Problem
Healthcare is a large and vital sector in Minnesota; this makes it a larger target for attacks and increases the severity of service disruptions. Cloud adoption provides solutions for many problems but also introduces new ones that must be addressed. No solution is ever foolproof, but the best way to ensure longevity is through mitigation. The question remains, how is the decision made for what to prioritized? Quantitative data provides a solution and visualizes the impact of many simulated scenarios. This data provides the structure to allocate funds in a meaningful and precise manner to decrease the risk to the state financially through mitigation expenses which in turn improves outcomes for those relying on the system.
Roles and Responsibilities
Enterprise Architect – Seth Breuer
Vendor Breach – Relying on partners means entrusting the security of data to them. A breach of their system could place our data at risk. As the Enterprise Architect, I ensure that systems isolate critical data and integration with vendors is secure. This reduces our liability during and ability to operate in the case of a vendor being compromised.
Ransomware Attack – Ransomware poses a serious threat to critical health systems, disruption of care, and public health operations. As Enterprise Architect, I must ensure that systems are resilient and segmented to decrease downtime during the recovery process.
Cloud Provider Outage – An outage from a cloud provider could make critical applications unavailable, impacting operations and critical functions. As Enterprise Architect, I design multi-cloud and multi-region systems that prioritize redundancy, failover performance to ensure normal operations of systems during provider disruption.
Chief Information Security Officer (CISO)
Cloud Data Breach – If someone access PHI because they have access to misconfigured cloud storage or compromised credentials, it would violate regulations under HIPAA and damage trust in our organization. As the CISO, I put in place encryption, multi-factor authentication, and continuous monitoring to mitigate this risk.
Insider Threat – Internal users can access or exfiltrate data without having it pass through the perimeter. In response I will make sure that privileged access and identity management is enforced across the enterprise, that employees are trained on how to identify threats and behavior analytic tools are made available across all systems.
API Security Vulnerabilities – Lack of security or excessive security of APIs can expose backend systems for exploitation. This is critical to the CISO role as modern health care apps often depend on APIs for interoperability. Mitigating this exposure can be accomplished by deploying token validation, zero-trust design, and API Gateways.
Chief Compliance Officer
HIPAA Noncompliance – Noncompliance with HIPAA regulations could result in major fines and reputational damage if patient data is mishandled in the cloud. This risk is crucial for the CISO because maintaining regulatory alignment directly impacts the organization's trust and legal standing.
Data Mismanagement – Inadequate data governance, such as improper classification or access control, could lead to data leaks or breaches. The CISO must ensure that privacy controls, encryption, and audit mechanisms are in place to safeguard sensitive health information.
Third-Party Compliance Failure – If cloud vendors or partners fail to meet compliance requirements, the organization remains liable. The CISO must manage vendor assessments and ensure contractual compliance to reduce supply chain risk.
VP Marketing
Reputation Damage and Patient Trust – Patients truly lose trust in the company when they learn that health medical care has been impacted due to data breaches. They may decide not to submit personal information or switch providers as a result. In my role as vice president of marketing, I would concentrate on restoring that trust by open communication, community involvement, and understanding information regarding the security of patient data.
Communication Damage during incident response – In the event of a data incident, a company's inability to effectively communicate can cause fear to spread immediately. They begin to believe the worst, which damages the company's reputation. It is important that I help plan communications that are clear and easy for both employees and the general public to understand.
Employee awareness and public Education gaps – Only a few people completely understand how cybersecurity protects them. This could result in the spread of misinformation so it's important that individuals know this. I would lead educational initiatives on the importance of compliance, security measures, and data protection in an understandable way.
Pre-implementation risk portfolio
The current risk is far above the level that should be tolerated at a level that it poses a significant threat to the operations of the state. Currently the state faces a 54.4% chance of a loss exceeding $10 million for the year. Solutions should not only decrease the risk this year, but also decrease the cost of protection for future years so that the initial investment is proportional to the actual benefits it provides. Due to the nature of the loss exceedance tolerance curve decreasing quickly which means that there is a greater tolerance for small loss rather than a large one, although at the extremely high end the risk falls below the curve, it does not fall beneath the curve quick enough.
| Risk | Prob. | Range (90% CI) | Expected loss |
|---|---|---|---|
| Cloud data breach CISO |
35% | $2M – $25M | $3,323,179 |
| Ransomware attack Enterprise Architect |
15% | $5M – $40M | $2,590,412 |
| Data mismanagement CCO |
30% | $1.5M – $10M | $1,372,088 |
| Reputation damage VP Marketing |
18% | $2M – $15M | $1,189,306 |
| Vendor breach Enterprise Architect |
12% | $2.5M – $20M | $1,036,165 |
| Insider threat CISO |
25% | $1M – $10M | $1,010,003 |
| HIPAA noncompliance CCO |
25% | $1M – $8M | $863,471 |
| Cloud provider outage Enterprise Architect |
8% | $3M – $24M | $828,932 |
| API security failure CISO |
20% | $500K – $8M | $570,564 |
| Communication failure VP Marketing |
14% | $1.5M – $8M | $552,007 |
| Third-party compliance CCO |
20% | $800K – $6M | $528,581 |
| Awareness gap VP Marketing |
20% | $1M – $5M | $504,068 |
| Total expected inherent loss | $14,368,776 | ||
Solutions
CISO – Cloud Data Breach – Encryption
Monte Carlo simulations reveal that data breaches to the cloud are one of the significant expected annual losses for our organization ranging from $2 million to $25 million depending on level of severity and data exposure. Adding encryption and identity controls will decrease the probability of loss (or "exposure") by approximately 45%, saving millions of dollars in potential fines (from regulatory bodies) and recovery costs. This finding is consistent with recent reports on healthcare security indicating that data breaches are still the most costly threat, averaging over $10 million per event in the U.S. healthcare market (IBM, 2024).
Enterprise Architect – Seth Breuer – Ransomware Attack – Logical Segmentation
Monte Carlo calculations show that ransomware attacks can result in losses ranging from $5 to $40 million each year. To reduce this impact, I would implement logical network segmentation, air-gapped backups, endpoint protection, and zero trust architecture. These measures would reduce the probability of a successful attack by 50% and significantly limit the blast radius of any breach that does occur.
Eddy (2024) states that 70% of cyberattacks on healthcare stem from Ransomware, this number highlights the high potential for the attacks and why it must be addressed. Due to the nature of these attacks, healthcare facilities lose operational capacity and prevent healthcare workers from providing life-saving care. The nature of the care provided is time sensitive, delays in action drastically decrease the likelihood of survival.
In the quantitative framework, ransomware attacks represent the highest-impact risk. The probability of 15% stemming from attackers focuses on the sector and the lower bound of $5 million combined with the $40 million upper bound for loss which results from the critical nature of the sector and officials being forced to negotiate with attackers makes it a primary driver of expected loss on the baseline curve. Based on the simulation, the cost of control of $800,000 is less than half of the expected annual risk reduction of approximately $1.3 million, which highlights the benefit of mitigation and the price effectiveness of our solutions. On top of this, it drastically decreases the worst-case scenario for the risk, decreasing it by 50%.
By implementing the measures suggested, the probability of loss decreases to 7.5%, a 50% drop. The lower bound decreases by 50% due to better data separation and policies that isolate different areas. Due to these solutions, the upper bound drops by 50%. The expected inherent loss due to the risk drops to roughly $648,000 and the loss exceedance curve closes sharply and places the inherent risk associated with the event below the loss exceedance tolerance.
VP Marketing – Reputation Damage and Communication
Depending on the extent of the impact, Monte Carlo simulations show that reputational costs resulting from a data leak could reach $15 million or more. Because it affects patient trust and retention, this is one of the biggest non-technical threats in healthcare. Applying communication and awareness tactics minimizes the likelihood of loss by approximately 55%. This, in turn, helps to rebuild trust and ensures brand stability (IBM, 2025; Edelman, 2024).
Chief Compliance Officer – HIPAA Noncompliance – Compliance Automation
Monte Carlo simulations show that HIPAA noncompliance can cost between $1 million and $10 million annually through fines and lost reputation. Automating compliance checks and audit logging can lower that risk by about 40% by detecting violations early. This aligns with current healthcare trends showing that automated monitoring cuts audit failures in half and helps maintain trust with patients and regulators while reducing the chance of costly penalties.
Post-implementation risk portfolio
The overall probability of loss exceeding $10 million drops from 54.4% to 7.8% after all controls are implemented. Solutions should not only decrease the risk this year, but also decrease the cost of protection for future years so that the initial investment is proportional to the actual benefits it provides.
| Risk | Prob. | Range (90% CI) | Expected loss |
|---|---|---|---|
| Cloud data breach | 19% | $1M – $14M | $980,760 |
| Ransomware attack | 7.5% | $2.5M – $20M | $647,603 |
| Data mismanagement | 20% | $1M – $6.5M | $599,497 |
| Insider threat | 15% | $500K – $6M | $345,580 |
| HIPAA noncompliance | 15% | $500K – $5M | $303,001 |
| Vendor breach | 6% | $1.25M – $10M | $259,041 |
| Reputation damage | 8% | $1M – $7M | $252,125 |
| Third-party compliance | 14% | $500K – $4M | $241,772 |
| API security failure | 12% | $300K – $5M | $211,859 |
| Communication failure | 7% | $750K – $4M | $138,002 |
| Cloud provider outage | 3% | $1.2M – $10M | $127,913 |
| Awareness gap | 9% | $500K – $2.5M | $113,415 |
| Total expected inherent loss | $4,220,568 | ||
Loss exceedance
By implementing the solutions provided, the risk of losing more than $10 million shrinks to 7.8% for the year. Although risk exceeds the tolerance curve at the low end, meaning that small losses exceed the loss curve, importantly potential losses do not exceed the threshold at more serious levels being those over $10 million.
Fig. 1 — Loss exceedance curve, 1,000-trial Monte Carlo simulation. Pre-mitigation (red) vs. post-mitigation (green).
Methodology
Each risk was modeled as a Bernoulli trial asking whether the event occurs this year, combined with a lognormal impact distribution bounded by expert-estimated 5th and 95th percentile values. The simulation aggregated all 12 risks per trial, ran 1,000 iterations, and produced the loss exceedance curve. Control effectiveness was applied as a percentage reduction in probability and residual risk was recalculated to show post-mitigation outcomes. Findings were mapped to NIST Cybersecurity Framework controls so that each identified gap tied directly to a recognized control area.
Outcome
We request approval, funding, and dedicated time to implement these risk mitigation measures. Investing in these controls now will significantly reduce long-term financial exposure, ensure compliance with HIPAA, and protect the continuity of healthcare services for our organization and the public.
Tools
Monte Carlo simulation
1,000-trial loss modeling
NIST CSF
Control mapping
Excel
OneforOne substitution model & data tables
Lognormal distributions
Impact range modeling
What I learned
Translating risk into a distribution of dollar outcomes changed the conversation entirely. The most valuable part of the exercise was not the final number but discovering that several initial mitigation proposals cost more than the risks they addressed. We had to restructure the controls until every one had a positive return. Numbers are the key to the game, without them it is just a debate over labels.