• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

How eClinicalWorks Agentic AI Is Helping Revenue Cycle Leaders Improve Financial Performance
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

Healthcare’s Cyber Playbook Was Built for Another Era. Here’s How Leaders Can Adapt

by Anurag Rai, Principal, Advisory, Cyber Security Services at KPMG US 09/16/2026 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
Anurag Rai, Principal, Advisory, Cyber Security Services at KPMG US

Healthcare organizations have invested heavily in cybersecurity over the past decade. Yet many of the assumptions those programs were built upon—how quickly threats emerge, where risks originate, and how disruption unfolds—are increasingly being challenged by artificial intelligence (AI), digital care delivery, and growing ecosystem interdependence.

The challenge is no longer simply protecting data or preventing breaches. It is ensuring organizations can continue delivering care when disruption becomes inevitable.

AI is accelerating the speed at which vulnerabilities are discovered and exploited. Healthcare delivery continues to expand beyond traditional clinical settings through remote monitoring, connected medical devices, and digital care models. At the same time, organizations are becoming increasingly dependent on vast ecosystems of technology vendors, data partners, and service providers. Collectively, these shifts are changing both the scale of cyber risk and the consequences of cyber failure.

In healthcare, where operational continuity is directly tied to patient care, the implications are especially significant. As leaders rethink their cyber strategies for an increasingly AI-driven and interconnected environment, three priorities are emerging: modernizing cyber operations to keep pace with machine-speed threats, strengthening governance for AI and digital care technologies, and building resilience across the broader healthcare ecosystem. These areas will likely play a defining role in how healthcare organizations manage disruption in the years ahead. 

1. Modernize cyber operations for AI-speed threats

For years, security teams have operated on the assumption that organizations would have sufficient time to evaluate vulnerabilities, prioritize remediation efforts, and deploy controls before attackers could capitalize on newly disclosed weaknesses.

For many healthcare organizations, that assumption has already started to break down.

Advanced AI models are enabling threat actors to accelerate activities that once required considerable time and expertise. Attackers using AI can reduce the time between vulnerability disclosure and exploitation to less than 24 hours, while typical enterprise patching cycles often extend well beyond that timeframe. The result is a widening gap between the speed of attack and the speed of defense—one that can directly affect scheduling systems, revenue cycle operations, and clinical workflows. 

This dynamic has important implications for healthcare leaders. Security programs designed around periodic patching cycles and manual response processes increasingly struggle to keep pace with machine-speed threats. Organizations should consider shifting from a patch-centric approach to one centered on exposure management, automated detection and containment, and resilience metrics that measure how quickly threats can be identified and isolated. As cyber threats continue to accelerate, cyber operations must evolve to keep pace. 

2. Strengthen governance for AI and digital care technologies

A second priority is establishing governance models that address both the rise of AI and the expansion of care delivery beyond traditional clinical environments.

Healthcare organizations are beginning to deploy AI in ways that extend beyond data analysis and workflow automation. Agentic AI systems are designed to execute tasks, interact with multiple systems, and make decisions within predefined parameters.

For healthcare organizations, that trend raises questions that cybersecurity programs have not traditionally needed to answer. How should non-human identities be governed? What level of oversight is required when AI systems participate in administrative or clinical workflows? How can organizations detect when an AI agent begins operating outside intended parameters?

These questions are not solely technical. They sit at the intersection of governance, risk management, patient safety, and organizational accountability. As AI adoption expands, organizations should begin establishing identity-first security models, applying governance controls to machine identities, and maintaining appropriate human oversight for decisions that affect patients, operations, or financial outcomes. Healthcare leaders will increasingly need to govern non-human identities with the same rigor applied to human users. 

The need for stronger governance extends beyond AI. Healthcare delivery continues to expand through connected medical devices, remote monitoring technologies, and digital care platforms. While these innovations offer significant benefits, they also increase the attack surface and create new pathways for disruption.

Organizations should focus on improving visibility across connected environments, strengthening controls around how external data enters clinical systems, and applying security principles consistently across digital care ecosystems. The objective is not to slow innovation, but to ensure innovation is deployed responsibly and securely. 

3. Build resilience across the healthcare ecosystem

The third priority is resilience across the healthcare ecosystem.

Many healthcare organizations now rely on complex networks of vendors to support everything from revenue cycle operations to clinical technologies and device management. Recent disruptions across the healthcare sector have demonstrated how vulnerabilities at a single organization can cascade across an entire ecosystem.

This highlights an uncomfortable reality: an organization’s resilience is increasingly linked to dependencies outside its direct control. Vendor management programs that focus primarily on periodic compliance reviews may provide only a partial view of risk in environments where threats evolve continuously. 

As a result, healthcare organizations should move beyond traditional vendor risk management approaches and toward continuous monitoring of critical third-party relationships. Leaders should identify key operational dependencies, evaluate potential single points of failure, and establish clearer accountability for cyber resilience across their partner ecosystems. Understanding risk annually is no longer sufficient. Organizations must be able to understand and respond to risk continuously. 

Resilience must be treated as an enterprise capability rather than a security function. That means understanding where technology failures could interrupt clinical operations. It means identifying critical dependencies across vendors and care delivery networks. It means establishing governance frameworks for AI systems before those systems become embedded in core business processes. And it means preparing for emerging risks, including post-quantum cryptography, that could affect how organizations protect sensitive information over time. 

The Bottom Line 

The healthcare organizations that adapt most effectively will not be defined by their ability to prevent every incident. In a sector as interconnected as healthcare, that objective is increasingly unrealistic. They will be defined by how quickly they can detect disruption, contain its effects, maintain trust, and continue delivering care.

As AI reshapes both healthcare operations and the cyber threat environment, resilience is becoming a defining characteristic of organizational performance. The debate is no longer whether healthcare operates in an AI-shaped threat environment. It already does. The more important question is whether leadership teams are adapting quickly enough.

Organizations that modernize cyber operations, establish effective governance for AI and digital care technologies, and strengthen resilience across their ecosystems will be better positioned to navigate disruption while maintaining trust, continuity, and patient care.


About Anurag Rai

Anurag Rai is an Advisory Principal, Cyber Security Services with KPMG in the U.S. Anurag has over 18 years of experience in the information security, risk management, compliance, privacy and identity and access management domains and serves as a leader for many important clients. In addition, Anurag also leads the CISO Advisory service offerings like cyber strategy, assessment, metrics and board reporting.


  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

Aligning IT & Clinical Teams: How to Reduce Friction and Improve Communication

Most-Read

M&A: Francisco Partners to Acquire Weave in $650M Take-Private Deal

Epic Launches One-Click Care Everywhere Diagnostic Image Exchange

Epic Launches One-Click Care Everywhere Diagnostic Image Exchange

Redesign Health Study: 71% of Health Systems Adopt an "Epic-First" AI Purchasing Strategy

Redesign Health Study: 71% of Health Systems Adopt an “Epic-First” AI Purchasing Strategy

iRhythm to Acquire VitalConnect for $287.5M to Build Broad Cardiac Intelligence Platform

M&A: iRhythm to Acquire VitalConnect for $287.5M to Build Broad Cardiac Intelligence Platform

CB Insights Q2 2026 State of Digital Health Report: Fewest Deals in Over a Decade as Median Sizes Rise

CB Insights Q2 2026 State of Digital Health Report: Fewest Deals in Over a Decade as Median Sizes Rise

mount-sinai-launches-epic-chart-with-art-nursing-ambient-ai

Mount Sinai Medical Center Extends Epic’s Ambient AI to Inpatient Nursing

M&A: Tempus AI to Acquire Personalis for $1.5B to Expand Precision Oncology and MRD Monitoring

M&A: Tempus AI to Acquire Personalis for $1.5B to Expand Precision Oncology and MRD Monitoring

Why Brain Health Is Entering Its Infrastructure Era

Brain Health’s Infrastructure Era: Proving Clinical Outcomes with Integrated Neuromotor Tracking

Why Catholic Health Inked a $500M Care Alliance with GE HealthCare to Automate Outpatient Triage

Catholic Health Inks $500M Care Alliance with GE HealthCare to Automate Outpatient Triage

KLAS Global HIT Trends 2026 Report: Artificial Intelligence Becomes the Top Investment Priority

KLAS Global HIT Trends 2026 Report: Artificial Intelligence Becomes the Top Investment Priority

Secondary Sidebar

Footer

Company

  • About Us
  • 2026 Editorial Calendar
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |