The Labcorp settlement with 44 state attorneys general answers this question the hard way: after costs $2,287,455, plus whatever you spend implementing the mandated security program. The 2019 AMCA breach exposed data from more than 27.5 million individuals, including over 10.2 million Labcorp patients. One settlement requirement stands out: Labcorp must now employ a Chief Information Security Officer to oversee its information security program.
This raises a question many healthcare organizations face: is a dedicated CISO necessary before you have a breach, or can you distribute security responsibilities across existing roles until something goes wrong?
The Case for Waiting
You're managing a lean operation. Your IT director handles security alongside infrastructure. Your compliance officer owns HIPAA. Your privacy official manages PHI policies. This distributed model has worked for years without incident.
The financial argument is straightforward. A qualified CISO commands a substantial salary, and smaller covered entities struggle to justify the expense when they haven't experienced a breach. You can point to your risk analysis, your Business Associate Agreements, your annual training. You're compliant on paper.
Some practitioners argue that the HIPAA Security Rule doesn't explicitly require a CISO role. The rule mandates a security official (§164.308(a)(2)) but doesn't specify credentials, title, or whether that person must focus exclusively on security. You can meet the requirement by designating your IT director or even your compliance officer to serve as security official while they maintain their other responsibilities.
For organizations with limited vendor relationships and straightforward technical environments, this approach can work. If you're a small practice using a single EHR vendor and a billing service, your attack surface is manageable. You can conduct vendor due diligence, review SOC 2 reports, and monitor for incidents without building a separate security function.
The Case for Appointing One Now
The Labcorp settlement makes the opposing argument concrete. The breach occurred at AMCA, Labcorp's debt collection Business Associate. The hacker accessed AMCA's network from August 1, 2018, until March 30, 2019, eight months before detection. During that window, the attacker exfiltrated names, Social Security numbers, financial information, medical test information, and diagnostic codes.
Labcorp didn't cause the breach directly, but the settlement holds them accountable for vendor risk management failures. This is the practical reality of the Business Associate relationship: you remain liable for how your vendors protect PHI, even when the breach happens entirely on their systems.
A dedicated CISO brings focus that distributed security responsibilities can't match. When security is one of seven things on someone's job description, it competes with infrastructure projects, compliance audits, and daily operations. A CISO wakes up every day thinking about one thing: how someone might compromise your systems or your vendors' systems.
The settlement's requirements reveal what a CISO should actually do. It's not just policy writing. Labcorp must now maintain a vendor risk management team, use security assessment and management tools for vendor monitoring, contractually require debt collectors to conduct penetration tests and annual SOC 2 Type 2 audits, and implement procedures for reporting vendor security incidents to senior management. Someone needs to own this work, and it's not a part-time job.
The AMCA breach also demonstrates that vendor incidents don't stay contained. AMCA filed for bankruptcy. Labcorp paid $2,287,455 to states and agreed to a $35,000,000 class action settlement earlier in the year. Other AMCA clients face ongoing litigation. When your Business Associate fails, you're not just managing a breach notification, you're managing financial exposure, regulatory scrutiny, and potential loss of the vendor relationship itself.
Where Practitioners Actually Land
Most healthcare organizations make this decision based on size and complexity, not principle. If you're a health system with dozens of Business Associates, multiple facilities, and complex data flows, you probably already have a CISO or you're building the business case for one.
Mid-sized organizations struggle most with this question. You're large enough to have meaningful vendor relationships and regulatory risk, but small enough that every senior hire requires board approval. You're trying to decide whether to promote your IT director into a security-focused role, hire a fractional CISO who splits time between organizations, or keep distributing security responsibilities while investing in tools and training.
The practical middle ground involves elevating security within existing roles before creating a dedicated position. Your IT director becomes IT and security director with explicit time allocation for security work. Your compliance officer takes on vendor risk management as a core responsibility, not an annual checkbox. You document security leadership clearly in your policies and hold that person accountable for outcomes, not just process compliance.
Our Take
The question isn't whether you need someone focused on security leadership. You do. The question is whether that focus can coexist with other responsibilities or requires a dedicated role.
If you share PHI with more than three Business Associates, you need dedicated security leadership. The vendor risk management work alone (due diligence, contract reviews, ongoing monitoring, incident response coordination) requires consistent attention that a multi-role executive can't provide alongside infrastructure management or compliance auditing.
The Labcorp settlement makes one thing clear: regulators now expect you to actively manage vendor security, not just sign Business Associate Agreements and hope for the best. The settlement requires Labcorp to minimize the PHI shared with debt collectors, maintain a vendor risk management team, and use security assessment tools for continuous monitoring. This is operational work that needs ownership.
You can start without a CISO title if you're genuinely small and simple. But you can't start without someone who has the time, authority, and accountability to answer this question every week: what are our vendors doing with our patients' data, and how do we know they're protecting it?
The alternative is learning the answer the way Labcorp did, eight months after a hacker has been inside your Business Associate's network.




