

Ransomware doesn’t care how big you are. It shuts down scheduling, locks the EHR, sends ambulances somewhere else, and turns a normal Tuesday into three weeks of paper charts. A 50-person IT department and a two-person IT department both get hit.
The difference isn’t whether it happens. The difference is what the hospital can do in the first 48 hours.
Right now, historic levels of federal and state funding are flowing into rural healthcare through HRSA grants, CMS innovation models, and state Medicaid 1115 waivers. This money is designed to modernize infrastructure, expand telehealth, and stabilize rural facilities. But most rural hospitals I talk to are building their spend plans entirely around clinical equipment and new software—without a line item for the security program that has to sit underneath all of it.
Whether you are looking at the HRSA Small Rural Hospital Improvement Program (SHIP), USDA telemedicine grants, or state-level transformation models, federal funding increasingly permits investments in data security, interoperability, and cybersecurity enhancements.
This means your cybersecurity program isn’t competing with the “real” priorities for these dollars. It is one of them.
Hospitals that understand this early get their security work funded. The ones that treat security as an afterthought will be paying for it out of operating margin in 2028—if they can afford to pay for it at all.
Here’s what I don’t run into: a rural hospital CEO who thinks they are secure.
Almost every leadership team I’ve sat with can name their weak spots without looking at a report. The vendor with too much access. The server that can’t be patched because the clinical application won’t run on anything newer. The nurse manager who is also, functionally, the security awareness program.
Awareness isn’t the shortfall. Capacity is.
Rural facilities face the threat profile of a large health system on the staffing model of a small business. You cannot train your way out of that. You cannot buy a software tool that magically fixes it. What closes the gap is leadership capacity—someone whose job is to own the security program.
For most rural hospitals, a full-time CISO (costing north of $200,000 a year before benefits) is completely out of reach. That’s why fractional CISO leadership exists, and it’s why leveraging grant funding to build that capability makes sense for organizations that could never justify a full-time hire.
The Healthcare and Public Health sector continues to be a top target for cyberthreats, reporting hundreds of ransomware attacks and data breaches to the FBI’s Internet Crime Complaint Center (IC3) year after year.
Healthcare isn’t at the top of that list because attackers admire our security. We’re there because downtime in a hospital creates a pressure to pay that downtime in most other industries does not. A rural hospital that is the only emergency department within 60 miles is, from an attacker’s point of view, a highly motivated customer.
Let’s be honest about what money does and doesn’t do. No grant award has ever patched a server, staffed an overnight alert queue, or written a downtime procedure.
What funding can pay for is the work rural hospitals consistently can’t build alone:
That last one is where the most money gets wasted. Hospitals buy a policy set, file it, and assume the control exists. It doesn’t. A policy is a statement of intent; a control is something you can demonstrate on the day an auditor, an insurer, or a plaintiff’s attorney asks you to.
The most common mistake I see with new funding is that the buying starts before the measuring does. A hospital gets an award, a vendor gets a meeting, and eighteen months later there’s a tool nobody configured and no clearer picture of the actual risk.
Run an assessment first. Understand where your controls stand today. Then you will know four things you can’t know otherwise:
That fourth category is your budget justification. It is also, in my experience, a much shorter list than leadership expects.
“Improve your cybersecurity” is not a directive. It’s a mood.
What a rural IT lead can act on sounds like this: These 340 endpoints get this agent by March 31. These twelve accounts with standing admin rights get converted to just-in-time access. These six policies get formalized and signed.
The same specificity applies to every vendor you onboard with new funding. New telehealth platforms, AI documentation tools, and analytics vendors all get access to patient data, and each one becomes your problem if they are breached. Risk-score them before you sign, not after.
I’m Melissa Thornton. I run Cybersecurity Advisory Group, and before I was a CISO, I was a CEO. Most security consultants think in terms of frameworks and audits. I think in terms of risk, revenue, and reality. I translate cyber risk into business language so we can build a program that protects your patients without slowing down your team.
For rural hospitals looking to modernize their security, I provide executive-level security leadership—without the executive price tag. Depending on where you are today, that usually looks like:
Your local IT team or MSP keeps doing what they do well. I handle the governance, strategy, and board-level translation—the layer rural hospitals almost never have and can’t easily hire for.
If your hospital is looking at modernization funding and nobody has answered the question “where does cybersecurity fit in this plan,” that’s a 30-minute conversation, not a procurement cycle.
Book a free 30-minute Security Clarity Session. We’ll go through where your controls actually stand, which gaps your funding can reasonably cover, and what a realistic first year looks like for a team your size. No pressure, no jargon, and no homework before we talk.
Most organizations leave that call with more clarity about their security posture than they’ve had in years—whether we end up working together or not.
Book Your Free 30-Minute Security Clarity Session →
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn

