A True Story on Implementation
Healthcare didn't decide one morning to adopt a new cybersecurity framework. It got here through pressure and accumulation — ransomware that shuts down clinics, third-party incidents that ripple across an ecosystem, and board questions that keep coming back:
Are we improving? Are we exposed? Are we prepared?
That is the context for the NIST Cybersecurity Framework 2.0, and why it is landing differently in healthcare than the version before it. NIST first released the framework in 2014 and refined it in 2018. But on February 26, 2024, it published CSF 2.0 — the first major structural update since inception, adding a sixth function: Govern.
The headline change is easy to summarize and hard to overstate. Govern makes explicit what healthcare has learned the hard way: cybersecurity is not just a technical capability. It is a governance problem, an enterprise risk problem, and — done well — a patient safety capability.
Why healthcare should take note
The framework is voluntary. It is not a law. But in healthcare, frameworks are the language of credibility — how you demonstrate you are not improvising. CSF 2.0 is built to help any organization understand, assess, prioritize, and communicate cyber risk, and it arrives as regulators sharpen expectations. HHS OCR has proposed a rule to strengthen the HIPAA Security Rule, continues to emphasize “recognized security practices” under the 2021 HITECH amendment, and in its January 2026 newsletter signaled more scrutiny of risk management and system hardening. CSF 2.0 is being adopted not as a trend, but as a structure that makes risk legible to leadership, defensible to regulators, and measurable over time.
Watch the sessionClearwater Monthly Cyber Briefing — Discussion on NIST CSF 2.0
The real shift isn't the new function. It's the new audience.
CSF 1.1 lived inside security teams; executives couldn't use it. CSF 2.0 forces the conversation outward — toward governance, oversight, accountability, and enterprise risk. NIST is acknowledging what boards already decided: cyber risk is business, legal, operational, and reputational risk at once. In healthcare, the translation is even more direct.
It is patient safety risk.
A healthcare story: OU Health starts with standards, not improvisation
Adoption is rarely a tidy strategic decision. Usually an organization tries to measure its program, finds the results subjective and not comparable year to year, and asks a harder question: What are we actually measuring against? That was the turning point for Sean Mathena, Director of Governance, Risk, and Compliance at OU Health. Their prior assessments weren't standards based — “cobbled together from several different standards.”
We wanted to do a standards-based assessment that had an actual maturity score that we could be measured against. Sean Mathena, Director of GRC, OU Health
They began with HIPAA risk assessments, then moved into a NIST CSF 2.0 assessment. It's the story many leaders recognize: not a desire to collect more controls — a desire to stop guessing.
Govern: the moment cyber stops being an IT program
For OU Health, Govern wasn't disruptive because they started with CSF 2.0. What followed mattered more: they are building an enterprise risk program that starts with cyber.
It's no longer just about cybersecurity. It's about enterprise risk, and how cybersecurity integrates with enterprise risk. Dave Bailey, Clearwater
That shift changes reporting structures, board conversations, and budgets. And it delivers what executives keep asking for — metrics. As Mathena put it, leadership is “really interested in getting the metrics out of the CSF.” Boards want directional visibility. CSF 2.0 gives them a way to see movement over time. At OU Health, that framing is explicitly patient-first: when systems go down, when diversion happens, when workflows revert to paper, patients feel it first. Cyber maturity here isn't theoretical — it is operational resilience in service of care.
Measurement changes behavior
Many organizations keep dashboards. Few tie cyber maturity to accountability. OU Health uses its CSF score as an annual goal that “drives things like budget, bonuses, things of that nature” — expecting to be held accountable for improvement year over year. And improvement is the pattern Clearwater sees across the industry.
That gain isn't accidental. It reflects commitment, multi-year strategy, and sustained governance focus. The question stops being Are we compliant? and becomes Are we getting better, and can we prove it?
What to expect when adopting CSF 2.0
The OU Health experience is candid about what the work actually takes:
Tell everyone involved what's coming and what's required. Unmanaged expectations derail assessments fast.
Standards-based maturity needs evidence, context, and cross-functional input. No shortcut to organizational truth.
Keep what you gave the assessor at your fingertips for next year — and for audit readiness.
Findings are governance decisions, not IT backlog. Treated as enterprise risk, they move.
CSF 2.0 and HIPAA: the safer way to operate
HIPAA doesn't mandate a single framework, but enforcement trends and the Security Rule NPRM increasingly expect demonstrable rigor around encryption, hardening, and accountability. CSF 2.0 translates that regulatory direction into a coherent operating model because it:
Compliance tells you what you must do. A framework tells you how to run the program.
Why CSF 2.0 is becoming the backbone of healthcare cyber programs
CSF 2.0 isn't gaining adoption because it's new. It's gaining adoption because it fits — healthcare is being pushed toward governance, evidence, and measurable improvement. OU Health shows the emerging pattern:
The emerging pattern
- A small GRC team chooses standards-based measurement over improvised models.
- Cyber maturity becomes the starting point for enterprise risk.
- Leadership demands metrics and board visibility.
- Results drive budgeting and accountability.
- The program is framed in terms healthcare understands — patient-first outcomes and operational resilience.
Hospitals don't adopt CSF 2.0 to feel more compliant. They adopt it to make cyber risk governable. The Govern function signals what the sector already knows: cybersecurity has matured into enterprise risk management, and healthcare is being asked to prove it, measure it, and improve it.
CSF 1.1 organized security activities. CSF 2.0 organizes accountability. And in healthcare, accountability is no longer optional.
Questions healthcare leaders are asking about CSF 2.0
What is the biggest change in NIST CSF 2.0?
CSF 2.0 adds a sixth function, Govern, alongside Identify, Protect, Detect, Respond, and Recover. It makes explicit that cybersecurity is a governance and enterprise risk problem, not just a technical capability.
Is NIST CSF 2.0 mandatory for healthcare organizations?
The framework is voluntary and is not a law. But in healthcare, frameworks have become the language of credibility. CSF 2.0 makes cyber risk legible to leadership, defensible to regulators, and measurable over time.
How does CSF 2.0 relate to HIPAA?
HIPAA does not mandate a single framework, but the proposed HIPAA Security Rule updates and OCR's emphasis on recognized security practices increasingly expect demonstrable rigor. CSF 2.0 translates regulatory direction into a coherent, measurable operating model.
What maturity improvement can organizations expect from CSF 2.0 assessments?
According to Clearwater's Dave Bailey, the average score for a first-time organization is in the 40s, and the average for a third assessment is in the 70s. That improvement reflects sustained governance focus and multi-year strategy, not a one-time compliance event.
Why does the Govern function matter in healthcare specifically?
Govern formalizes cyber as a risk discipline rather than an IT silo. In healthcare, cyber risk is patient safety risk. When systems go down, patients feel it first, so cyber maturity becomes operational resilience in service of care delivery.
Move from compliance to measurable cyber governance
CSF 2.0 is not a checklist. It is a governance model. If you're maturing your program, integrating cyber into enterprise risk, or preparing for tougher regulatory scrutiny, we can help you build a defensible, measurable path forward. Get out of the storm and into Clearwater.


