — the second one is where the rules are heading

How this was built — and its limits.
  • US–EU, by necessity. Healthcare has no comparable UK corpus in this library (NHS resilience runs on the DSPT toolkit, tracked but not machine-extractable), and Canadian health law is largely provincial — so the two-accent comparison is US versus EU. Canada’s 16 obligations are federal medical-device cybersecurity only, read as directional.
  • The corpus is front-loaded. About 160 of 290 in-force obligations (well over half) come from the 2016–17 CMS Emergency Preparedness Conditions of Participation; a few large codified rules dominate, so we report theme migration (robust) rather than a year-by-year volume trend (misleading).
  • Time axis = when the regulator acted (publication date, falling back to effective date). Curated EU/Canada instruments are point-in-time landmarks, not a continuous stream.
  • In-force and pipeline are separated. The 290 in-force obligations exclude 17 proposed ones (the 2025 HIPAA Security NPRM), which are analysed only in the “What’s coming” section, never in the in-force charts. EHDS’s 2027/2029 phase-ins and the UK Cyber Security and Resilience Bill are milestone-tracked, not yet enumerated as obligations here — so the pipeline is read as direction and magnitude, not a precise count.
  • Principles are emergent, then reconciled to a canon — scored by the same transparent, deterministic keyword-and-domain lexicon as the cross-sector and transatlantic notes, so all three are comparable.
  • Thought-leadership, not compliance advice. Applicability is entity- and activity-specific; confirm against the instrument text and your own counsel.

Sources

Datasets (broad). United States — Electronic Code of Federal Regulations (eCFR) and the Federal Register (CMS, HHS/OCR, FDA, ONC). European Union — EUR-Lex. Canada — Health Canada guidance library.

Specific instruments cited

  1. CMS Emergency Preparedness Rule (81 FR 63860, 2016) — Conditions of Participation, incl. 42 CFR 482.15 (hospitals), 485.625, 483.73, 416.54, 484.102, 494.62. In force (compliance from Nov 2017). — https://www.ecfr.gov/current/title-42/…/section-482.15
  2. HIPAA Security Rule — 45 CFR Part 164, Subpart C, incl. §164.308(a)(7) contingency plan (data backup, disaster recovery, emergency-mode operation, testing). — https://www.ecfr.gov/current/title-45/…/part-164/subpart-C
  3. HIPAA Security Rule To Strengthen the Cybersecurity of ePHI — Proposed rule (NPRM), 90 FR 898 (6 Jan 2025). Forward signal, not in force. — federalregister.gov · 2024-30983
  4. FD&C Act §524B (21 U.S.C. 360n-2) — Ensuring the Cybersecurity of Medical Devices (added 2023). — https://www.fda.gov/medical-devices/…/cybersecurity
  5. Drug Supply Chain Security Act (DSCSA), 2013 — enhanced drug distribution security. — https://www.fda.gov/drugs/drug-supply-chain-security-act-dscsa
  6. Directive (EU) 2022/2555 (NIS2) — health as an essential sector; Art. 21 risk-management measures, Art. 23 incident notification. Transposition Oct 2024. — eur-lex · CELEX 32022L2555
  7. Regulation (EU) 2025/327 — European Health Data Space (EHDS); EHR-system requirements, cross-border infrastructure, health-data governance. Phased application. — eur-lex · CELEX 32025R0327
  8. Regulation (EU) 2017/745 (MDR), Annex I (esp. §§3, 17.1–17.4) & MDCG 2019-16 — medical-device security, IT-security measures, defense-in-depth, threat modelling. — MDCG 2019-16 guidance
  9. Health Canada — Pre-market Requirements for Medical Device Cybersecurity (2019); detect / resist / respond / recover design controls, post-market vulnerability vigilance. — canada.ca · device cybersecurity guidance
  10. 21st Century Cures Act — Interoperability, Information Blocking (ONC/HHS), 45 CFR Part 171; health-IT availability context. — federalregister.gov · 2020-07419
  11. UK Cyber Security and Resilience Bill — would extend NIS-style duties toward the NHS/health sector; introduced Nov 2025, Royal Assent expected 2026 (pipeline item, not yet law). — gov.uk · Cyber Security and Resilience policy statement

Acronyms

BC — Business continuity
CoP — Condition of Participation (CMS)
CMS — Centers for Medicare & Medicaid Services (US)
CSIRT — Computer Security Incident Response Team (EU)
DR — Disaster recovery
DSCSA — Drug Supply Chain Security Act (US)
EHDS — European Health Data Space — Reg (EU) 2025/327
EHR — Electronic health record
ePHI — Electronic protected health information
FD&C — Federal Food, Drug & Cosmetic Act (US)
HHS/OCR — HHS Office for Civil Rights (US, HIPAA enforcer)
HIPAA — Health Insurance Portability & Accountability Act (US)
MDCG — Medical Device Coordination Group (EU)
MDR — Medical Devices Regulation — Reg (EU) 2017/745
NIS2 — Network & Information Security Directive 2 — Dir (EU) 2022/2555
NPRM — Notice of proposed rulemaking (US)
ONC — Office of the National Coordinator for Health IT (US)

Running care through disruption?

WSquare Advisory builds the resilience operating capability healthcare regulators now expect — a tested continuity-of-care programme that also holds up as cyber, health-IT and data continuity — and helps you evidence one capability in the two idioms, US and EU, that examiners actually grade. If that’s the work in front of you, let’s talk.

Start with an Operating Survey · $5,000 →