banner
Third Quarter 2026 | Archives
Author photo

Daniel Kent Cassavar, MD, MBA, FACC, Medical Director, The Doctors Company and TDC Group

Summary

We can preserve cybersecurity in healthcare through our daily habits as working clinicians, and we must integrate cyber vigilance into our culture of patient safety.

In 2021, Cardiology Magazine ran a feature titled, “You Will Be Hacked. Plan Now: Cybersecurity in Health Care.” That advice is even more true today. Many practices—even many large hospitals and healthcare systems—are not addressing conspicuous vulnerabilities as technology changes. These vulnerabilities create openings for both criminal and noncriminal cyber threats. When doors are left open for hackers, this can lead to disastrous consequences for patient safety, while data scrapers or other noncriminal technologies can threaten the security of healthcare data, compromising the financial security of a practice or organization.

The pace of change in technology is dizzying, which can tempt us to give up. Instead, we must reach toward whatever low-hanging cybersecurity fruit our practice has not yet harvested. There may be a lot of it, and we may be surprised to discover how many fairly accessible security measures are in reach. Whatever we pick first, cybersecurity is no longer something that can be handled by the IT team alone. Cybersecurity rests in all of our hands. We preserve it through our daily habits as working clinicians, and we must integrate it into our culture of patient safety.

Truth and Consequences

The attractiveness of healthcare data to hackers pairs badly with healthcare’s vulnerability. The potential consequences of a cybersecurity breach go beyond fines, lawsuits, and reputational damage, though those are bad enough: In just the first few months of 2026, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) levied more than a million dollars in penalties against U.S. healthcare organizations whose HIPAA violations had contributed to ransomware attacks. OCR also demanded corrective action plans.

But the real threat is that a ransomware attack can lock a healthcare team out of their EHR, because forcing even a temporary halt in the operations of a practice or hospital directly endangers patients.

Many types of gaps in defenses that hackers see are inconspicuous to us. Therefore, investment in cybersecurity by a practice or organization starts with investing the attention to notice which doors are standing open. Some of these gaps can be closed through repairs completed by an IT professional, and then kept shut through small, daily workflow habits adopted system-wide by clinicians and employees at every level.

The following steps can help healthcare institutions identify and close high-priority cybersecurity gaps:

  1. Recruit every team member to follow data-secure best practices, and document adherence. Human factors are key to achieving cybersecurity success, because busy healthcare professionals can easily, if inadvertently, leave digital doors open to hackers. In fact, healthcare environments are unusually high in cyber risk, not least because healthcare professionals are accustomed to communicating with individuals they do not personally know. This element of daily work gives advantage to cybercriminals, especially as phishing attempts get more convincing. This may be why “a patient safety–focused culture of cybersecurity” has been described as an organization’s “most important defense” by a senior advisor at the American Hospital Association. Team leaders need to promote buy-in and ensure that their care teams cooperate with the organization’s cybersecurity professionals when they are performing routine data-security audits and preparing documentation of compliance. Participation in cybersecurity efforts is not an interruption in care; it is part of providing care.
  2. Enable multifactor authentication. During an exercise by the HHS Office of the Inspector General, a mock phishing campaign captured hospital credentials that should have been secure, because the hospital had left large, simple holes in their cyber defenses, including the fact that no one had turned on key existing capabilities in their software systems, like multifactor authentication. Cybersecurity experts can help healthcare practices find their own digital doors that are propped open and then train staff members in how to keep them closed.
  3. Understand and update data-sharing settings in referral networks. Remember the old saying, “A chain is only as strong as its weakest link”? It’s still true. Improvements in interoperability link hospitals and ambulatory care centers, for instance, making it easier over time for systems to communicate and coordinate patient care. However, increasing interconnectivity also means that healthcare organizations may be vulnerable to cyberattack through their referral networks. Therefore, negotiating agreements related to patient transfers and referrals is not just an administrative chore. Rather, revisiting institutional arrangements is a chance to test digital passageways between organizations and look for vulnerabilities to discover what updates are needed.
  4. Recognize cyber risks from vendor agreements. Hackers often target vendors that support clinical practice, such as those for billing and other electronic data interchange transactions. Data breaches begun through a third party take an organization longer to identify, which gives cybercriminals more time to cause disruption. Rather than assuming that vendors are cybersecure, healthcare’s decision-makers must investigate vendors’ cybersecurity measures and create vendor contracts that demand high standards for risk mitigation.
  5. Plan on data triangulation and pattern recognition.Artificial intelligence (AI) tools can connect multiple sources of information. Among other implications, this means that previously deidentified patient photos or other records may now be identifiable. Further, deep learning models can decipher information about patients that even practitioners cannot: One study showed that deep learning models have a high degree of accuracy in detecting a patient’s self-reported race using radiographic images. Granted, there are many components to patients’ demographic information, and there may or may not be anything especially risky or amiss when a patient’s self-reported race is detected by an AI tool. But this example illustrates how even without bad actors, new risks are created when practitioners and practices cannot confidently say whether or not they have anonymized patient records. At a minimum, practices should take the following steps:
    1. Be mindful when naming image files. Avoid naming image files with identifiers connected directly to patients, such as their names or birth dates. Patients have found their private medical photos by Googling their own names.
    2. Consider revising informed consent forms. As an example, The Doctors Company’s template “Authorization for Use or Disclosure of Photographs/Images/Films/Videos” includes a space for patients to initial their acknowledgement that through changes in technology, someone may someday identify them, despite the practice’s best efforts to preserve anonymity.
  6. Know that for cybersecurity, the AI knife cuts both ways. Hackers can use AI tools to chase their goals in ever faster and more inventive ways, just as healthcare can. Fortunately, some experts propose that those who use AI for cybersecurity have advantages over those who use AI for cybercrime.
  7. Understand that AI is unavoidable. As statutory and regulatory levers are pushed and pulled, there are AI tools for cybersecurity that may suddenly become mandatory for use, or may suddenly be used by collaborating institutions, creating an urgent need for more sophisticated data governance. Even decision-makers who are less than enthusiastic about technological advancements would be wise to strengthen their data platforms and assess their teams’ readiness to safely implement new tools.

Commitment to a culture of patient safety demands cyber-safety diligence across clinical encounters, care collaboration, and business agreements. If we can lock certain digital doors and eliminate our most obvious vulnerabilities, then perhaps any hackers casing our neighborhoods will keep walking and pass on by.


The Doctor’s Advocate is published by The Doctors Company to advise and inform its members about loss prevention and insurance issues.

The guidelines suggested in this newsletter are not rules, do not constitute legal advice, and do not ensure a successful outcome. They attempt to define principles of practice for providing appropriate care. The principles are not inclusive of all proper methods of care nor exclusive of other methods reasonably directed at obtaining the same results.

The ultimate decision regarding the appropriateness of any treatment must be made by each healthcare provider considering the circumstances of the individual situation and in accordance with the laws of the jurisdiction in which the care is rendered.

The Doctor’s Advocate is published quarterly by Corporate Communications, The Doctors Company. Letters and articles, to be edited and published at the editor’s discretion, are welcome. The views expressed are those of the letter writer and do not necessarily reflect the opinion or official policy of The Doctors Company. Please sign your letters, and address them to the editor.

banner