The resilience that moved
A companion note asked how four jurisdictions regulate resilience in finance. The obvious next question: does healthcare look the same? It does not. Healthcare regulates resilience in two accents — the US as continuity of patient care, the EU as cyber and data security — and over the last decade the field has quietly rewritten what “resilience” means, from the loading dock to the server room.
We mapped 290 in-force healthcare-resilience obligations — United States (220), European Union (54), Canada (16) — onto the same eight-principle framework used for finance, so the two are directly comparable. (A further 17 proposed obligations sit in the pipeline; we hold them out of the in-force picture and take them up at the end, because they are the clearest signal of where this is heading.) Going in, the working assumption was that healthcare would mirror finance. The data says otherwise, in two ways. First, the volume of resilience rulemaking is not a rising trend — it is anchored on a handful of landmark rules, above all the 2016 CMS Emergency Preparedness Rule. Second, and more usefully, the character of that rulemaking has migrated — decisively — from physical, all-hazards preparedness to cyber, health-IT and data continuity. So the honest answer to “is resilience taking precedence?” is not “more rules every year.” It is: the definition of resilience is widening, and going digital.
What “taking precedence” actually looks like
The physical foundation was built once and has barely been touched since: US emergency-preparedness obligations were 85% of everything issued through 2018 — and 0% of everything issued after. Every US healthcare-resilience obligation written since 2019 is cyber, health-IT or data. (The small digital seed was already there in the foundation era — the 2005 HIPAA Security Rule’s data-backup and contingency requirements — it simply took over the whole stream once the physical rulebook was finished.) The last big physical-preparedness rule was the 2016 CMS Emergency Preparedness Rule; since then the US stream has moved indoors. That is the “over time” signal — not a taller bar each year, but a regulator re-pointing its definition of continuity from “keep the hospital running through the hurricane” to “keep the systems, devices and data running through the outage and the ransomware.”
Two accents: how the US and EU each encode “resilience”
The two columns are near mirror images. The United States concentrates over half its in-force healthcare-resilience obligations in business continuity and operational resilience (51%) — continuity of patient care — and puts just 4% into enumerated cyber controls. The European Union does the opposite: 72% of its obligations are technical and cyber security controls, and just 11% touch business continuity. Same word, opposite centre of gravity. The US healthcare regulator’s instinct is “can the hospital keep treating patients when something goes wrong?”; the EU’s is “are the systems, devices and data secure and available?” Canada’s 16 obligations are read as directional only, but they point the same way as the EU — they are entirely medical-device cybersecurity, via Health Canada.
The same field, two accents
Read the two regimes side by side on the principles where they diverge, and the difference in technique is unmistakable. Every quote is from an in-force instrument.
| Principle | United States | European Union |
|---|---|---|
| Business continuity & continuity of care | “Develop arrangements with other hospitals and providers to receive patients in the event of limitations or cessation of operations, to maintain the continuity of care.”CMS · 42 CFR 482.15(b)(7) | Light — continuity is 11% of the EU corpus; NIS2 frames continuity as an outcome of cyber risk-management measures rather than a care-delivery standard. |
| Technical & cyber security controls | “Data backup plan (Required): establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.”HHS/OCR · 45 CFR 164.308(a)(7)(ii)(A) (HIPAA Security) | “Manufacturers shall set out minimum requirements concerning hardware, IT-network characteristics and IT-security measures, including protection against unauthorised access, necessary to run the software as intended.”EU · MDR Annex I §17.4 / MDCG 2019-16 |
| Incident detection, response & reporting | “Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence — for example, fire, vandalism, system failure and natural disaster — that damages systems containing ePHI.”HHS/OCR · 45 CFR 164.308(a)(7)(i) | “Ensure that essential and important entities notify, without undue delay, the CSIRT or competent authority of any incident that has a significant impact on the provision of their services.”EU · NIS2 Directive 2022/2555 Art. 23 |
| Risk & resilience assessment | “Address the patient population, the type of services the facility can provide in an emergency, and continuity of operations — including delegations and succession plans.”CMS · 42 CFR 482.15(a)(3) | “Establish and operate a risk-management system across the entire lifecycle of the medical device, as a continuous, iterative process requiring regular systematic updating.”EU · MDR Annex I §3 / MDCG 2019-16 |
| Testing & exercises | “Conduct exercises to test the emergency plan at least twice per year, including participation in an annual full-scale, community-based exercise.”CMS · 42 CFR 482.15(d)(2) | “Apply a ‘defense-in-depth’ strategy and threat-modelling techniques across the product lifecycle to identify, enumerate and prioritise vulnerabilities.”EU · MDCG 2019-16 §3.1–3.4 |
Canada, for reference: “The manufacturer should consider design controls that will allow the device to detect, resist, respond and recover from cybersecurity attacks.” — Health Canada, Pre-market Requirements for Medical Device Cybersecurity §2.1.1. A pure device-cyber posture, like the EU’s.
Why they diverge
The split is not disagreement about what resilience is; it is two starting points. The United States built its healthcare-resilience regime around the hospital as a physical community anchor that must keep treating patients through hurricanes, wildfires and pandemics — so the 2016 CMS Emergency Preparedness Rule, an all-hazards continuity-of-care standard enforced through Medicare Conditions of Participation, is the backbone, with HIPAA’s contingency-planning standard beside it. The European Union arrived through product-safety and cyber law: medical-device security under the MDR, network-and-information-system security under NIS2, and health-data governance under the new European Health Data Space — so its healthcare-resilience obligations read as cyber controls and data requirements. Neither is wrong; they grade different evidence.
But the US is now moving toward the EU’s ground — visibly. In force, just 4% of US healthcare-resilience obligations are enumerated cyber controls. The direction of travel, though, is set: the FDA gained explicit medical-device cybersecurity authority under FD&C Act §524B in 2023, and a proposed 2025 overhaul of the HIPAA Security Rule would import prescriptive cyber controls into a frame that has been physical-continuity-first for two decades. How far that moves the needle is the subject of the next section.
What’s coming — and how it moves the needle
The clearest single signal is the one we deliberately held out of the in-force numbers: the proposed 2025 HIPAA Security Rule overhaul adds 17 obligations, 12 of them enumerated cyber controls — multi-factor authentication, a technology-asset inventory, encryption, and mandatory (no longer merely “addressable”) access, audit and integrity controls. On its own, if finalised, it would roughly double the share of the US corpus that is cyber controls, from 4% to about 8% — the first enumerated cyber-control regime in US healthcare. It would still sit far below the EU’s 72%, but the gap would visibly narrow.
Zoom out to the whole pipeline and the pattern is consistent across all three jurisdictions:
| Jurisdiction | What’s coming | Status & timing | Effect on the needle |
|---|---|---|---|
| United States | HIPAA Security Rule overhaul — MFA, technology-asset inventory, encryption, mandatory access / audit / integrity controls, annual risk analysis. | Proposed rule (NPRM), Jan 2025; comment period closed; not yet finalised. | Roughly doubles US cyber-control emphasis (4% → ~8% of the US corpus) — the first enumerated cyber-control regime in US healthcare. |
| United States | FDA medical-device cybersecurity under FD&C §524B (secure-by-design, SBOM, coordinated vulnerability disclosure). | In force since 2023; premarket obligations accreting with each device cycle. | Steady growth of device-cyber duties; reinforces the digital tilt rather than shifting it. |
| European Union | European Health Data Space (EHDS) — EHR-system requirements, secure processing environments, cross-border and secondary-use data rules. | In force 2025; core requirements apply Mar 2027; priority data exchange & secondary use Mar 2029. | Deepens the EU’s already-dominant cyber/data corpus; most operative obligations are still ahead of it. |
| United Kingdom | Cyber Security and Resilience Bill — NIS2-style duties extended to the NHS and health sector. | Introduced Nov 2025; Royal Assent expected 2026. | Would create a UK healthcare-resilience corpus where none exists today — and it would be all cyber. |