The recent cyberattack on Ascension Health highlighted the vulnerabilities of connected healthcare systems and the urgent need to prioritize cybersecurity in long-term strategies. A lack of proactive measures puts both organizational reputation and, even more concerning, patients at risk.
In May 2024, Ascension Health, one of the largest U.S. healthcare systems, experienced a ransomware attack that took its IT network offline, disrupting patient care in 15 states. Sensitive data was exposed, and critical technology like EHR and phone systems became unavailable.
This incident was part of a growing trend of cybersecurity breaches in healthcare, underscoring the need for proactive security measures. Ascension was praised for its response, including fast public disclosure, a dedicated update website and clear, frequent communication. Though leaders haven’t confirmed using a crisis response plan, it’s unlikely that such swift, high-level coordination was achieved without one in place. In fact, John Riggi, national cybersecurity advisor for the American Hospital Association, referred to Ascension’s response as a “role model” for other organizations.
As healthcare embraces new technologies like clinical AI, cybersecurity must evolve to address the unique challenges that come with it. Clinical AI depends on patient data, requiring health systems to share this information with AI developers for accurate performance.
This presents a classic risk-reward challenge: while data is the foundation for AI’s capabilities, it simultaneously introduces considerable cybersecurity vulnerabilities. Without robust AI governance, including threat modeling and secure model training, organizations expose themselves to AI-specific risks, such as adversarial model manipulation and unintended bias in AI decision-making.
Legacy security methods, such as firewalls and virus scans, are insufficient in addressing the dynamic and sophisticated nature of emerging threats. This necessitates a more adaptive, integrated security approach.
Managing multiple AI partners will complicate this, as each may offer different solutions that don’t always integrate seamlessly, resulting in fragmented security protocols. This lack of coordination can create dangerous gaps.
An enterprise-wide AI platform that consolidates AI solutions into a unified system can address these challenges by streamlining data integration and security monitoring. This centralized approach can help identify and mitigate threats more effectively.
However, the AI integration method is just one aspect of a proactive cybersecurity strategy. Strong governance frameworks, including regular risk assessments, data handling protocols and continuous vendor monitoring, are essential to ensure security and compliance across all AI partnerships.
With so much sensitive information being exchanged, having proactive cybersecurity conversations with AI partners is critical.
When to Start: It’s never too early to engage potential and current AI partners in cybersecurity discussions. Ideally, these conversations should start at the very beginning of any business relationship, during the planning and strategy phase. Security should be as important as any other quality indicator.
What to Ask: When evaluating a potential partner, ask for references related to cybersecurity. What protocols do they have in place? Have they experienced any data breaches? If so, how were they handled? Do they have an incident response plan? A strong partner will have transparent answers and a proven track record of security compliance.
Who to Include: Involve your IT, legal and compliance teams in these conversations. Bringing different departments to the table ensures that all areas of vulnerability are covered — from technical and patient care controls to legal safeguards.
To ensure your partners are up to par, ask them about these cybersecurity categories:
1. Regulatory Compliance
2. Security Measures
3. Experience in Healthcare
4. Third-Party Audits
5. Data Management
6. Risk Management
As AI technology continues to evolve, healthcare organizations must adopt a comprehensive, multi-layered cybersecurity approach. Enterprise-wide platforms, like the Aidoc aiOS™, coupled with a robust governance framework, can help protect sensitive data, maintain trust and ensure compliance. Proactive engagement with partners, careful vendor evaluation and continuous monitoring are crucial to minimizing risks.
Cybersecurity is not a one-time task but an ongoing practice that must evolve with emerging threats. By taking a proactive, enterprise-wide approach, healthcare organizations can stay ahead of potential risks and ensure they’re well-prepared for future challenges.
Aidoc experts, customers and industry leaders share the latest in AI benefits and adoption.
Explore how clinical AI can transform your health system with insights rooted in real-world experiences.
Learn how to go beyond the algorithm to develop a scalable AI strategy and implementation plan.
Explore how Aidoc can help increase hospital efficiency, improve outcomes and demonstrate ROI.