THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



"Healthcare cybersecurity is entering a new era where resilience matters more than perfection. The organizations that succeed will be those that detect threats quickly, respond effectively and maintain care delivery even when systems are disrupted.”
My career in cybersecurity did not begin in a boardroom or server room. It began in uniform. Nearly three decades ago, I entered the field through the U.S. Army’s Intelligence Security Command, progressed through the Electronic Warfare Directorate and moved into leadership roles across finance, retail, travel, utilities, life sciences and manufacturing. Each sector shaped how I think about risk and adversaries. But healthcare ultimately claimed my full focus, and it has held it for the last decade.
The reason is simple. The stakes are fundamentally different. When a ransomware attack forces a hospital to divert ambulances or delay surgery, every other industry’s security challenges feel abstract. In healthcare, cybersecurity is not only about protecting data. It is about protecting patient safety and continuity of care. That distinction changes everything about how I lead and make decisions.
Building Cybersecurity Programs That Deliver Resilience
Today, I serve as Chief Strategy Officer and Chief Information Security Officer at Fortified Health Security, a healthcare-exclusive managed security services partner. My responsibilities span operational leadership and long-term initiatives across threat intelligence, security operations, threat defense and risk advisory.
Fortified’s mission is to strengthen the cybersecurity posture of the healthcare sector while helping organizations mature their security programs. Too many initiatives still revolve around buying tools instead of building operational capabilities. Our goal is to move organizations toward measurable outcomes centered on resilience, operational visibility and safe patient care.
As a healthcare-exclusive MSSP, Fortified works across academic medical centers, integrated delivery networks, critical access hospitals and community health systems. That visibility allows our teams to identify patterns no single health system can see alone. When one client encounters a new attack technique, every client benefits.
Beyond Fortified, I contribute to the Health Sector Coordinating Council and the HHS 405(d) Task Group, which develop cybersecurity frameworks and best practices for healthcare organizations.
Compliance is a Floor, Not a Ceiling
Healthcare has maintained the highest data breach costs of any industry for fourteen consecutive years, according to IBM’s Cost of a Data Breach Report 2024, with average breach costs reaching $9.77 million per incident. Threat actors target healthcare because it remains highly vulnerable and operationally dependent on uninterrupted access to systems.
“The February 2024 Change Healthcare attack was not a technology failure. It was a program failure and the clearest possible argument for why compliance alone is not a security strategy.”
rategy.” Nothing illustrated this more clearly than the February 2024 ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary and the nation’s largest healthcare payment clearinghouse. The entry point was not a sophisticated exploit. It was a Citrix remote access portal without multi-factor authentication enabled. The ALPHV/BlackCat ransomware group exfiltrated data on approximately 190 million Americans, making it the largest healthcare data breach in U.S. history.
An American Hospital Association survey found that 74% of hospitals reported direct patient care impacts and 94% experienced major financial disruption. UnitedHealth Group’s costs reached $2.87 billion in 2024 alone. That is not a technology failure. It is a program failure.
Healthcare organizations operate under enormous regulatory pressure, but compliance does not equal security. Regulatory frameworks define a floor, not a ceiling. The objective is operational resilience so organizations can continue delivering safe care even when systems are under attack.
Five pressures are shaping healthcare cybersecurity today.
1. Skills gap. Demand for cybersecurity talent continues to outpace supply, and healthcare’s compensation constraints intensify the challenge.
2. Technology complexity. Organizations continue adding EDR, SIEM, connected medical device management and network detection tools. Without skilled operators, complexity compounds and execution suffers.
3. Evolving threat landscape. Ransomware groups, nation-state activity and AI-enabled attack tools continue to raise concerns across critical infrastructure.
4. Regression rather than sophistication. Attackers continue exploiting years-old vulnerabilities because many healthcare environments have not closed those gaps.
5. Financial pressure and regulatory gaps. Healthcare still relies on the HIPAA Security Rule, which was last substantively updated in 2003. Until accountable cybersecurity controls are mandated, the baseline will remain too low.
Cutting across all five pressures is a challenge unique to healthcare: the connected medical device ecosystem. These environments include infusion pumps, imaging systems, surgical robots and patient monitoring equipment, many running legacy operating systems that cannot easily be patched.
The March 2026 attack on Stryker Corporation demonstrated this clearly. The Iran-linked group Handala wiped nearly 80,000 devices across Stryker’s infrastructure, disrupting operations in 79 countries. No connected medical device was compromised. Instead, the attack disrupted manufacturing and distribution systems, delaying delivery of patient-specific surgical implants and forcing hospitals, including CommonSpirit Health, to reschedule surgeries.
HHS proposed significant updates to the HIPAA Security Rule in late 2024 that would mandate controls such as multifactor authentication, network segmentation, encryption and vulnerability scanning. The intent is right. However, prescriptive requirements mean little without enforcement and funding support for smaller health systems.
Building Teams around Mission, Not Metrics
Security teams operate under constant pressure, and leadership must respond with clarity, accountability and purpose. Cybersecurity professionals perform best when they understand the mission they support. In healthcare, when analysts understand their work is connected to patient safety, it changes everything.
“When an analyst genuinely understands that their work is connected to whether a patient receives safe care, it changes everything. That passion is a genuine competitive advantage.”
High-performing teams require clear expectations, continuous learning and strong collaboration across IT, clinical and executive leadership. Security cannot operate in isolation.
AI as Enabler and Risk
In healthcare cybersecurity, AI is both a capability and a threat vector.
Threat actors are using AI to automate attacks, accelerate vulnerability discovery and create more convincing phishing campaigns. AI-powered tools lower the technical barrier for adversaries while increasing the scale and precision of attacks.
At Fortified, we use AI to reduce mean time to detect and investigate, applying large language models and private models to surface and correlate data faster for analysts.
“When an Analyst Genuinely Understands that their Work is Connected to Whether a Patient Receives Safe Care, It Changes Everything. That Passion is a Genuine Competitive Advantage.”
We do not allow AI to make autonomous decisions. AI will remain a powerful enabler as long as humans stay in the loop. Organizations that approach AI governance with the same rigor they apply to identity governance will be better positioned than those that do not.
For healthcare organizations considering AI adoption, my guidance is direct. Understand your existing operational gaps first. If cybersecurity vulnerabilities already exist, layering AI on top only amplifies those risks.
Advice For Aspiring CISOS
After three decades in this field, the guidance I offer aspiring healthcare CISOs centers on three principles.
Communicate in business language, not technical language.
Cybersecurity leadership is ultimately about communication and trust. When leaders explain how security investments protect revenue, ensure care delivery and reduce organizational risk in terms executives understand, cybersecurity becomes a strategic conversation rather than a technical one.
Build around a proven framework and think holistically.
I rely heavily on NIST CSF 2.0 and its six pillars: govern, identify, protect, detect, respond and recover.
Cultivate relationships with clinical leadership.
This is the differentiator unique to healthcare. CISOs who thrive are those who earn the trust of CMOs, CNOs and department chairs while understanding clinical workflows and the realities of care delivery.
The Mission Ahead
Healthcare cybersecurity is entering an era where resilience matters more than perfection. Breaches will continue to occur. Organizations that succeed will detect threats quickly, respond effectively and maintain care delivery even when systems are disrupted.
Operational resilience is not a product organizations purchase. It is a discipline they build through clinical downtime procedures, incident response plans that include clinical leadership and tabletop exercises that simulate real attack scenarios.
The Change Healthcare breach should serve as a sectorwide inflection point. The vulnerability was not sophisticated. The impact was historic. The lesson is clear: compliancefocused and tool-centric programs are insufficient against today’s threat environment.
That is the mission I have committed my career to getting right. In an industry where the ultimate measure of security is whether a patient receives safe care, there is no more meaningful work.
Sources & Citations
1 IBM Security. Cost of a Data Breach Report 2024. July 30, 2024. Healthcare led all industries for the 14th consecutive year at $9.77M average breach cost. ibm.com/security/data-breach
2 U.S. Department of Health & Human Services, Office for Civil Rights. Change Healthcare Cybersecurity Incident FAQ. Updated 2025. Approximately 190–192.7 million individuals affected. hhs. gov/hipaa/change-healthcare
3 American Hospital Association. AHA Survey: Change Healthcare Cyberattack Impact on Patient Care and Hospital Finances. March 15, 2024. aha.org/change-healthcare-survey
4 U.S. Department of Health & Human Services. HIPAA Security Rule Proposed Updates. December 2024. First proposed mandate of specific technical controls including MFA, encryption and network segmentation. federalregister.gov/hipaa-securityrule-2024
5 AHA News. Medical Technology Company Stryker Disrupted Globally by Cyberattack. March 12, 2026. Iran-linked group Handala wiped ~80,000 devices across 79 countries; surgical procedures rescheduled at multiple health systems. aha.org/ stryker-cyberattack-2026
6 HIPAA Journal. Healthcare Was the Most Breached Industry in 2024. 2025. Healthcare accounted for 23% of all global data breaches, surpassing finance. hipaajournal.com/2024-breachreport.