Administrators often ask the same question: how much should we spend on cybersecurity? There is no universal percentage, and anyone who quotes you one without knowing your operation is guessing. What you can do is build a budget around real risks, spend first on controls that matter most and keep a record of the reasoning.
This guide is for administrators and owners of small and mid-size care organizations who must balance security against staffing, supplies and everything else a facility needs.
The best budget begins with a security risk analysis, which HIPAA already requires. It tells you which systems hold resident data, where the biggest gaps are and what an outage or breach would cost you in disruption. Without it, you may spend money on shiny tools while basic gaps remain.
Some measures give strong protection for relatively modest cost. The HHS 405(d) Health Industry Cybersecurity Practices publication and the NIST Cybersecurity Framework both point to these basics:
Multi-factor authentication on email, remote access and administrator accounts.
Email security filtering.
Endpoint protection on all computers and servers.
Regular patching of systems and applications.
Backups that are protected, offsite and tested.
Staff security awareness training.
A firewall that is managed and updated.
A written incident response plan.
If these are not in place, they come before anything advanced.
A useful budget has several buckets:
Tools and services that reduce the chance of an incident: email filtering, firewalls, MFA, patch management, training.
Monitoring that spots trouble early, such as endpoint detection and response, log monitoring and alerting. Detection matters because even well-defended networks can be breached.
Backups, disaster recovery, incident response planning and, if appropriate, cyber insurance. These determine how quickly you recover.
Training, policy writing, tabletop exercises, risk analysis and vendor reviews. These often cost mainly time but deliver real value.
The sticker price is only part of the picture. Consider:
Staff time to manage tools and respond to alerts.
Licensing that renews every year.
Hardware replacement cycles for firewalls, switches and computers.
Training time for employees.
Costs of downtime if systems fail.
Unsupported equipment often costs more over time through outages and repairs than replacing it on a schedule.
Small organizations rarely can hire a full security team. Options include:
A single IT generalist, who may be stretched thin and have gaps in security expertise.
A managed service provider that bundles helpdesk, monitoring and security under a predictable monthly fee.
A hybrid, where an internal person handles daily needs and a provider handles security tooling and after-hours coverage.
When comparing, ask what is included, how incidents are handled and how the provider supports HIPAA documentation.
Policies can help cover response costs and certain losses, but insurers commonly require controls such as MFA, backups and endpoint protection before offering coverage or favorable pricing. Read exclusions carefully. Insurance complements security spending, it does not replace it.
A three-tier approach keeps things manageable:
Now: close urgent gaps, such as no MFA, untested backups or unsupported software.
Next 6 to 12 months: add monitoring, formal training and incident response planning.
Later: invest in improvements like network segmentation, deeper logging and regular testing.
Put dates and owners on each item, and revisit the plan each year.
Boards and owners respond to clear, nonjargon explanations:
Connect each expense to resident safety and operations. For example, backups mean you can keep documenting medication administration after a ransomware event.
Show what is already covered and what remains.
Describe the consequences of inaction: downtime, regulatory exposure, breach notification duties and damage to trust.
Avoid fear tactics and invented numbers. Plain facts persuade better.
Which risk does this reduce?
Does it replace something we already pay for?
Who will operate it day to day?
What happens after the first year?
How will we know it is working?
UnityCare IT helps healthcare and senior-living organizations prioritize security spending and build phased plans that fit their budgets. If you are preparing next year's numbers, we can help you separate must-haves from nice-to-haves.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172