

Part 3 of 3. Two numbers have been moving in opposite directions for a decade, and where they crossed is the most under-priced risk in healthcare private equity right now. Here is the arithmetic, and what to do about it before July 2027.
In January 2015, a telehealth vendor serving the Veterans Health Administration had a security breach affecting more than 7,000 patients. Ordinary enough.
A year later, in January 2016, that company acquired Peachstate Health Management, a Georgia clinical laboratory operating as AEON Clinical Laboratories.
When OCR investigated the 2015 breach, it noticed the acquisition — and opened a separate compliance review of the company that had just been bought. Peachstate had no involvement in the breach that triggered the investigation. None. It had simply been bought by the company under scrutiny.
What OCR found at Peachstate was the same thing it finds nearly everywhere it looks: no security risk analysis had ever been conducted. No compliance review procedures. Undocumented security policies. The resolution — $25,000 and a corrective action plan — was announced in May 2021 (HHS; background via Bass, Berry & Sims).
Count the years. The breach was 2015. The acquisition closed in 2016. The finding landed in 2021.
The dollar figure is beside the point — $25,000 is a rounding error on any transaction. What matters is what the case shows about how these investigations actually unfold: an OCR inquiry that begins at one organization can widen into a compliance review of others connected to it. For a fund running a roll-up, that is worth sitting with. It describes a path by which one add-on's incident draws attention to companies that had nothing to do with it.
Here is the argument this entire article exists to make. Two numbers have been moving in opposite directions, and almost nobody has noticed they crossed.
The average North American buyout holding period ran roughly 4.9 years across 2004–2013. By 2023 it was 7.1 years (Preqin via S&P Global). Bain's 2025 data puts the global buyout average at approximately 7 years; median holds sit around 5.4 years.
Every sponsor reading this already knows that number, and knows why. A slower exit environment has stretched every hold in the portfolio.
This is the number nobody has put next to the first one. Take the HIPAA settlements OCR announced in 2026 and measure the distance from the underlying incident to the resolution:
| Organization | Incident | Resolved | Elapsed |
|---|---|---|---|
| Assured Imaging | May 2020 | 2026 | ~6 years |
| MMG Fusion | December 2020 | March 2026 | ~5.3 years |
| Regional Women's Health Group / Axia | December 2020 | 2026 | ~5.5 years |
| Consociate Health | November–December 2021 | 2026 | ~4.5 years |
| Star Group Health Benefits Plan | October 2021 | 2026 | ~4.5 years |
| Peachstate / AEON | January 2015 | May 2021 | ~6.3 years |
Call it five years, give or take.
When holds averaged under five years and OCR resolutions landed five to six years after the incident, the math worked in the sponsor's favor without anyone having to think about it. A latent HIPAA matter at an acquired company surfaced after the exit. It was the next owner's problem, priced into nothing, discussed by no one.
At a seven-year hold, that is no longer true. The enforcement lag now fits comfortably inside the hold period.
Which means the pre-acquisition compliance failure you did not diagnose at diligence is now far more likely to surface on your watch — during the value creation window, in the middle of an integration, or worst of all, while a sale process is live.
Nobody decided this. No regulator announced it. It is an emergent property of two independent trends crossing, and it has quietly repriced a risk that most healthcare funds still treat as an IT diligence line item.
Standard cyber diligence asks a version of: Has the target experienced a data breach or security incident?
In a meaningful number of cases, the honest answer is “no” and the accurate answer is “we don't know.”
Part 2 of this series covered MMG Fusion, a dental software vendor whose December 2020 breach exposed approximately 15 million individuals. That breach was never reported. OCR did not learn of it from a notification; it opened an investigation in March 2023 after receiving a complaint, and the data had already surfaced on the dark web. Had that company been a diligence target in 2022, its management could have answered the breach question in good faith and been wrong by fifteen million records.
This is why breach history is a lagging indicator and a poor one. The leading indicator — the only one that actually correlates with latent exposure — is far simpler:
Has this organization ever completed an accurate and thorough security risk analysis? When? Performed by whom? And what happened to the findings?
Every enforcement action cited across this three-part series turned on that document. Not a missing firewall, not an unpurchased SIEM. Ask for it by name at diligence. If it does not exist, or it is a certificate from an online portal, you have not found a gap in a control. You have found an organization that has never looked.
This overlay deserves more attention than it gets. PwC's June 2026 health services outlook reports that physician medical groups captured a record 46% of first-quarter deal volume, with deal count up 18% year over year, and that behavioral health and long-term care led market performance (PwC).
Now look at who OCR settled with: a substance use disorder treatment provider, a women's health physician group, a diagnostic imaging provider, a health benefits plan, a dental software vendor.
The hottest asset classes in healthcare private equity and OCR's active enforcement profile are, to a first approximation, the same list. That is not a coincidence — both follow the same underlying fact, which is that these organizations hold enormous quantities of sensitive data on operating budgets that have never supported a security function.
Ten add-ons means ten risk analyses that were never performed, ten EHR instances, ten sets of local administrator credentials, ten vendor stacks with overlapping and unmapped business associate relationships. Integration merges the networks long before it merges the controls, and the shared services function that generates the synergy is the same thing that removes the segmentation that would have contained an incident.
In an operating business, a security gap is a risk. In a roll-up, it is a defect you replicate at every close.
This is the operational point that follows directly from the arithmetic above, and it is the one most integration plans get backwards.
Every clock that matters here runs on calendar time, not ownership time. The five-year enforcement lag started when the incident happened, not when you bought the company. The twelve-month look-back on Recognized Security Practices measures continuous use, not intent. Remediation timelines are set by how long the work takes, which is unaffected by who owns the equity.
Now consider what actually happens to security work in the first year after a close. Systems consolidation gets priority. The EHR migration gets priority. The revenue cycle integration gets priority. Security is deferred until “after the systems settle down” — which is precisely the period when networks are being merged, credentials are being provisioned in bulk, temporary access is being granted, and nobody yet owns the combined environment.
The riskiest twelve months in an acquired healthcare company's life are usually the twelve months immediately following its acquisition. And they are the twelve months during which almost every sponsor has explicitly decided to postpone the work.
PwC's 2026 outlook puts it directly: buyers now demand measurable operating impact from AI rather than pilot-stage promises. But AI in revenue cycle and analytics depends on large data volumes and complex vendor ecosystems, and in a PE-backed healthcare platform it is almost always being layered onto acquired legacy systems that lack modern controls.
Every AI capability that supports your value creation thesis is also a new flow of protected health information through a vendor chain that predates it. Both of those things are true at once, and the diligence usually only measures one.
Part 1 of this series covered the delay: the HIPAA Security Rule overhaul slipped from a May 2026 target to roughly July 2027. Most of the industry has read that as breathing room.
For a fund, it is the opposite, and the reason is straightforward:
If your hold period puts an exit in 2027 or 2028, your buyer's diligence will be run against the new rule, not the current one.
The delay is not relief. It is the last window in which remediation is a planned capital expenditure rather than an emergency finding in someone else's diligence report — and remediation priced under deal pressure is remediation priced at a discount to your equity.
The scale is knowable. HHS estimated the proposed changes would cost the industry roughly $9 billion in the first year and $6 billion annually thereafter. That cost does not land on the industry in the abstract. It lands on operating companies — yours among them — and it is either budgeted across 2026 and 2027 or absorbed in a purchase price adjustment.
The requirements themselves are all capital and operating projects with real lead times: MFA and encryption at rest and in transit, network segmentation, penetration testing every 12 months, vulnerability scanning every six, an annual compliance audit, an asset inventory and network map refreshed at least annually, written procedures to restore critical systems within 72 hours, and 24-hour notification obligations flowing between covered entities and their business associates (HHS NPRM fact sheet). The “addressable” category — the flexibility to document why you did not do something — goes away entirely.
Set against that, the downside case is well documented. Healthcare has been the costliest industry for data breaches for thirteen consecutive years, averaging $6.64 million per incident in IBM's 2026 report. A live OCR investigation or an unremediated risk analysis finding discovered during a sale process is not a line item. It is a valuation event and, occasionally, a timeline event.
For platforms with rural footprints, the CMS Rural Health Transformation Program is $50 billion over 2026–2030, roughly $10 billion per year, awarded to all 50 states on December 29, 2025, with FY2026 state awards ranging from $147.3 million to $281.3 million. Cybersecurity strengthening is named among the allowable technology-infrastructure uses, alongside interoperability, telehealth, and AI-assisted clinical applications (CMS).
State-level allocation decisions are being made now. This is a funded remediation path that most sponsors have not connected to their security budget, and the window for influencing where the money goes is open rather than theoretical.
Not $6.64 million. Not $9 billion.
Five years. That is roughly the distance between a healthcare organization's security failure and the day a regulator puts a number on it.
For most of the last two decades, that lag was longer than a hold period, and healthcare private equity got to treat HIPAA enforcement as somebody else's timing problem. At a seven-year hold, it is yours.
The rule is not final until July 2027. The lag is running right now, on every company you already own, from breaches that may have already happened.
Cybersecurity Advisory Group works with private equity sponsors and their healthcare portfolio companies. Pre-close cyber and compliance diligence, portfolio-wide vCISO engagement covering policies, risk management, board reporting, vendor oversight, and incident response, and HIPAA risk assessment across a platform and its add-ons.
The premise is straightforward: security leadership sized and priced for companies that will never hire a full-time CISO, delivered by someone who has sat in both the CISO chair and the CEO chair and thinks in terms of risk, revenue, and reality.
Book a free 30-minute Security Clarity Session. We'll go through where a platform or a target actually stands, what the proposed Security Rule would require of companies that size, and what a realistic remediation budget looks like across a portfolio. No pressure, no jargon, and no homework before we talk.
Book Your Free 30-Minute Security Clarity Session →
This concludes the three-part series. Part 1 — HIPAA's Deadline Moved. OCR's Didn't. covers provider organizations. Part 2 — A $10,000 HIPAA Fine Is Worse News Than a $10 Million One covers health tech and digital health vendors.
Enforcement and transactional diligence
Deal environment and hold periods
Regulatory requirements and timeline
Cost data and funding
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn
