Adam Kehler headshot

Adam Kehler

Director, Consulting Delivery

States are moving quickly to implement Rural Health Transformation Program (RHTP) funding, but RHTP is only one piece of a broader federal effort to modernize rural healthcare. 

Across Centers for Medicare and Medicaid Services (CMS) and Health Resources and Services Administration (HRSA) initiatives, organizations are investing in telehealth, interoperability, AI, cloud modernization and digital care delivery. Every one of those investments depends on one foundational capability: cybersecurity.

The same cybersecurity investments that support RHTP also strengthen organizations pursuing HRSA Health Center modernization, Rural Hospital Flexibility initiatives, CMS interoperability objectives, telehealth expansion and evolving HIPAA Security Rule expectations. 

Rather than viewing cybersecurity as another compliance requirement, states have an opportunity to treat it as infrastructure that enables all these priorities.

That's why cybersecurity has become one of the most valuable eligible investments under RHTP. But there's a design question that needs to be answered early if they want those investments to deliver lasting value.

Most cybersecurity frameworks assume an enterprise health system. Most rural providers aren't one.

Having worked with hundreds of rural healthcare organizations, we've consistently found that success comes from right-sizing cybersecurity expectations to each organization's capabilities while providing a practical roadmap for continuous improvement.

If a state's funding program or vendor requirements are built around enterprise-grade maturity models, rural hospitals and clinics will either fail to qualify, misuse the funding, try to meet requirements they can't sustain or quietly deprioritize security work altogether because it's deemed unachievable. None of those outcomes moves the needle on the resilience that the funding is meant to buy.

The design problem, from a state's seat

Rural providers operate with small IT teams, often one or two IT generalists responsible for everything from clinical applications to networking and cybersecurity. At the same time, an infrastructure must keep serving patients as new tools are layered on top. That's not a temporary gap that a grant cycle closes; it's the operating reality that states are funding into.

Which means the design questions for a state program look different from those for a large hospital system procurement:

  • Should vendor and grantee cybersecurity requirements be tiered by organizational size and capacity, rather than a single statewide bar?
  • Does the program reward providers for measurable improvement over their own baseline, or does it require them to hit an absolute standard that assumes resources they don't have?
  • Are technical assistance dollars built in, so providers aren't left to interpret complex frameworks alone, or is the state just handing over a checklist and a deadline?
  • Do vendor and procurement requirements assume dedicated security operations centers and large specialist teams that most rural applicants can't staff?

Get these wrong, and the funding either goes unspent or results in documentation that demonstrates compliance without materially improving resilience.

Cybersecurity shouldn't compete with transformation funding. It should be embedded within every transformation initiative, from telehealth and interoperability to AI adoption and cloud migration, because none of those investments can succeed without trust, resilience and secure operations.

A maturity-based model fits this funding better than a compliance checklist

Fortunately, states don't have to start from scratch. HHS' 405(d) Health Industry Cybersecurity Practices (HICP) offers practical safeguards designed specifically for resource-constrained healthcare organizations, while the HHS Health Sector Cybersecurity Coordination Center (HC3) provides timely threat intelligence and healthcare-specific guidance. Combined with the NIST Cybersecurity Framework 2.0, these resources provide states with a proven foundation for establishing scalable cybersecurity expectations.

Rather than requiring every grantee to reach the same fixed security bar, a risk-based maturity model approach aligned with NIST CSF 2.0 allows states to:

  • Set a realistic starting requirement that accounts for organizational size, current infrastructure and workforce capacity
  • Define a small number of high-leverage next steps for each maturity tier, the moves that reduce the risk with the resources actually available
  • Track progress against each provider's own baseline over the life of the program, rather than a single go/no-go standard
  • Build cybersecurity into transformation projects (telehealth, data sharing, cloud migration) from the start, instead of treating it as a bolt-on compliance requirement funded separately. This gives states a common language for measuring progress across diverse providers. Rather than simply counting completed projects, states can demonstrate measurable improvements in cyber resilience over time.

This isn't lowering the bar. It's making the bar something providers can clear, which determines whether the state's investment translates into real resilience rather than paperwork.

Where does this fit in program design?

States administering Rural Health Transformation dollars are typically making decisions in a few places where this matters most:

  • Eligibility and scoring criteria for cybersecurity-related grant applications
  • Vendor and technology partner requirements for telehealth, interoperability and cloud initiatives funded through the program
  • Technical assistance structure, whether providers get hands-on support to reach requirements, or just a standard to meet on their own
  • Reporting and outcome metrics, measuring resilience gained, not just controls checked off

We've worked through exactly these design questions with organizations facing the same constraints rural providers do. We help states and program administrators build funding requirements and technical assistance structures that rural applicants can realistically meet, and that produce measurable security improvement, not just a compliance record.

Practical cybersecurity is good cybersecurity

The goal isn't simply stronger cybersecurity controls. It ensures that clinicians can continue delivering care when systems are targeted, that patient information remains protected and that rural communities maintain access to essential healthcare services.

By enabling Rural Health Providers with a right-sized, realistic and consistent approach and resources, they are much more likely to achieve these goals. CGI currently works directly with Federally Qualified Health Centers (FQHCs) and through Health Center Controlled Networks (HCCNs) and Primary Care Associations (PCAs) to provide cybersecurity assessment and advisory services. Through this experience, our team understands the nature of these organizations, the challenges of implementing mature cybersecurity programs, and right-sized solutions that are both effective and achievable.

If your state is finalizing cybersecurity requirements for Rural Health Transformation funding, or you want a second look at whether current requirements are calibrated to what rural providers can actually deliver, we'd welcome the conversation. Connect with us today.
 

About this author

Adam Kehler headshot

Adam Kehler

Director, Consulting Delivery

Adam Kehler serves as Director, Cybersecurity and Governance, Risk, and Compliance (GRC) for CGI, leading the delivery and growth of cybersecurity consulting services for healthcare, government and commercial clients. He helps organizations strengthen their security posture through strategic advisory services, risk management, compliance, offensive security ...