AWS Public Sector Blog

What HCLS security teams can do this quarter to close the execution gap

What HCLS security teams can do this quarter to close the execution gap

Most security teams know what’s needed to defend their organization. Regulatory guidance is available, threat intelligence sharing has increased, and risks are well-documented. So why are healthcare and life sciences (HCLS) groups, from commercial payors to public health systems, still facing recurring incidents or falling behind in protecting sensitive information? The answer is the execution gap: the space between knowing what to do and the ability to get it done.

When working with health systems, I have seen security teams who could name most gaps in their physical or Amazon Web Services (AWS) environment. Awareness or execution were not their primary problems. Evidence unavailability or governance immaturity drove many of their issues. Unfortunately, this is the norm and not the anomaly. Controls were operational but lacked evidence or consistent follow through, including disaster recovery tests with no captured results, logging with no active monitoring, or governance meetings with no documented action items. Other teams had the reverse problem. They were so consumed by manual evidence collection that control execution slipped.

Both teams want to succeed, but the ever-changing regulatory environment and emerging security risks make it difficult to close the execution gap. To help you, instead of being a to do checklist, this post explores the widening knowing-doing gap and offers suggestions on what you can start changing now using existing resources.

The compounding risk spiral

Three forces are simultaneously pulling in the same direction: economic pressure, regulatory requirements, and AI-enabled threats. While manageable alone, together they compound in ways most security programs aren’t designed to absorb.

Economic pressure is real and accelerating. Reimbursement cuts, acute for nonprofit health systems, community hospitals, and academic medical centers already operating on thin margins, are usually felt by security in the form of reduced headcount or funding. This usually impacts monitoring, patching, and evidence collection. Someone absorbs the work into their existing workload or it’s deprioritized, risking overall defense and compliance.

The regulatory landscape is moving faster than teams can absorb. It’s not only the Health Insurance Portability and Accountability Act (HIPAA) anymore. State privacy laws are expanding, carrying shorter compliance windows, potentially conflicting requirements for multistate groups, and costly noncompliance. AI governance laws are emerging rapidly with aggressive enforcement timelines.

Most teams struggle to keep pace with one regulatory change; three at once introduces unintended risk, cost, and adoption pressures. The problem isn’t understanding the requirements but whether your governance program, resources, and executive support can keep pace with the rate of change.

AI-enabled threat activity targets healthcare specifically. The timing between vulnerability identification and exploitation is shrinking. According to Cogent Security, the window has reduced to 12 hours from 125 days. Healthcare groups, especially in the public sector, are targeted because resource constraints are well known, resulting in security teams having difficulty remediating fast enough to ward off unauthorized actions and continuing to widen the execution gap.

The 2026 Verizon Data Breach Investigations Report confirms the acceleration. This year’s report indicated that vulnerability exploitation surged 55% year-over-year to become the leading initial access vector for the first time in the report’s 19-year history. Meanwhile, Comparitech reports that 120 ransomware attacks targeted hospitals and clinics in Q1 2026 alone.

These aren’t separate problems to solve independently, which is why they compound. Strained teams fall behind on security posture work, leading to control weakness accumulation. This often translates to increased incident probability, with the organization spending more on reactive triage without catching up. The funding needed for security maturity is now spent on incident management.

The common thread between the three is capacity and needing to do more with what you have without it becoming burdensome.

Your problem isn’t only your problem

A security gap is an ecosystem problem, but many treat it as internal. Think about who might be connected to your systems or environment: payers, providers, electronic health record (EHR) vendors, state health information exchanges, pharmacies, and members. Third-party interconnection means that when one organization has an unaddressed gap, everyone connected to it inherits a portion of that risk. Controls are strongest when the connections between domains are secure and there is continuous collaboration to keep them protected.

The execution gap isn’t about one health system failing to maintain their controls, but how you and your providers are intertwined and must collaborate to address the shared risk.

The access you haven’t detected

When was the last time you had full confidence that nothing unauthorized was happening in your environment? The answer often heard is “we have not had an incident yet.” Without continuous monitoring, that often means “we have not detected one yet.”

Dwell time is the window between unauthorized access and its discovery. For teams that can’t staff or afford around-the-clock security operations monitoring, that window stretches and damage accumulates.

Your cloud detection services can help close this gap and provide visibility where it’s lacking without adding headcount or constraining teams. For example, Amazon GuardDuty runs continually across accounts and workloads, surfacing findings on unauthorized access, credential misuse, and data exfiltration that would otherwise sit undetected. When GuardDuty identifies a finding, Amazon Detective correlates activity across your logs, network flows, and API calls for event reconstruction, significantly reducing investigation time and expediting root cause determination and remediation. This requires no manual effort from team members or reassignment. Instead, team expertise focuses on response and control improvements rather than manual log review or incident retracing.

Why checkbox compliance must remain in the past

Historically, many organizations’ security compliance efforts were focused on what’s necessary to pass the latest audit or customer assessment. They were checking off an annual compliance requirement instead of taking security seriously, creating false confidence and significantly increasing risk. Passing an audit means your controls met the criteria at the time of the assessment. It doesn’t mean those controls are operating as designed between audits or that data privacy protections are consistently adequate.

The pattern across resource-constrained HCLS organizations is consistent: compliance-as-event (what’s needed to pass) rather than compliance-as-operating-posture (continuous and evolving). Due to resource constraints and unfunded regulatory mandates, teams scramble to pass regulations and then revert to baseline or delay remediations until the next cycle. They’re usually surprised when next year’s assessment criteria don’t match the prior year or their remediation no longer fully meets this year’s requirement, leading to a new exception. Even without the new HIPAA Security Rule changes, enforcement actions now consider how risks from the addressable requirements were handled. That would be an expensive surprise to someone who believed that they were compliant because the rules weren’t mandatory. Whether an organization is a small practitioner or a large nonprofit community hospital, when resources are stretched, remediation timelines and framework or regulatory change maintenance are challenged as well.

This is where you determine whether your operating processes are making your team’s work invisible or unsustainable. The shift from annual evidence collection to continuous documentation is where automation matters most. Passing the current regulations isn’t enough. You need to put systems in place that will ease the overall burden. This will also organically help with posture strengthening and shifting your organization from reactive to proactive.

The privacy dimension you’re probably underestimating

When the industry talks about the execution gap, the default framing is security. But the downstream consequence of a healthcare incident is rarely a security issue alone. It’s a privacy violation, with data exposed, patients affected, and trust eroded.

Many HCLS organizations merge privacy and security rather than treating privacy as a parallel discipline with its own governance, impact analysis, and by-design standards. The regulatory scrutiny is increasingly coming from the privacy side: state privacy, AI data-use rules, and patient rights provisions many security professionals aren’t traditionally skilled to handle.

A practical starting point is to gain visibility into what sensitive data, such as protected health information (PHI), you have and where it lives. Services such as Amazon Macie help you discover health-related data located in unmonitored locations across Amazon Simple Storage Service (Amazon S3) storage. That visibility is the first step toward governing what you can’t currently see, and it shifts data privacy from aspiration to operational capability.

When deciding if your privacy program is sufficient, examine whether you have true data governance or have security controls that merely happen to protect data. Also look at whether the time spent on maintenance has been sufficient.

The path forward starts this quarter

The postponement to the HIPAA Security Rule changes gave you time, but a delayed deadline doesn’t delay your risk. If enacted, all addressable requirements become required. If your team can’t handle your current compliance workload, what happens when the HIPAA or new federal or state regulations arrive? Because of the deferral, you can close gaps at a controlled pace before they become the next obligation you’re juggling. The following path is how to take advantage of the extra time while also beginning to close your own execution gap.

None of this requires a massive transformation or additional resources. It requires sequencing.

Days 1–30: Increase visibility into your system

Deploy Amazon GuardDuty in your environment for continuous detection. Amazon Macie can then be run against your Amazon S3 storage to identify sensitive data in unexpected locations. Afterwards, conduct a shared-responsibility analysis, which maps each compliance requirement to your obligations or your cloud provider’s attestable controls, revealing which items your team must actively prove and which are already covered. It’s a high-impact exercise that can provide HCLS organizations significant efficiencies. Finally, use AWS CloudTrail for API activity logging across your accounts.

Collectively, these lay the groundwork to provide the visibility and monitoring manual efforts can’t sustain. They also provide effective, automated discovery, analysis, and evidence logging that establishes an enhanced baseline.

Days 30–60: Operationalize your visibility

Configure AWS Security Hub to aggregate account findings and evaluate your posture against Foundational Security Best Practices, providing you with a single view instead of isolated alerts. Conformance packs in AWS Config further help by continually evaluating configurations against HIPAA and National Institute of Standards and Technology (NIST) SP 800-53 control baselines, identifying risks as they occur instead of during periodic reviews or audit preparation.

Those steps operationalize your new visibility to make it actionable and increase detective and prevention layers of defense. It also helps you move from a state of preparing for audits to operating in an audit-ready state that continuously protects your organization and helps you demonstrate compliance. Your evidence now becomes a byproduct of operations and not a quarterly sprint consuming team capacity or shifting their focus from defense and posture improvement.

Days 60–90: Communicate and sustain

Take your new visibility and translate it into language your leadership can act on. Quantify what you found and frame it as business risk instead of technical debt. If you discovered your team was already doing the work and the operating model was hiding it, show leadership: here is what we do, here is the evidence, and here is how we sustain and evolve it. This is the bridge from discretionary project funding to sustained operational investment.

Each step is independently valuable and moves you from knowing what’s needed to doing it and being able to demonstrate program maturity.

What comes next

The execution gap won’t close because someone publishes another best-practices guide or leadership agrees to fund additional staffing, probably at the cost of needed technology. It closes when teams start using the solutions they possess now to shrink visibility gaps, automate evidence, and reduce manual efforts. This means your team can focus on defense, strategy, and translating findings into language that moves leadership to act.

This is the first of three connected posts. The focus in this post is to close the execution gap with existing resources. The next post examines how AI can multiply a stretched team’s capacity to help strengthen your security posture maturity without increasing overhead or risk. The last post turns to the element most technical programs struggle with: communicating risk to leadership in language that secures sustained support.

Get started

Activate Amazon GuardDuty in your account for continuous detection and initiate a shared-responsibility analysis using the AWS Compliance Center. Specific HCLS guidance can be found at AWS HCLS compliance solutions or contact your account team for help.

Which of these forces (economic pressure, regulatory acceleration, or AI-enabled risks) is hitting your team hardest right now?

Adam Birnbaum

Adam Birnbaum

Adam Birnbaum is a Senior Assurance Consultant with AWS Security Assurance Services, specializing in helping HCLS organizations strengthen their security posture while also guiding their efforts to close operational and regulatory risks. His background spans nearly 30 years across healthcare security, compliance, governance, and risk management from program inception through maturity.