A penalty table alone does not describe business exposure, and a single “cost per record” creates false confidence. Executives should model credible scenarios using documented assumptions, operational dependencies, insurance terms, legal guidance, and ranges that can be updated as controls improve.
01
Regulatory and legal response
Consider privacy and breach counsel, forensic support, notification analysis, regulatory response, document production, corrective-action work, contractual disputes, and potential penalties or settlements. Outcome depends on facts, culpability, cooperation, history, mitigation, and applicable law.
02
Notification and individual support
Estimate data reconciliation, address verification, printing and mailing, call center, website notices, translation, substitute notice, credit or identity services when chosen or required, and response to patient questions. Complexity rises when records are incomplete or vendors hold affected data.
03
Clinical and business interruption
Model appointment disruption, procedure delay, manual documentation, lost billing capacity, claims backlog, overtime, referral impact, vendor downtime, diverted patients, recovery validation, and delayed cash flow. Measure both technology restoration and the time required to return operations to normal.
04
Remediation and resilience
Include identity redesign, endpoint replacement, segmentation, logging, backup modernization, restore testing, application changes, vendor transition, policy revision, training, monitoring, and validation. Emergency remediation is usually more expensive than planned improvement.
Use scenarios to choose controls
Compare the expected reduction from MFA, privileged-access cleanup, endpoint security, logging, segmentation, protected backups, restore testing, vendor oversight, incident exercises, and accurate inventories. Fund controls that reduce plausible high-impact paths, not merely those with the most familiar marketing.
Use ranges and sensitivity tests
Show low, expected, and high assumptions; identify which variables drive the result; and recalculate when evidence changes. The model should support management decisions, not claim to predict an enforcement outcome or guaranteed breach cost.