Back

Healthcare Optimize Technology

Protecting patient care through advanced cybersecurity and AI

08/12/2026

by Angela Burnett and Joel du Plessis

Doctor holding a clipboard and talking to a patient

With regulatory challenges, legacy infrastructure, and an industry built on trust, healthcare presents unique roadblocks to cybersecurity organizations and teams. If patient care is to be safeguarded, resistance to change needs to be overcome.

Cyberattacks increasingly use modern AI tools. If healthcare firms are to remain competitive and secure, they will need to adapt to these new developments quickly, both in the tools they use and in the processes that enable them. To realize the benefits of AI while maintaining a strong cybersecurity posture, healthcare organizations must address challenges across people, technology, and governance.

Problem 1: Human error is scaled by AI tools

High regulatory environments often lead to risk-averse behavior and a grocery list of approvals and sign-offs for decisions across the organization. Accordingly, legacy systems and designs incorporate humans throughout the process. The reasoning for this is simple: The cost of mistakes is high—not just to bottom-line economics but to patient care. Unfortunately, however, even the most capable humans are still prone to make mistakes. To best position themselves, healthcare organizations need to prioritize minimizing opportunities for human error and match the pace of threat innovation with technological enablement.

In March 2026, Stryker was compromised by a cyber-attack. InTune credentials were stolen via phishing, allowing admin-level access to a critical tool to go undetected. Upon gaining access, the group was able to wipe tens of thousands of devices, effectively shutting down operations from business processes to patient care. While this incident reinforces the risk of phishing, it also highlights two other lessons:

  • First, phishing is explicitly linked to human error. As AI improves, so does the likelihood that phishing and vishing attacks succeed. Deepfakes are much more convincing than emails of the past.
  • Second, automated response and AI-enabled tools can help mitigate the impact of threats. There are few cases in which the tens of thousands of workforce devices need to be wiped, even by a privileged admin. Having an automated response to the actions of the attacker—both logging in from an unknown device and executing the wipe—could have mitigated some of the impact and freed security operations to identify and prevent the threat.

AI-enabled threats can keep security teams up at night because, at the end of the day, humans will continue to make errors even in the most elegantly designed systems. Automating threat responses through SOAR tools and redeploying humans to focus on proactive security overhauls allows healthcare organizations to prepare instead of react. Ultimately, patient care is built on a foundation of trust. Patients want to trust that providers will be there to help and that their information will be secure. Cybersecurity teams are guardians of that trust and will need to evolve with AI faster than threats to continue delivering in that role.

Problem 2: Legacy device designs constrain security overhauls

In 2025, SK Telecom disclosed a breach involving BPFDoor malware that compromised sensitive subscriber data associated with nearly 27 million users. Known vulnerabilities persisting in one’s environment caused major breaches for these companies, and medical devices present an interesting concentration of some of these legacy design vulnerabilities.

Medical devices deal with the monitoring, treating, and sustaining of health and therefore face a lot more regulatory scrutiny before being ready to sell. With lengthy regulatory timelines to develop alternatives and high replacement costs, these machines present a unique constraint on security and infrastructure teams as their price and functional lifetimes make security overhauls difficult. A series of EKGs or infusion pumps can sometimes be the reason decade-old vulnerabilities remain scattered throughout an organization. AI presents a unique opportunity for developers and security teams to modernize system and device design without sacrificing patient care. Shortening development and testing timelines means replacements can go to market quicker and healthcare organizations can modernize faster.

While the cost landscape around AI matures, its impact on timelines has been made clear. By bringing complex devices into alignment with organizational standards more quickly, healthcare organizations can streamline modernization efforts and keep pace with peers across industries. Old issues can be fixed faster both in and around the assets that deliver high-quality patient care.

Problem 3: Governance processes struggle to keep pace with AI changes

When a patient enters a hospital or a clinic, they often leave more than just blood samples behind. Some of their most sensitive information is also left behind. A key part of patient care is not just health and well-being but good data stewardship. That implicit trust in one’s provider is exactly what should guide unified zero-trust systems in our machine learning age. As AI tools change week to week and month to month, it’s important to create Agile frameworks that ensure AI governance moves just as quickly to ensure that patient care and trust can be maintained and improved.

In 2023, Samsung had a series of leaks due to employees using AI to optimize many of their tasks, from debugging to meeting transcriptions. The leak made headlines as proprietary source code and internal company discussions became training data for the models that were used. A ban on AI models was instituted and only lifted three years after the incident. In the years following the incident, privacy and observability have been vastly improved, and the overhaul demonstrates a key lesson: AI will move incredibly fast, and it’s important to create processes and policies that match that pace without sacrificing key security considerations.

Constant organization-wide rollouts maximize risk but get productivity scalers in people’s hands. Building all the needed controls is admirable and minimizes the risks but is disconnected from the pace of changes in Silicon Valley. Moving down the middle, pilot groups offer a compromise that lowers organizational risk, while empowering employees to scale their output. The approach helps establish security baselines and best practices without falling behind on developments. As security and support teams start to use the tools, the baselines and controls can start to keep pace with the changes as well.


The technological upheaval with AI is telling as organizations adopt, struggle to adopt, and sometimes refuse to adopt AI and automation in their workflows. Regardless, generative AI has become ubiquitous in the modern world, and it is important to lead the change rather than react to it. Healthcare may present additional industry-specific hurdles to the benefits of AI, but by no means is it excluded from the gains it stands to reap. The organizations best positioned will be those that pair AI adoption with thoughtful automation, modernization of legacy systems, and agile security models built on good principles that adapt to the evolving risk environment. Connect with us to explore how you can prepare your organization for the next steps in your AI and cybersecurity journey.