Proactive Healthcare Cybersecurity for Today’s Threat Landscape
Healthcare cybersecurity is no longer just about compliance—it’s about protecting patient care, safeguarding operations, and maintaining trust in a high-stakes threat environment. With 92% of healthcare organizations experiencing cyberattacks in 2024 and the average breach cost reaching $4.7 million, leaders are under pressure to make every security decision count. In this expert-led webinar, leaders from Stellarus, NextGen, and Tevora share how healthcare organizations can strengthen cyber resilience, navigate shifting regulations, and prioritize the right strategies in an increasingly AI-driven and high-risk landscape. Drawing from real-world experience, our panel will offer actionable insights to help you secure what matters most.
Key Takeaways:
- Today’s most pressing cyber threats in healthcare—what’s new and what’s escalating
- The operational, financial, and patient care impacts of modern attacks
- What recent HIPAA changes mean for your security and compliance roadmap
- Emerging technologies shaping the future of healthcare cybersecurity
- What to prioritize on your 2025 healthcare security agenda
Whether you’re leading IT strategy, managing risk, or responsible for compliance, this session will help you focus your efforts and protect your organization against the threats ahead.
Proactive Healthcare Cybersecurity for Today’s Threat Landscape
Healthcare organizations are facing an unprecedented cybersecurity challenge. Cyberattacks are no longer just IT problems—they have become patient care, operational, and business continuity issues.
In this webinar, Spencer Romero (Enterprise Consulting Director, Tevora) sat down with healthcare and cybersecurity leaders Garo Doudian (CISO, NextGen Healthcare), Eddie Borrero (CIO, Stellaris), and Jeremiah Sahlberg (Principal, Tevora) to discuss today’s healthcare threat landscape, the rise of AI-driven risks, evolving HIPAA expectations, and the practical steps organizations should take to improve resilience.
Why Healthcare Remains a Prime Target
Spencer Romero: Cybersecurity in healthcare is no longer a back-office concern. The consequences of cyber incidents increasingly impact operations, patient care, and organizational viability.
Garo Doudian:
Healthcare has experienced major cybersecurity incidents for years—from Anthem to Change Healthcare—but the impact is growing.
What’s changing is not just the frequency of attacks, but their operational consequences. Organizations are dealing with outages that can disrupt:
- Electronic Health Records (EHRs)
- Imaging systems
- Clinical workflows
- Revenue cycle processes
- Patient services
The result can be much more than a data breach. It can become a full-scale business interruption event.
The Top Threats Keeping Healthcare Leaders Awake at Night
1. Ransomware
For Garo, ransomware remains one of the most significant threats facing healthcare organizations.
A typical attack often begins with:
- A phishing email
- A malicious attachment
- A compromised user account
From there, attackers can move laterally across the network and impact critical systems.
The concern isn’t only the theft of data. It’s the potential inability to provide care when key systems become unavailable.
2. Third-Party and Supply Chain Risk
Modern healthcare organizations rely heavily on vendors, cloud providers, software platforms, and integrated technologies.
Garo:
Many organizations have strong internal security controls, but they’re still dependent on partners they don’t directly control.
Incidents like:
- Software supply chain compromises
- Managed service provider breaches
- Third-party data incidents
highlight the importance of continuous vendor risk management.
3. Credential-Based Attacks
Credential theft remains highly effective.
Attackers routinely use:
- Credential stuffing
- Password spraying
- Stolen credentials from unrelated breaches
When employees reuse passwords across systems, a breach somewhere else can become an entry point into healthcare environments.
Strong identity controls and multifactor authentication remain critical defenses.
The Real Impact of a Healthcare Cyberattack
Eddie Borrero:
The impact goes beyond data loss.
Many healthcare organizations operate on tight financial margins. If claims processing systems become unavailable for extended periods, organizations can lose substantial revenue.
In severe cases:
- Clinics have closed
- Healthcare organizations have faced financial distress
- Communities have lost access to local care
Cybersecurity incidents increasingly have public health implications.
As Eddie noted:
“The health and well-being of communities can be affected by cyberattacks.”
How AI Is Changing the Threat Landscape
One of the most discussed topics during the session was artificial intelligence.
Lower Barriers for Attackers
Eddie:
AI has dramatically lowered the barrier to entry for cybercriminals.
Threat actors can use AI to:
- Generate phishing campaigns
- Research targets
- Create malware
- Build attack infrastructure
- Conduct social engineering
They no longer need advanced technical expertise to launch sophisticated attacks.
Better Phishing and Social Engineering
Garo:
Organizations are seeing higher success rates from AI-generated phishing emails.
AI can:
- Produce convincing language
- Eliminate grammatical mistakes
- Tailor attacks to specific targets
This increases the likelihood that users will trust malicious messages.
Faster Exploit Development
Panelists also discussed concerns that AI may shorten the timeline between:
- Vulnerability disclosure
- Patch release
- Exploit development
As AI-assisted coding continues to advance, attackers may be able to weaponize newly disclosed vulnerabilities faster than ever before.
AI-Powered Defenses: The Other Side of the Equation
The panel emphasized that AI isn’t only benefitting attackers.
Security teams are increasingly using AI to:
- Analyze large volumes of logs
- Detect anomalies
- Improve threat hunting
- Automate investigations
- Accelerate response actions
Rather than replacing security teams, AI is becoming a force multiplier.
Eddie described a future where security capabilities become increasingly self-healing and adaptive, automatically generating protections as threats emerge.
The Rise of Identity-Based Threats
A newer threat discussed by the panel involves attackers using AI-generated identities.
Jeremiah Sahlberg:
Organizations are increasingly encountering cases where applicants appear legitimate during virtual hiring processes but later turn out to be fraudulent identities.
Examples include:
- Deepfake-enabled interviews
- Synthetic identities
- Remote workers operating under false credentials
- State-sponsored actors seeking employment
As remote work expands, identity verification is becoming a critical security challenge.
Why Cybersecurity Leaders Must Become Better Communicators
When asked how CISOs can secure more investment and support, panelists agreed on one core principle:
Stop Leading with Technology
Eddie:
Security leaders should focus less on technical jargon and more on business impact.
Executives care about:
- Revenue
- Operations
- Customer trust
- Patient care
- Organizational resilience
Framing cybersecurity discussions around those outcomes leads to better decision-making.
Risk Should Be Discussed Like Any Other Business Risk
Garo:
Cybersecurity isn’t separate from enterprise risk.
Leaders should focus on:
- Quantifying risk
- Prioritizing risk reduction
- Demonstrating business impact
The goal isn’t eliminating risk entirely—it’s reducing it to acceptable levels.
HIPAA Security Rule Changes: What Organizations Should Prepare For
The panel also explored proposed updates to the HIPAA Security Rule.
Asset Inventory Requirements
Jeremiah:
One of the most important themes in the proposed updates is establishing and maintaining comprehensive asset inventories.
Organizations must understand:
- What systems they own
- Where data flows
- How systems connect
Without an accurate inventory, effective security becomes nearly impossible.
Stronger Incident Response Expectations
Organizations should expect increased emphasis on:
- Formal incident response plans
- Testing those plans
- Business continuity planning
- Recovery validation
The panel repeatedly stressed that plans must be exercised—not simply documented.
Mandatory Multifactor Authentication
MFA is increasingly becoming a foundational expectation.
For organizations not already deploying MFA broadly, the panel suggested they should treat it as an immediate priority.
Increased Third-Party Oversight
Vendor assessments can no longer be one-time exercises.
Healthcare organizations should implement:
- Ongoing vendor monitoring
- Continuous risk assessments
- Supply chain governance
Zero Trust and Other Promising Approaches
Zero Trust Architecture
Garo:
One of the most promising trends is the move toward Zero Trust.
Rather than assuming users or devices are trusted based on network location, Zero Trust treats every request as potentially untrusted.
Benefits include:
- Reduced attack surface
- Improved segmentation
- Better containment during incidents
Behavioral Identity Controls
Beyond passwords and MFA, organizations are increasingly adopting identity systems that evaluate:
- Device posture
- User behavior
- Access patterns
- Risk scoring
These additional signals help organizations determine whether activity is genuinely legitimate.
Why Compliance Alone Isn’t Enough
One theme appeared repeatedly throughout the discussion:
Compliance does not equal security.
Jeremiah described compliance as a minimum expectation rather than a complete security strategy.
Organizations that focus only on HIPAA requirements risk falling behind evolving threats.
The panel encouraged healthcare leaders to view compliance as a baseline while building broader security capabilities that exceed regulatory requirements.
Recommendations for Smaller Healthcare Organizations
For organizations with limited staff or resources, the panel offered practical starting points.
1. Begin With an Assessment
Eddie:
Before investing in technology, understand your risks.
An assessment helps organizations determine:
- Current maturity
- High-risk gaps
- Investment priorities
2. Know Your Assets
Jeremiah:
If you don’t know what systems you own, it’s difficult to protect them.
Asset management remains foundational.
3. Know Your Data
Understanding:
- Where data resides
- How it is used
- Who can access it
is equally important.
Top Priorities for Larger Healthcare Organizations
As organizations move through 2025 and beyond, panelists highlighted four areas of focus:
1. Cyber Resilience
Organizations must prepare for the possibility that key systems or vendors become unavailable.
The key question:
Can we continue delivering care when technology fails?
2. Identity Security
Identity remains one of the most critical control points.
Focus areas include:
- MFA
- Identity governance
- Account monitoring
- Identity verification
3. Data Security and Governance
Healthcare organizations must improve visibility into:
- Sensitive data
- Data flows
- Data exposure risks
4. AI Governance
Organizations need policies, controls, and oversight mechanisms to ensure AI is used safely and responsibly.
Final Takeaways
The healthcare cybersecurity landscape is evolving rapidly. Ransomware, supply chain attacks, identity-based threats, and AI-powered adversaries are forcing organizations to rethink their strategies.
The panel’s overarching message was clear:
- Know your assets.
- Know your data.
- Build resiliency.
- Strengthen identity controls.
- Treat AI as both an opportunity and a risk.
As Eddie Borrero summarized in his closing remarks:
“A lot of people are afraid of AI taking jobs. AI is going to create opportunities. If you’re not paying attention to it, learning it, and using it, you risk falling behind. Use it as a force for good.”
For healthcare organizations navigating an increasingly complex threat landscape, proactive preparation—not reactive response—will define cyber resilience in the years ahead.




