Reasons Cybersecurity Projects Fail in Healthcare

Explore top LinkedIn content from expert professionals.

Summary

Cybersecurity projects in healthcare often fail because they don't address the unique risks and operational realities of the industry, where patient safety, data protection, and vendor connections are critical. These failures can result in costly breaches, disrupted care, and compliance issues that put both organizations and patients at risk.

  • Prioritize patient safety: Design security measures for medical devices and data systems that focus on maintaining safe and reliable patient care rather than just protecting information.
  • Improve vendor oversight: Regularly monitor third-party access and maintain clear plans for isolating systems if a vendor is compromised, since many hacks start with external partners.
  • Streamline usable tools: Provide healthcare staff with secure, validated technology that is easy to use, discouraging risky workarounds and unapproved tech like shadow AI.
Summarized by AI based on LinkedIn member posts
  • View profile for Dev Mitra

    Forbes Business Council I Helping HNI Entrepreneurs Build & Scale Startups in Canada | IP & Technology Lawyer | Managing Partner @ Matrix Venture Studio™

    20,344 followers

    A single unprotected server at Change Healthcare cost hospitals $1 billion every day for an entire month. The 2024 CDK Global attack left 15,000 car dealerships unable to process sales, forcing them back to pen and paper. In a similar incident, 800 hospital operations in London were canceled after hackers breached Synnovis, their lab testing provider. Companies invest in security but forget they're connected to dozens of outside systems. The reality is that 90% of business technology comes from just 150 companies. Hackers know this. They've changed tactics to target your vendors - an easier path to your data. In February 2024, Change Healthcare's breach cost healthcare providers $1 billion per day for over a month. The cause? A single server without multi-factor authentication. The problem isn't just technology: - Most businesses don't know all their vendors - Security questionnaires only show a snapshot in time - Vendors rarely report security issues promptly After auditing over 200 enterprise security programs, I've found the most resilient organizations:   📍 Limit vendor access to critical systems  📍 Implement continuous monitoring beyond questionnaires  📍 Maintain isolation playbooks ready to deploy within minutes  📍 Test vendor breach scenarios quarterly Supply chain security isn't just an IT checkbox, it's the difference between a minor disruption and business extinction. Do you have a plan if one of your vendors gets hacked? #security #business

  • View profile for Jan Beger

    Our conversations must move beyond algorithms.

    91,098 followers

    This paper systematically analyzes the existing literature on personal health data breaches, focusing on the facilitators and impacts of these breaches. It reviews 120 articles, summarizing the findings into an integrative model that offers a multifaceted view of health data breaches. The study also identifies gaps in the current literature and suggests avenues for future research, providing a comprehensive understanding that is valuable for both practitioners and researchers in managing data breach risks effectively. 1️⃣ The paper reveals that personal health data breaches pose significant challenges, as the worth of an individual’s medical record far exceeds that of credit card details in the darknet market. This makes the healthcare sector particularly vulnerable to cyber threats. 2️⃣ The study emphasizes that healthcare organizations exhibit higher vulnerability to data breaches compared to other sectors due to multiple actors having access to personal health data, inadequate staffing, and investments in IT security. 3️⃣ The paper develops an integrative model based on the analysis, which can be a valuable tool for evidence-based data breach risk management, offering guidance for future investigations and enhancing the collective understanding of personal health data breaches within healthcare. This paper is worth reading as it provides a comprehensive and systematic analysis of personal health data breaches, offering valuable insights and a practical model for managing risks associated with data breaches in the healthcare sector. It also identifies gaps and suggests future research directions, making it a valuable resource for researchers and practitioners aiming to enhance data security in healthcare. 🌐⇢ https://lnkd.in/eTx5brVR ✍🏻 Javad Pool, Saeed Akhlaghpour, Farhad Fatehi, Andrew Burton-Jones. "A systematic analysis of failures in protecting personal health data: A scoping review." International Journal of Information Management 74 (2024). DOI: 10.1016/j.ijinfomgt.2023.102719 ✅ Sign up for my newsletter to stay updated on the most fascinating studies related to digital health and innovation: https://lnkd.in/eR7qichj

  • View profile for Christian Espinosa

    I keep medical devices from being the reason someone doesn’t go home. Founding CEO, Blue Goat Cyber, 250+ FDA submissions, zero rejections. 24x Ironman.

    14,855 followers

    A manufacturer walked away from $8 million. Their FDA submission failed because they framed cybersecurity around data protection instead of patient safety. This is the most common mistake I see in medical device submissions. With medical devices, confidentiality is actually third on the priority list. Integrity and availability are what matter most. If you can alter data on a device, a clinician won't trust it anymore. That's disruption of clinical workflow. If drug infusion pumps go down at scale, patients don't get care. That's the real threat. Traditional IT security is all about protecting data. Medical device security is about protecting patients. The FDA expects you to look at your device through the lens of patient safety first. What could happen if this device is compromised? How could it disrupt care? Get this wrong and you're not just rewriting documentation. You're redoing your entire risk methodology. I've seen it cost manufacturers 180 days, millions in rework, and in this case - abandoning the whole product.

  • View profile for Trey R.

    SVP Partnerships at Datavant

    24,460 followers

    I've uncovered why so many promising health tech solutions never make it past the pilot stage. The problem isn't value demonstration—it's a fundamental misunderstanding of how healthcare budgets actually work. Here's what most founders get wrong: They calculate TAM by multiplying market size by assumed spend per customer, imagining there's some magical "innovation fund" waiting to be tapped. In reality, healthcare budgets are rigid structures where every dollar is already allocated, constrained by regulations, labor contracts, and mandatory expenses. Take a typical 500-bed hospital with $1.2B in revenue. While that sounds like massive potential, labor consumes $720M, supplies another $300M, and facilities $60M. The IT budget of $72M? Most goes to EHR licensing, cybersecurity, and maintaining legacy systems. The actual discretionary innovation budget might be just $10-15M—and it's fiercely contested by dozens of internal projects. The math gets even tighter for other players. A physician group generating $60M might have only $100K truly discretionary. A TPA with $12M revenue could have less than $500K available for innovation. Even large national insurers, despite billions in premium revenue, face medical loss ratio requirements that severely limit their administrative spending flexibility. Looking ahead to 2030, the situation will likely worsen. Labor costs are projected to hit 65-70% of hospital budgets, specialty drug spending will consume 70% of pharmacy budgets, and regulatory compliance costs continue rising. In my worst-case scenario modeling, discretionary budgets could shrink to less than 0.5% of revenue. The entrepreneurs who succeed will be those who map their solutions to non-discretionary budget lines—cybersecurity, compliance, labor cost reduction, or direct replacements for existing spend. They'll price within existing constraints rather than requiring new budget allocation, and they'll time their sales cycles to customer budget calendars. This isn't about building worse products or lowering prices arbitrarily. It's about budget fluency—understanding that in healthcare, the money flows through very specific channels, and your innovation needs to align with those channels to reach scale. ____________ Disclaimer: These thoughts and opinions are my own and do not reflect those of my employer or any other entities. ____________ The full analysis, including detailed mock budgets and scenario modeling through 2030, is linked in the comments below.

  • View profile for Sigrid Berge van Rooijen

    Helping healthcare use the power of AI⚕️

    29,981 followers

    86% of healthcare IT leaders report shadow AI in their organizations. An increase from last year. I am not surprised.  Clinicians are overworked, the tools they are given are often slow or outdated, and approved alternatives either do not exist or are worse than what they can find themselves. And getting tools approved in itself takes months. Of course they find workarounds. I have written about this before. But somewhere we need to draw a line. Using ChatGPT to draft an email or summarize meeting notes? Understandable.  Using it to look up a differential diagnosis on a personal account with patient details pasted in? That is a different conversation. The tool does not know it is handling protected health data. It is not covered by your security controls. It is not validated for clinical use. And if it gives a confident but wrong answer, that error can permanently end up in a patient record. 71% of GenAI logins happen through personal accounts. I promise you many of these logins are used for professional activities. No SSO, audit trail, or visibility for IT. In healthcare, that impacts both security and compliance. It’s not a privacy risk, it already is a security breach. Blocking tools does not fix this issue. It’s nothing new that IT tools are being used without the organizations’ knowledge. If you want to avoid Shadow AI and unapproved IT tools, clinicians should have usable tools. If the approved option is worse than ChatGPT, people will use ChatGPT. It is a product problem, not a discipline problem. Have a clear line between acceptable and dangerous use.  Admin tasks, drafting, scheduling etc: Go ahead with approved tools.  Clinical decisions, patient data, diagnostic support: Only through validated, governed systems. Without exceptions. And please don’t forget AI literacy. It won’t work without. Not as a policy PDF nobody reads. Real training. What these tools can and cannot do, where they fail, and why clinical validation matters. 63% of organizations that experienced security breaches either had no finalized AI governance policy. AI adoption is faster than organizations govern it, and that is where the risk is. Shadow AI is not going away. Your organization either governs it or finds out about it after the breach. What is your organization to avoid unapproved uses of AI tools? Read more here: https://lnkd.in/eqjj9rbA https://lnkd.in/eAKjApU7

  • View profile for Manuel Barragan

    I help organizations in finding solutions to current Culture, Processes, and Technology issues through Digital Transformation by transforming the business to become more Agile and centered on the Customer (data-informed)

    25,414 followers

    Cybersecurity in Healthcare: Your Weakest Link The Change Healthcare attack was a painful lesson. It wasn't just an IT system failure. It stopped pharmacies from filling prescriptions. It prevented providers from getting paid. The event showed everyone how a single security gap can disrupt the nation's healthcare system. It was a clear warning for every healthcare leader. Many executives think a firewall and updated software make them secure. That is a dangerous assumption. This "checklist security" approach creates a false sense of safety. The biggest threats often don't break down the door. They are invited in when an employee clicks on a phishing email or a remote worker logs in from an unsecured home network. The cost is more than money. It is measured in canceled appointments, delayed care, and a permanent loss of patient trust. A strong defense is a strategy, not a shopping list of tools. It requires focus on three areas. First, your people. They are your first and last line of defense. Regular, practical training on how to spot threats is more valuable than any software. Second, your processes. You need strict access controls and multi-factor authentication on every system. You must test your vulnerabilities and have a practiced incident response plan. Third, your technology. Encrypt all patient health information. Keep offline, encrypted backups that ransomware cannot reach. Your security is only as strong as its weakest point. Is that an old server, or is it a culture that treats cybersecurity as someone else’s job? Let’s talk with Digital Transformation Strategist on how to do it.

  • View profile for Christina Maher, PhD

    Neuroscientist + biomedical engineer | Transforming human connection with neurotech | Ex @Macquarie Bank | PhD in neural engineering

    2,662 followers

    Last month’s leaked NSW hospital audit didn’t surprise me, it just confirmed what I see every day in public healthcare which is high spend, low resilience. $39 million was spent last year on cybersecurity across the health system, rising to $64 million by 2030. Yet not one of the audited local health districts met minimum requirements. No clear roles. No working disaster recovery plans. No confidence that patient data or core systems could be recovered under pressure. I lead eHealth security engagements where we see hospitals running on 10+ year old infrastructure, flat networks, admin interfaces exposed to the internet, and no centralised view of risk. And we’re told “we have a SOC.” Security is not something you outsource and forget. It’s part of the service you deliver - just like clean water, sterile instruments, and working power. Healthcare deserves better than a spend-and-hope model. It needs security that is operational, aligned to clinical realities, and governed with teeth.

  • View profile for Jason Elrod

    Healthcare CISO | Guiding Boards Through Enterprise Risk, AI & Cybersecurity | 2025 ORBIE CISO of the Year

    7,954 followers

    Healthcare security teams are treating shadow AI as a security problem. That framing produces prohibition. Prohibition does not work. The 1920's already proved that. 57% of healthcare professionals have encountered or used unauthorized AI tools. Clinicians are using ChatGPT, Claude, and Gemini to draft clinical notes, generate diagnostic hypotheses, and synthesize treatment options and often processing protected health information without Business Associate Agreements. HIPAA fine exposure runs up to $1.5 million per violation category. The average healthcare breach costs $10.93 million. The root cause is not recklessness. It is desperation. Clinicians face unsustainable documentation burdens. Approved AI solutions move slowly through procurement and compliance. The unauthorized tool is available now and saves 30 minutes a day. I know at least one healthcare system that reframed the problem. Instead of prohibiting unauthorized use, they provided approved alternatives. 89% reduction in unauthorized use. 32 minutes of daily time savings per employee. The governance model that works in clinical environments is not prohibition. It is approved replacement. Security leaders who arrive with a policy and a warning will get the same result prohibition always gets. Security leaders who arrive with approved alternatives and a governance model get compliance and clinical adoption. The framing determines the outcome. @LimitlessCyber

  • View profile for Marcus W.

    Author | Identity Security Leader | Reducing Fraud, Waste, and Abuse | Business Risk Strategist |

    7,874 followers

    Tales from the CyberSecurity Interview Files: Misaligned IAM Roles in Healthcare Here’s a scenario that still has me shaking my head. Not too terribly long ago, I spoke with a recruiter about an IAM consultant position supporting a large healthcare client. As I always do, I asked the hard questions: What operational phase does the client need this consultant to work in? How will responsibilities be divided to avoid conflicts of interest? The recruiter’s response? Crickets. Not only could they not answer, but they also made a point to tell me I was the only candidate who had even asked. Here’s the kicker - the role combined conflicting responsibilities across architecture, engineering, and analyst functions. And when we’re talking about IAM in healthcare—an environment where every second matters—that’s not just a poorly scoped job; it’s a recipe for disaster. There are REAL Risks when IAM Roles in Healthcare are Misaligned. This isn’t just about the consultant. This is about the patients and hospital staff who rely on these systems to do their jobs and save lives: 1️⃣ Patients’ Lives at Stake: If a clinician can’t access critical systems during an emergency, the delay can mean the difference between life and death. Poorly designed IAM solutions leave systems vulnerable to breaches, jeopardizing sensitive patient data. 2️⃣ Healthcare Staff Under Pressure: Frustrating workflows and access delays take time away from patient care and add unnecessary stress to already overburdened teams. Poor privilege management puts staff credentials at risk, making them easy targets for phishing or ransomware attacks. 3️⃣ Ransomware Chaos: Misaligned systems create vulnerabilities that attackers exploit. When ransomware takes down systems, everything—from surgery schedules to life-saving devices—grinds to a halt. 4️⃣ Erosion of Trust: Patients expect their records to be secure and accessible. A breach not only harms the individual but also undermines public trust in the entire healthcare system. What's the moral of the story? IAM in healthcare is not just another technical project. It’s a lifeline. The stakes couldn’t be higher, which is why it's VITAL to prioritize these key focus points... Clarity of Roles: Define responsibilities to avoid conflicts of interest and ensure effective execution. Patient-Centered Solutions: Design SOLUTIONS that empower healthcare teams to act fast, securely, and with confidence. Trust at the Core: Protect patient data to maintain the integrity of the patient-provider relationship. The recruiter may not have appreciated my questions, but they revealed something critical... a lack of preparedness can rip through an entire organization, putting patients, staff, and even public health at risk. What’s your take? Have you seen IAM challenges like this in healthcare or other critical industries? Let’s discuss. #CyberSecurity #IdentityMob #BusinessRisk #SellingSolutions #PatientSafety #ZeroTrust #CleverGirl

  • View profile for Don Baham

    Technology & Security Executive | Building AI-Enabled Technology Organizations | Cultivating High-Performing Teams and a Strong Company Culture | Board Candidate

    13,565 followers

    Legacy medical devices are quietly becoming one of the most significant cybersecurity and patient safety challenges in healthcare. The recent Health-ISAC Global Health Sector Threat Landscape Report (2026) shares that devices like infusion pumps and imaging systems often remain in service for decades. Their longevity makes sense. These are expensive, mission-critical systems that clinicians rely on every day. But it also creates a widening cybersecurity gap. As operating systems age out of support (Windows 10 reached end-of-life on Oct 14, 2025), many of these devices continue running software that will no longer receive security patches. The result is an expanding attack surface embedded directly in clinical care environments. This concern reached the policy level as well. During the April 1, 2025, House Energy & Commerce Oversight & Investigations Subcommittee hearing on “Aging Technology, Emerging Threats,” lawmakers highlighted how legacy medical devices are not held to the same cybersecurity requirements as newer technologies. Replacing devices is costly and often impractical given their role in critical care. But the risk can’t be ignored. Practical steps: • Identify devices still operating on end-of-life systems • Implement compensating controls like network segmentation and monitoring • Build long-term strategies for phased upgrades or replacements • Move toward modular medical devices that are less dependent on fixed operating systems Cybersecurity in healthcare is a patient safety issue and increasingly, a national security issue.

Explore categories