{"id":590553,"date":"2026-04-17T22:17:20","date_gmt":"2026-04-17T22:17:20","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/590553\/"},"modified":"2026-04-17T22:17:20","modified_gmt":"2026-04-17T22:17:20","slug":"health-cares-biggest-cybersecurity-vulnerability-is-structural","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/590553\/","title":{"rendered":"Health care\u2019s biggest cybersecurity vulnerability is structural"},"content":{"rendered":"<p>On April 6, cancer patients at <a href=\"https:\/\/thecyberexpress.com\/signature-healthcare-cyberattack\/\" target=\"_blank\" rel=\"noopener nofollow\">Brockton Hospital<\/a> in Massachusetts showed up for chemotherapy infusions and were told to go home. The hospital\u2019s information systems had been hit by a cyberattack. The ER closed. Ambulances were diverted. Staff switched to paper records. Patients were told to call back later to reschedule their treatment.<\/p>\n<p>This wasn\u2019t the first time that this kind of incident has happened. In May 2024, the <a href=\"https:\/\/www.hipaajournal.com\/ascension-cyberattack-2024\/\" target=\"_blank\" rel=\"noopener nofollow\">Ascension ransomware attack<\/a> took down systems across 136 hospitals for six weeks. That same year, the <a href=\"https:\/\/cyberscoop.com\/change-healthcare-breach-affected-100-million-americans-marking-a-new-record\/\" target=\"_blank\" rel=\"noopener nofollow\">Change Healthcare breach<\/a> compromised the personal health information of 100 million Americans, roughly one in three people in the country, and disrupted billing and authorization systems so severely that physician practices warned they might have to close their doors. After the Change breach, an <a href=\"https:\/\/www.aha.org\/2024-03-15-aha-survey-change-healthcare-cyberattack-significantly-disrupts-patient-care-hospitals-finances\" target=\"_blank\" rel=\"noopener nofollow\">AHA survey<\/a> of nearly 1,000 hospitals found that 74% reported direct impact on patient care.<\/p>\n<p>What\u2019s coming may be even bigger.<\/p>\n<p>When health care infrastructure is attacked and held for ransom by hackers, patients become real casualties. People miss chemotherapy appointments, echocardiograms, and lifesaving surgeries. Prescriptions can\u2019t be filled. Emergency rooms can\u2019t look up your medication allergies when you arrive by ambulance.<\/p>\n<p>I come at this from two directions that don\u2019t usually overlap. I\u2019m a patient advocate \u2014 I\u2019ve spent years working\u00a0for transparency in how health systems handle our data and make decisions that affect our care. I\u2019m also a security researcher. Finding security flaws\u00a0 and navigating the painstaking process of coordinating with companies to close vulnerabilities takes a ton of time and effort.\u00a0\u00a0<\/p>\n<p>Those two experiences have taught me the same lesson from opposite sides: The gap between finding a problem and fixing it in health care is not technical. It\u2019s structural.<\/p>\n<p>A new kind of arms race<\/p>\n<p>The same capabilities being celebrated for drug discovery are now powerful enough to find and weaponize software vulnerabilities at machine speed, and health care\u2019s defenses weren\u2019t built for that pace. And while health care has been racing to find cures with artificial intelligence, nation-states have been in an arms race to wield power over each other. This adversarial landscape is compounded by a race between Silicon Valley and health systems to compete, often with each other.<\/p>\n<p>On April 7, Anthropic announced <a href=\"https:\/\/www.anthropic.com\/project\/glasswing\" target=\"_blank\" rel=\"noopener nofollow\">Claude Mythos Preview<\/a>, an AI model capable of autonomously discovering thousands of critical software vulnerabilities and generating working exploits without human guidance. Rather than release it commercially, the company launched <a href=\"https:\/\/www.anthropic.com\/project\/glasswing\" target=\"_blank\" rel=\"noopener nofollow\">Project Glasswing<\/a>, a $100 million coordinated disclosure program giving restricted early access to AWS, Apple, Google, Microsoft, and other partners so they could patch their own products. It appears that the health sector was not included. Anthropic estimated comparable capabilities will appear in other models within six to 18 months.<\/p>\n<p>Five days later, the Cloud Security Alliance (CSA) <a href=\"https:\/\/labs.cloudsecurityalliance.org\/mythos-ciso\/\" target=\"_blank\" rel=\"noopener nofollow\">published \u201cThe AI Vulnerability Storm,\u201d<\/a> co-authored by former Cybersecurity and Infrastructure Security Agency Director Jen Easterly, Bruce Schneier, Katie Moussouris, and dozens of enterprise security leaders. Their central finding: The time between a vulnerability being disclosed and a working exploit appearing has collapsed to under one day. Every organization, they write, should begin a 90-day preparedness plan immediately.<\/p>\n<p>Security researcher <a href=\"https:\/\/cybernews.com\/ai-news\/hutchins-questions-anthropic-mythos-bug-hunting-ai\/\" target=\"_blank\" rel=\"noopener nofollow\">Marcus Hutchins<\/a>, famous for stopping the WannaCry ransomware attack that crippled critical infrastructure, including\u00a0 hospitals, in 2017, offered a blunt critique: Bugs don\u2019t go unpatched because no one can find them. They go unpatched because no one is being paid to patch them fast enough.<\/p>\n<p>Patients caught in the middle<\/p>\n<p>Experts in the field of health care cybersecurity <a href=\"https:\/\/www.statnews.com\/2024\/08\/13\/cybersecurity-healthcare-cyberattack-resiliency-patient-data-protection\/\" rel=\"nofollow noopener\" target=\"_blank\">have warned about this coming reckoning for years<\/a>. The challenge isn\u2019t that hospitals don\u2019t care about security. It\u2019s that health systems don\u2019t control some of the software they depend on, and policy waits until a crisis arrives to actually change things. We scaled up health care\u2019s dependence on digital infrastructure without scaling up the incentives and obligations to protect what was built. When a new vulnerability is found, the hospital can\u2019t simply push a fix. It waits for the vendor to develop a patch, for compatibility testing, and sometimes regulatory clearance before a medical device can be updated, to validate the patch is safe. A hospital can\u2019t push a patch to electronic health records any more than a homeowner can reinforce a levee owned by the county that may break in a hurricane.\u00a0<\/p>\n<p>The <a href=\"https:\/\/labs.cloudsecurityalliance.org\/mythos-ciso\/\" target=\"_blank\" rel=\"noopener nofollow\">CSA report<\/a> says it plainly: \u201cAttackers already operate as syndicates, crowdsourcing, sharing tools, and moving as a collective. Defenders must do the same.\u201d Health care hasn\u2019t done the same because it\u2019s not built in the same way. Securing health care infrastructure from hackers was barely manageable when attackers needed weeks or months to weaponize a new vulnerability. It is not manageable when that <a href=\"https:\/\/zerodayclock.com\" target=\"_blank\" rel=\"noopener nofollow\">timeline to exploit<\/a> a vulnerability is measured in hours, and the patch can take months or years. This means in the months ahead, regardless of whether hackers are using Mythos or other models that manage to catch up in this arms race, attackers will be able to exploit vulnerabilities much faster than health care can defend itself.<\/p>\n<p>Large academic medical centers have dedicated cybersecurity teams and vendor relationships that give them leverage. Community hospitals, rural critical access facilities, and safety-net clinics, the ones many of us depend on, run older equipment with smaller IT staffs and less bargaining power. They are the least able to patch fixes. Community hospitals go back online last. And they serve the patients with the fewest alternatives when the doors close.<\/p>\n<p>When every link in the chain has a different economic incentive, speed of response isn\u2019t a function of urgency. It\u2019s a function of who pays. And in health care, the entity with the most to lose (the patient) has no seat at the table where patching decisions are made. <\/p>\n<p>We can\u2019t forecast where the storm will hit<\/p>\n<p>While forecasting a hurricane, the National Weather Service publishes a cone of uncertainty, a widening funnel showing where landfall will likely happen. It\u2019s a scientific forecast so you can make decisions before the wind arrives. Health care cybersecurity doesn\u2019t have that kind of forecast. But an unprecedented storm is forming.<\/p>\n<p>Think of Anthropic\u2019s <a href=\"https:\/\/www.anthropic.com\/glasswing\" target=\"_blank\" rel=\"noopener nofollow\">Project Glasswing<\/a> as an example levee-reinforcement program for the organizations inside the wall. Health care\u2019s patchwork of vendor-controlled systems sits outside that wall. The offensive timeline just collapsed to hours. The defensive timeline for device manufacturers, regulatory clearance, and downstream testing\u00a0 hasn\u2019t moved at all.<\/p>\n<p>Some infrastructure to defend against this exists, and it has a short window to scale faster than the threat. For example <a href=\"https:\/\/arpa-h.gov\/explore-funding\/programs\/upgrade\" target=\"_blank\" rel=\"noopener nofollow\">Project UPGRADE<\/a> and the <a href=\"https:\/\/archive.aicyberchallenge.com\" target=\"_blank\" rel=\"noopener nofollow\">ARPA-H Cyber Challenge<\/a> used AI to find and patch vulnerabilities, while CISA developed <a href=\"https:\/\/www.cisa.gov\/resources-tools\/services\" target=\"_blank\" rel=\"noopener nofollow\">no-cost tools and services<\/a> for under-resourced facilities. Security researchers have begun <a href=\"https:\/\/www.thecipherplatform.com\/home\" target=\"_blank\" rel=\"noopener nofollow\">tracking patient casualties<\/a> from cyberattacks on hospitals. The Health Sector Coordinating Council is also <a href=\"https:\/\/protect.checkpoint.com\/v2\/r01\/___https:\/\/healthsectorcouncil.org\/wp-content\/uploads\/2026\/04\/AI-Third-Party-Risk-Guide.pdf___.YzJ1OmJvc3Rvbmdsb2JlMTpjOmc6ZmFlNTlkYWQ2MTk3NmI2NDVmNjI2ODNiNDFlYjQzM2U6NzpiMmMyOmUwOWYzNmQ0MTIxYWNiYmQxNjQyYmRmOWIyNWJhNTEzYzU5NWI1YzQ4YWMyYmE0MzViMWZjYzBhZDY1YTFkNGM6aDpUOkY\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">working to mobilize resources.<\/a><\/p>\n<p>To make sure better resources get to your community, call your senators about <a href=\"https:\/\/www.congress.gov\/bill\/119th-congress\/senate-bill\/3315\" target=\"_blank\" rel=\"noopener nofollow\">this bipartisan bill,<\/a> now awaiting a Senate vote. As a matter of patient safety, if we are building the digital infrastructure that hospitals and patients depend on, we need the mandates, incentives, and funding to defend it.<\/p>\n<p>Most patients have no idea this landscape exists. We\u2019re told our records are protected by HIPAA. We trust that the devices monitoring our hearts or delivering our medications are secure. We assume someone is in charge of making sure a cyberattack can\u2019t cancel our chemotherapy or shut down the ER we need.\u00a0<\/p>\n<p>Regardless of what happens with Mythos, this problem isn\u2019t going away in the near future. And when cyberattacks hit, it\u2019s our families, friends, and local communities who won\u2019t get a lifesaving treatment. It\u2019s an ambulance that diverts to an ER that now has a 24-hour wait period. Patients are the ones on low ground when the cyber levees break.<\/p>\n<p>Andrea Downing is a security researcher, patient advocate, and co-founder of <a href=\"https:\/\/lightcollective.org\" target=\"_blank\" rel=\"noopener nofollow\">The Light Collective.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"On April 6, cancer patients at Brockton Hospital in Massachusetts showed up for chemotherapy infusions and were told&hellip;\n","protected":false},"author":2,"featured_media":590554,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[181,97,252,253,9447,21450],"class_list":["post-590553","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-artificial-intelligence","tag-health","tag-health-care","tag-healthcare","tag-hospitals","tag-patients"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/590553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=590553"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/590553\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/590554"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=590553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=590553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=590553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}