Collective Blog of Health IT
Episode 264: One Mistake Is All Hackers Need: Building a More Resilient Healthcare Cybersecurity Strategy
Healthcare organizations have never had more technology—or more reasons to protect it.
Electronic health records, connected medical systems, cloud applications, third-party vendors, remote access and a growing number of digital tools have transformed how healthcare is delivered. But that same connectivity creates an increasingly complex cybersecurity environment.
For Jeff Macomber, CTO at Sightview, understanding that environment starts with understanding why healthcare remains such an attractive target for cybercriminals.
In a recent episode of The Collective Voice of Health IT (ep264), Macomber shared his perspective on the evolution of healthcare cybersecurity, the vulnerabilities attackers are exploiting, the growing role of artificial intelligence, and some practical steps healthcare organizations can take to reduce their exposure.
Why Healthcare Is Such an Attractive Target
Macomber's path into healthcare cybersecurity wasn't a straight line. After beginning his career in electrical engineering, he moved into software development, including work in education and voice recognition, before finding his way into healthcare IT more than a decade ago.
That experience gave him a firsthand appreciation for the complexity of healthcare technology—and the challenges that complexity creates for cybersecurity.
Healthcare organizations bring together large amounts of sensitive information, complex technology environments, legacy systems, regulatory requirements and connections to countless other organizations and vendors. When one part of that ecosystem is compromised, the impact can extend far beyond a single computer or application.
Macomber identified three characteristics that make healthcare particularly attractive to attackers.
First, healthcare data is deeply personal. Information about a person's health can be used to establish trust or create fear.
Second, medical information can create significant pressure on individuals and organizations, making it potentially valuable to criminals seeking financial gain.
And third, perhaps most importantly, healthcare depends heavily on its technology infrastructure.
When those systems go down, healthcare organizations don't simply lose access to data. They can lose the ability to conduct normal business.
A cyberattack can prevent staff from accessing records, disrupt communications, interfere with scheduling and billing, and force organizations to revert to manual processes. One disruption can lead to another, creating what Macomber and I described as a kind of "domino effect" or "nesting doll effect" in which one problem exposes another.
The Weakest Link Isn't Always Technology
One of the biggest misconceptions about cybersecurity is that the primary vulnerability is always a technology flaw.
In reality, attackers often gain access through two much more familiar avenues: people and third parties.
Social engineering can persuade legitimate employees to provide credentials or take an action that gives an attacker access. At the same time, healthcare organizations increasingly depend on vendors and other external partners with legitimate connections to their systems.
That interconnectedness is essential to modern healthcare—but it also expands the potential attack surface.
The challenge becomes even greater as attackers gain access to better tools.
AI Is Changing the Cybersecurity Equation
Artificial intelligence is making cyberattacks more sophisticated and scalable.
One of the traditional warning signs of a phishing email might have been obvious grammatical errors, awkward language or an unusual writing style. AI can make those clues much harder to spot.
More importantly, AI allows attackers to create convincing messages and target large numbers of people much more efficiently.
The result is a changing threat environment in which organizations cannot simply rely on employees recognizing the obvious signs of a phishing attempt.
Macomber's message is that organizations need to understand their own vulnerability profile—and recognize that AI can be used on both sides of the cybersecurity equation.
The same technology that can make attacks more effective can also help organizations identify suspicious activity and improve detection.
Security Needs to Work in Layers
If a healthcare organization could build a perfect cybersecurity environment from scratch, the solution might look very different.
But healthcare organizations don't have that luxury.
They have legacy systems, long technology lifecycles, existing vendors, limited resources and business processes that cannot simply be redesigned overnight.
Macomber therefore emphasized a layered, or "nested," approach to security.
The idea is straightforward: don't rely on one security control to protect the entire organization.
If an attacker gets past one layer, another should stand between the attacker and the organization's most sensitive systems and information.
For organizations that aren't able to implement every possible security measure immediately, Macomber highlighted three areas where they can focus.
- Train the Workforce
Employees remain an important part of an organization's cybersecurity strategy.
Regular training and simulated phishing exercises can help employees recognize suspicious activity and understand what to do when something doesn't look right.
But training shouldn't be viewed as simply putting the responsibility on employees. Organizations should also build systems and processes that reduce the consequences of human error.
- Strengthen Network Controls
Firewalls, VPN controls and other network protections remain important tools for reducing an organization's attack surface.
Macomber also pointed to controls such as geographic blocking, where appropriate, as another way organizations can limit unnecessary access.
The goal is to make it harder for an attacker to move from an initial point of access into the broader environment.
- Know Your Vendors
Third-party access is an increasingly important part of healthcare cybersecurity.
Organizations need to understand which vendors have access to their systems, what that access allows them to do, and how those relationships are being secured.
Vendor vetting isn't simply a procurement exercise. It is part of an organization's overall cybersecurity strategy.
Don't Forget the Basics
As technology and threats become more sophisticated, some of the most important cybersecurity practices remain remarkably basic.
Patch systems.
A sophisticated attack doesn't necessarily require a sophisticated vulnerability. Macomber emphasized that attackers can use AI and other tools to chain together vulnerabilities and gain access to a network.
Keeping systems updated and vulnerabilities addressed remains one of the fundamental ways organizations can reduce that opportunity.
Healthcare organizations should also have a clearly defined incident response plan.
When something goes wrong, employees need to know what to do—and just as importantly, what not to do.
Staff shouldn't be expected to diagnose a cybersecurity incident themselves. They should know who to contact, how to report a suspicious event and when to escalate it.
Even something as simple as ensuring that guest Wi-Fi is separated from the organization's primary network can help reduce unnecessary exposure.
Cybersecurity Is About Resilience, Not Just Prevention
Perhaps the biggest takeaway from the conversation is that healthcare organizations cannot realistically expect to prevent every attack.
The objective is to make the organization harder to penetrate, limit the damage when something does happen, and recover as quickly as possible.
That requires multiple layers of protection: trained employees, strong network controls, secure vendor relationships, patched systems, clear incident-response procedures and an understanding of where the organization's greatest vulnerabilities lie.
And as AI changes the way attacks are created and delivered, healthcare organizations will need to continue adapting.
Cybersecurity isn't a one-time project or a technology purchase. It is an ongoing process of understanding risk, strengthening defenses and preparing people and systems to respond when something inevitably goes wrong.
For an industry that increasingly depends on technology to deliver care, that resilience isn't just about protecting data.
It's about protecting the ability to provide healthcare.
You can listen to Michael’s conversation with Jeff Macomber of Sightview at www.wedi.org/category/podcasts
