Skip to main content
The state of ai impact assessment
Five IT Security Mistakes That Put Patients at RiskPrivacy and Security
6 min readFor Enterprise IT Leaders

Five IT Security Mistakes That Put Patients at Risk

Healthcare organizations often stumble in cybersecurity, not due to a lack of good intentions, but because they repeat structural mistakes, thinking they're on the right track. When Aesto Health's December 2025 breach took five months to confirm, exposing 9.5 million patient records, or when Luminis Health's systems failure forced patients to use phone numbers instead of digital portals, these weren't isolated incidents. They were predictable outcomes of common organizational errors.

Here's why these mistakes persist, and what you can do to avoid them.

Why These Mistakes Keep Happening

Healthcare IT leaders often view clinical systems as support infrastructure rather than mission-critical assets. You're battling for budgets where a new MRI machine is approved quickly, but a security operations center proposal languishes. Meanwhile, threat actors have industrialized their operations. The Gentlemen ransomware group claimed over 675 attacks since mid-2025, with healthcare as their second most targeted sector. Your adversaries treat this as a business; your organization often treats it as an IT problem.

The gap between threat velocity and organizational response creates a pattern of reactive, underfunded decisions that leave exploitable weaknesses until an incident forces change.

Mistake 1: Treating Risk Analysis as a Compliance Exercise

Why it happens: Your team conducts an annual risk assessment because the HIPAA Security Rule requires it. You fill out the spreadsheet, rate some threats as "medium," implement a few controls, and file the documentation. The assessment becomes a checkbox, not a diagnostic tool.

The consequence: In April 2026, the HHS Office for Civil Rights settled four separate ransomware investigations for $1.165 million combined. The root cause in every case: failure to conduct an adequate risk analysis. When your risk assessment doesn't reflect actual threat exposure, your controls don't address real vulnerabilities. You're compliant on paper but exposed in practice.

The fix: Build your risk analysis around attack paths, not abstract categories. Map how an attacker would move from initial access through lateral movement to data exfiltration or system disruption. Identify the controls that would detect or prevent each stage. Test whether those controls work under realistic conditions. Document gaps with specific remediation timelines and resource requirements. Your risk analysis should tell you exactly where you'd fail under current threat scenarios.

Mistake 2: Underfunding IT Security Relative to Operational Impact

Why it happens: Healthcare budgets prioritize revenue-generating departments and direct patient care equipment. Security spending is justified through compliance requirements, not operational necessity. Your CFO sees IT as a cost center, not a care enabler.

The consequence: When Luminis Health's systems went down, clinical operations didn't just slow down. They shifted to manual processes that delay care and introduce safety risks. Electronic health record downtime creates immediate operational paralysis. Your emergency department reverts to pen and paper. Lab results get called in instead of transmitted digitally. Medication orders require manual verification. The operational cost of an incident dwarfs the investment required to prevent it.

The fix: Reframe your security budget requests around patient care continuity. Calculate the revenue loss per hour of EHR downtime. Document the patient safety risks of manual clinical workflows. Present security investments as insurance against operational paralysis, not just data protection. When you're asking for funds to maintain backup systems or implement network segmentation, translate that into "hours of uninterrupted care delivery" rather than technical specifications.

Mistake 3: Delaying Breach Confirmation While Legal Exposure Accumulates

Why it happens: Your team discovers suspicious activity and launches an investigation. You want complete information before making any public statements. Legal counsel advises caution. Weeks turn into months while you're determining scope and impact.

The consequence: Nutex Health disclosed their breach to the SEC on August 24. A class action lawsuit was filed in Texas three days later, before the company finished determining what was stolen. The window between breach disclosure and legal action has collapsed. Delayed confirmation doesn't protect you from liability. It extends the period during which affected individuals can't take protective action, which plaintiffs' attorneys will use against you.

The fix: Establish clear internal timelines for breach assessment phases. Set a maximum investigation period before preliminary notification, even if you don't have complete details. Draft templated disclosure language that communicates what you know, what you're still investigating, and what protective steps individuals should take. Coordinate with legal counsel on notification strategy before an incident occurs, not during crisis response. Your goal isn't perfect information. It's timely, accurate communication that demonstrates reasonable response.

Mistake 4: Accepting Vendor Risk as Inevitable

Why it happens: Your business associates and technology vendors are essential to operations. You sign their standard contracts, complete their security questionnaires, and assume they're managing their own security adequately. You don't have leverage to demand significant changes.

The consequence: Aesto Health's breach impacted 30 healthcare providers through a single business associate compromise. When your vendor's security fails, your patients' data is exposed and your organization faces regulatory consequences. The HIPAA Security Rule holds covered entities responsible for business associate security, regardless of where the breach originated.

The fix: Build vendor risk management into procurement requirements before contracts are signed. Require evidence of specific controls: network segmentation, multi-factor authentication, encryption at rest and in transit, security operations center monitoring, and incident response capabilities. Establish the right to audit vendor security annually. Include breach notification timelines and liability provisions in contracts. For critical vendors, require participation in tabletop exercises that test coordinated incident response. You can't eliminate vendor risk, but you can make it manageable and contractually bounded.

Mistake 5: Assuming Current Defenses Will Stop Tomorrow's Attacks

Why it happens: You've implemented the controls required by your last audit. Your security tools are deployed and configured. You're meeting regulatory baselines. The assumption is that maintaining current state equals adequate protection.

The consequence: Threat actors adapt faster than regulatory requirements update. The Gentlemen ransomware group emerged in mid-2025 and rapidly scaled to hundreds of attacks. Your static defenses are designed for last year's threat landscape. Plaintiffs' attorneys are already citing freely available CISA recommendations to establish the standard of care in court. The legal bar for reasonable cybersecurity exceeds minimum regulatory compliance.

The fix: Implement continuous security validation, not just periodic assessments. Run tabletop exercises that simulate current threat scenarios. Test whether your detection capabilities would identify the techniques used in recent healthcare breaches. Monitor threat intelligence specifically for healthcare-targeting groups and update defenses accordingly. Treat security as an operational discipline that requires ongoing refinement, not a project with an end date.

Prevention Checklist

Before the next budget cycle:

  • Calculate the hourly revenue impact of EHR system downtime
  • Document patient safety risks associated with manual clinical workflows
  • Present IT security funding requests in terms of care continuity, not just compliance

Before the next vendor contract:

  • Define required security controls as procurement requirements
  • Establish audit rights and breach notification timelines
  • Include vendor participation in incident response exercises

Before the next risk assessment:

  • Map realistic attack paths through your environment
  • Identify controls at each stage and test their effectiveness
  • Document gaps with specific remediation timelines and resource needs

Before an incident occurs:

  • Establish maximum investigation periods before preliminary notification
  • Draft templated breach disclosure language with legal counsel
  • Define roles and communication protocols for breach response

This quarter:

  • Run a tabletop exercise simulating a current healthcare threat scenario
  • Review threat intelligence for healthcare-targeting groups
  • Validate that detection capabilities would identify techniques from recent breaches

Healthcare IT security isn't failing because the solutions are unknown. It's failing because organizations repeat structural mistakes that leave known vulnerabilities unaddressed until an incident forces change. The cost of prevention is always lower than the cost of recovery, but only if you're willing to treat IT security as essential to patient care rather than ancillary to it.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like