How Adaptive Cyber Security Can Enable Digital Health Adoption

Jun 27, 2018 | Healthcare Tech, Security, Social Media

Featured article by Dave Anderson, BlackRidge Technology

Digital health focuses on connecting the systems, tools, medical devices, and services together that deliver needed healthcare to each of us and gives critical data insights to each player across the healthcare delivery landscape that weren’t available before.  According to the recent 8th Annual Industry Pulse Report from Change Healthcare, security and privacy concerns are causing healthcare payers and providers to strongly reconsider whether or not they want to adopt these digital health technologies and mobile tools.   In fact, approximately half of all respondents stated that security and privacy were the leading causes of not widely adopting digital health technology, particularly around diagnostic apps and health monitoring devices.  Given the amount of coverage recently on healthcare organizations that have experienced a data breach, or been hit with a ransomware attack, this should come as no surprise.

Chart

Many healthcare organizations are starting to see cyber security as a key driver to support technological innovation that can directly improve patient care.  Much of this is being driven by the need to improve and replace much of the outdated IT systems that are currently in place across the overall industry.  These systems have shown to be unable to support the interoperability and data processing needs of today’s healthcare market as it shifts to more of a digital platform.

Due to the growth of breaches and attacks in healthcare, many organizations are starting to prioritize cybersecurity as they look to revamp these outdated IT systems.  A recent Health IT Security report concluded that 92 percent of healthcare organizations plan to increase their technology spending for cybersecurity needs.  What’s interesting, however, is the focus of this spend, based on what many healthcare organizations perceive as the greatest risk.

So much of the security “innovation” over the last decade has focused on faster and more agile identification of threats, viruses and attacks on a network or over a device.  The prevailing thought being that the sooner an attack can be identified, the quicker the likely response, resulting in a lessened impact to the business.  The underlying problem with this approach is that these tools target identification of threats after an attacker is already on the network or has already taken control of a device.  These technologies “detect” rather than “prevent”.

Unfortunately, this causes a great deal of peril to the healthcare industry who is trying to balance the need to implement new digital health technologies to remain competitive with outdated systems and immature security processes.  The approach of using these traditional detection tools and products is exacerbating the problem for many healthcare organizations, who are finding that these detection tools simply can’t keep up with the attackers.  It’s getting so bad that several healthcare CISOs who were recently surveyed stated that they are so certain they will be subject to a ransomware attack that they are allocating budget to pay the ransom, as this is just easier than dealing with the security issues these products create.

As described earlier, the current mindset on security challenges caused by these ineffective tools is hindering, even disabling, an organization’s ability to implement digital health technology.  However, a different mindset can turn security into an enabler of digital health initiatives, regardless of the state of an organization’s IT infrastructure and processes.  How?

The new mindset needs to focus on prevention, rather than detection.  We’ve seen that current security technologies simply try to detect the bad actor once they’re in the network.  Some security companies are starting to position products that try and prevent the bad actor from accessing the network, but this doesn’t go far enough.  The new focus really should be on preventing the bad actor from even seeing or knowing that a network or segment, and the associated applications, systems and devices running on the network, even exist in the first place.  Attackers don’t try to breach a network or device that they can’t see or don’t know exists.

This shift is enabled by embedding network cloaking technologies that can significantly prevent the risk of a security breach to their critical patient care delivery systems and connected devices.  Cloaking technologies can keep any unknown or unauthorized users from ever seeing these digital health technologies or devices, whether they’re legacy or brand-new systems.  The risk of a compromise is virtually alleviated when IT systems are visible to only known and authorized identities.  Further, cloaking technologies can be implemented prior to a network session being established, so there is no further complexity or management overhead added to a network’s topology.

Adapting one’s security mindset to focus on removing all visibility of a network to unknown or unauthorized actors, even insiders, can allow healthcare organizations to start to receive the potential value of digital health technologies.  This new adaptive approach to security can directly enable more effective security capabilities, but also enable greater operational and financial value in supporting digital health initiatives that can improve patient care.

About the Author

Dave is a senior security marketing and strategy executive, and currently managing marketing strategy for BlackRidge Technologies.  Dave has 25 years of experience in data security and privacy, security analytics and risk management, helping companies develop and grow markets, and commercialize security technologies to protect financial, customer, patient, and infrastructure across global industries.  Dave is a frequent publisher and speaker on cyber security and analytics, and applying security to build corporate value, and holds an MBA from Duke University.

For more information on BlackRidge Technology, please visit www.blackridge.us.

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more