Why Cybersecurity Risk Management Must Be a Top Priority in Healthcare
Healthcare Tech Outlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.

Methodist Le Bonheur Healthcare

Why Cybersecurity Risk Management Must Be a Top Priority in Healthcare

Steve Crocker

Healthcare breaches are escalating quickly. These incidents go far beyond data loss or regulatory fines. They disrupt patient care, delay treatments, and put patient safety at risk. The financial fallout is significant too. According to industry reports, healthcare continues to suffer the highest breach costs of any sector, and by a wide margin.

Despite growing investment and attention, cybersecurity in healthcare still lags behind other industries. One of the biggest reasons? Many organizations still treat cybersecurity as a technical function buried in IT rather than a core risk management discipline that demands executive accountability and formal governance.

That mindset has to change.

Some healthcare leaders still argue that security is unaffordable or will interfere with care delivery. But the truth is, the status quo—not cybersecurity investment—is what’s harming patient care and draining resources.

When ransomware hits, hospitals are forced offline, records become inaccessible, and patients are diverted elsewhere. Several studies have linked ransomware incidents to increased mortality rates. These aren’t theoretical risks— they’re playing out in real hospitals, right now. Claiming that cybersecurity hurts patient care is a fallacy. Failing to invest in security is what puts patients at risk.

Yes, hospitals are under financial pressure. But many continue to invest in new technologies and platforms that improve care or efficiency. That’s smart, but if you can’t afford to secure it, you can’t afford to implement it. No one would manufacture a car and leave out the brakes because it was cheaper.

Cybersecurity must be recognized for what it is—a business risk, just like finance, legal or clinical safety. It belongs at the executive and board level, not buried under IT. The CISO’s job is to inform and advise. The responsibility for accepting or mitigating risk lies with leadership.

And to be fair, some organizations are already getting this right. In these cases, executives are engaged, risk decisions are tracked and owned, and cybersecurity is integrated into planning, not treated as an obstacle. These organizations are better protected and faster to respond when something does go wrong.

Key Elements of a Risk-Based Cybersecurity Program

1. Executive Buy-In

This is where it starts and often where it stalls. Without executive support, security decisions get pushed back to InfoSec, and blame follows when things go wrong. Leaders need to understand cyber risk in terms of operations, finances, and patient safety, not just technical jargon.

2. Define Risk Appetite

Document how much risk your organization is willing to tolerate, and have it approved by leadership. This sets the tone for how day-to-day cyber decisions should be made.

3. Use a Framework

Start with something proven, like the NIST Risk Management Framework. Customize it if needed, but don’t dilute the core principles. Good frameworks help create consistency, accountability and scalability.

4. Maintain a Real Risk

Register Not a list of vulnerabilities, a real risk register. Vulnerabilities may trigger risks, but the actual risk must be assessed in context. Define severity, ownership and impact in clear, business-friendly terms.

5. Assign Ownership

Every risk should have both an owner and a custodian. For example, a CFO may own the accounting system, but IT applies the patches. These roles must be clearly defined and enforced. Otherwise, risks linger.

6. Formalize Risk

Treatment Every risk should follow one of four paths—mitigate, avoid, transfer or accept.

• If mitigating, document the plan by outlining what’s being done, who’s doing it and by when.

“The time to act is now. Build a program that fits your mission, supports your clinical priorities, and treats cybersecurity as what it really is, a business issue that affects every patient you serve.”

• If accepting, require a formal, signed Risk Acceptance Request. It must be traceable and periodically reviewed.

This level of formality builds accountability, something too often missing in risk programs.

7. Tier Approvals Based on Risk Severity

Who approves the risk should depend on how serious it is. For example:

• Critical risks → CEO

• Very High risks → SVP

• High risks → VP

This ensures visibility at the right level of leadership.

8. InfoSec Oversees—Not Owns— Remediation

The InfoSec team should track risks and report on them, but they shouldn't be the ones managing every project. Risk owners and custodians must take responsibility for their actions. InfoSec’s role is governance, not operations.

Common Pitfalls to Avoid

• No Risk Ownership: If no one owns it, no one fixes it.

• Unclear Roles: Confusion leads to delays and finger-pointing.

• Overreach by Security: Security shouldn’t dictate. It should advise and enable.

• Lack of Documentation: Without clear processes, people don’t act.

• Infrequent Training: Leaders need regular reminders and support.

• Ignoring Risk Due to Difficulty: Saying something is “too hard to fix” isn’t a treatment plan. If you can’t mitigate it, accept it formally.

• Too Much Focus on Vendor Risk: Important, yes, but it’s only one part of the bigger picture. It also requires collaboration across Legal, Compliance, Supply Chain and InfoSec.

The Path Forward

This kind of program is a cultural shift, and yes, it’s hard. But other industries, like banking, have made it work. Healthcare can too.

The alternative? More breaches. More disruptions. More patient harm. And eventually, more government regulation. Waiting for that to happen means giving up the opportunity to shape your own strategy.

The time to act is now. Build a program that fits your mission, supports your clinical priorities, and treats cybersecurity as what it really is, a business issue that affects every patient you serve.

Executive buy-in. Risk ownership. Clear processes. Real accountability. That’s how we move the industry forward.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief

-->