Cyber Resilience in Healthcare | Health IT Security
- As cyber threats intensify, healthcare organizations are prioritizing cybersecurity resilience to maintain operations and safeguard patient care.
- Keith Duemling, VP/CISO at Catholic Health, defines cyber resilience as the ability to withstand cyber events while ensuring caregivers can continue providing optimal care.
- With clinicians heavily reliant on digital tools, paper-based backups are no longer sufficient.
Healthcare organizations are intensely focused on cybersecurity resilience to shield patient care from escalating digital threats. Learn how leading healthcare systems, like Catholic Health and UChicago Medicine, are developing strategies to withstand cyber events and ensure operational continuity. Discover how coordinated planning across departments alongside rigorous testing and validating data recovery are crucial for withstanding cyberattacks. Experts stress adapting clinical workflows and integrating cybersecurity with emergency management. The imperative focus is on framing cyber risk as a strategic issue, which helps gain vital executive support. news Directory 3 reports on the need for annual validation of recovery plans for critical applications, involving clinical and business leaders. Discover what’s next for effective health IT security.
Health Systems sharpen Focus on Cybersecurity Resilience
Updated May 27, 2025
As cyber threats intensify, healthcare organizations are prioritizing cybersecurity resilience to maintain operations and safeguard patient care. Leaders from catholic health, Children’s Hospital of Philadelphia (CHOP), UChicago Medicine, and CTG recently convened to discuss strategies for navigating the evolving landscape.
Keith Duemling, VP/CISO at Catholic Health, defines cyber resilience as the ability to withstand cyber events while ensuring caregivers can continue providing optimal care. The goal is swift recovery with minimal impact on patient safety, compliance, and reputation.
With clinicians heavily reliant on digital tools, paper-based backups are no longer sufficient. Karen Habercoss, VP, Chief Information Security & Privacy Officer at uchicago Medicine, emphasized integrating cybersecurity planning with emergency management across all departments.
Monique St. John, VP, CISO/Associate CIO at CHOP, echoed the need for collaboration. Regular continuity planning and exercise testing are essential to refine strategies. “Its not just the security team leading this,” St. John saeid.”its clinicians, operations, and business departments coming together.”
Chad Alessi, Managing Director for Cybersecurity at CTG, pointed out a gap between business impact analyses and disaster recovery. He stressed the importance of preparing clinical teams to operate without full system access by identifying alternate workflows and validating manual workarounds.
“I consider cyber resilience the ability of our systems,technology,and processes to withstand diffrent types of cyber events and continue operating so that our caregivers can provide the best care possible,” said Keith Duemling,VP/CISO at Catholic Health.
Panelists emphasized the need to test data restoration and usability.St. John urged annual validation of recovery plans for critical applications, involving clinical and business leaders.
Duemling highlighted the importance of anticipating cascading failures and personnel unavailability. Tabletop exercises that account for staff absences are becoming best practice, revealing knowledge gaps and improving readiness.
Cybersecurity leaders are also fostering cultural change by supporting other departments’ initiatives. duemling noted that participation in patient safety huddles translates to better collaboration during cybersecurity exercises.
Panelists agreed that framing cyber risk as an enterprise-wide hazard is crucial for gaining executive and board support. Duemling focuses on long-term program value, while Habercoss includes cyber risk in UChicago Medicine’s top five business risks.
St. John presents quarterly updates to CHOP’s board, emphasizing threats, responses, and investment alignment. She also highlighted a well-being initiative to help team members manage stress during high-pressure incidents.
Alessi noted the unique challenges of medical device security, emphasizing segmentation and isolation. Duemling stressed the need for nuanced decision-making, involving medical executives in scenarios where they must prioritize system shutdowns.
What’s next
Healthcare organizations must continue to prioritize cybersecurity resilience through coordinated planning, regular testing, and a focus on both technology and the well-being of their teams. By framing cyber risk as a strategic issue and fostering collaboration across departments, health systems can better protect patient care in the face of evolving threats.
