Safeguarding Healthcare Operations with Cybersecurity and AI
Healthcare Tech Outlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.

Mary Rutan Health

Safeguarding Healthcare Operations with Cybersecurity and AI

David Kelly

David Kelly is a seasoned healthcare leader with over 18 years of experience specializing in revenue cycle management, operational efficiency, and physician relations. As vice president of revenue cycle and ambulatory operations at Mary Rutan Health, he drives financial performance, cost optimization, and strategic growth.

David leverages his expertise in managed care, reimbursement strategies, patient access, HIM and EMR systems like EPIC and Meditech to implement innovative solutions. He is known for his leadership and team-building skills, which help foster collaboration and achieve organizational goals. David is passionate about sustaining community healthcare and is committed to ensuring the continued success and excellence of Mary Rutan Health.

Roles and Responsibility

As the vice president, David Kelly oversees both the revenue cycle of Mary Rutan Health and the operational management of its medical group.

His daily responsibilities include participating in meetings and work groups where they collaborate with colleagues to address challenges and implement effective solutions. A significant portion of this work focuses on identifying and removing operational barriers to streamline processes and improve overall efficiency.

He also ensuring the long-term independence and sustainability of the organization. This involves strategic planning and working closely with leaders across departments to establish systems that will support growth and resilience well into the future.

Ongoing Challenge of Maintaining System Continuity in Healthcare

Cybersecurity has become a critical focus in healthcare, especially within revenue cycle management (RevCycle), due to the rising incidence of cyber breaches.

A key strategy is to assess and implement redundancies across essential systems. While an electronic medical record (EMR) system is typically a single platform, other critical tools—like claims clearinghouses and insurance eligibility systems—can benefit from having backup options. These redundancies help ensure that healthcare organizations can maintain operational continuity even in the event of a cyberattack or system failure.

Implementing such redundancies though, can add to operational costs and be challenging given the generally tight profit margins in healthcare. Despite this, establishing these safeguards is similar to purchasing insurance—it’s an investment in protecting against potential disruption.

Cybersecurity Trends Shaping the Future of Healthcare Operations

David identifies that traditionally, healthcare organizations have relied on a single primary software vendor without backup options. However, recent cyber threat incidents have given rise to the trends of contingency planning to protect operations and data integrity.

Another trend is the return of cybersecurity talent to the healthcare sector. Recently high-profile breaches like the Change Healthcare incident, have acted as a wake-up call, prompting renewed investment in cybersecurity expertise.

AI is also becoming a prominent factor in cybersecurity, presenting both opportunities and challenges. While AI can be leveraged by attackers to enhance social engineering tactics, it also provides defenders with powerful tools for advanced threat detection and proactive security measures. AI is a doubleedged sword, but it is expected to play a crucial role in helping healthcare organizations counter cyber threats in a more dynamic way.

Employee Training Project to Elevate Cybersecurity Awareness

There are several cybersecurity initiatives recently implemented to strengthen its security posture. One of the key actions has been mandating two-factor authentication for all users. The organization has also ramped up its cybersecurity education efforts, moving beyond the once-a-year webinar to more frequent, ongoing training sessions to ensure that employees remain up-to-date on best practices.

The institution has hired external companies to conduct ethical hacking attempts to test the system for vulnerabilities. It is relatively new for healthcare, especially for smaller hospitals with limited resources.

The focus is also on maintaining redundancy for missioncritical systems. By implementing these precautions, Kelly aims to mitigate the risks, ensuring that operations continue smoothly even in the event of a security breach.

AI’s Impact on Healthcare in the Next 18 to 24 Months

Given the ongoing risk, healthcare organizations are likely to increase their investments in cybersecurity. These investments will be crucial in addressing the growing threats and ensuring that institutions are better prepared to defend against attacks.

“Healthcare organizations must recognize that cyberattacks are not a matter of if, but a matter of when. Given the increasing sophistication of cyber threats, it is crucial for organizations to acknowledge the inevitability of an attack and to proactively build strategies to mitigate the associated risks.”

The healthcare providers will face increased scrutiny from regulators, who will likely demand more stringent cybersecurity practices. Hospitals and healthcare organizations may find themselves under pressure to demonstrate their efforts in protecting sensitive data and preventing breaches.

Furthermore, since patients tend to trust their local healthcare providers more than other entities, they may turn to their doctor’s office or hospital when they receive notification of a breach from a third party. As a result, healthcare providers may find themselves in the spotlight for breaches that are beyond their control.

Advice to peers

David stresses that healthcare organizations must recognize, that cyberattacks are not a matter of if, but a matter of when. Given the increasing sophistication of cyber threats, it is crucial for organizations to acknowledge the inevitability of an attack and to proactively build strategies to mitigate the associated risks. Healthcare leaders can better manage the consequences when they inevitably occur, by preparing for such incidents.

David also highlights the importance of revenue cycle management in addressing the impact of cyberattacks. He advises that revenue cycle and managed care leaders negotiate with insurance plans and vendors to secure flexibility in contracts, particularly regarding issues like prior authorization and timely filing deadlines. For example, if a healthcare organization experiences a prolonged system downtime due to a cyberattack, these negotiated provisions can help mitigate financial and operational damage, providing more time to recover without facing penalties.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief