Despite numerous challenges, healthcare organisations can adapt to modern cybersecurity threats, balance data interoperability with privacy, and strengthen compliance in the age of AI.
To understand how this can be achieved, Digital Journal spoke with Chirag Shah, Global Information Security Officer & DPO at Model N. Here Chirag discusses key strategies for risk mitigation, the shift toward zero-trust architecture, managing third-party vendor risks, and lessons learned from containment in recent data breaches.
Digital Journal: What are the biggest cybersecurity threats facing healthcare organizations today, and how are IT leaders handling risk mitigation?
Chirag Shah: Ransomware and stolen credentials remain top concerns, but the speed of attacks has escalated. Threat actors use AI to scale phishing, execute deepfake social engineering and instantly find software or infrastructure vulnerabilities, leaving a much smaller window between compromise and damage. Current risks also include delayed vulnerability remediation, exposed cloud services, unmanaged endpoints, and third-party platforms that can become an entry point into healthcare environments. Priorities right now centre on identity protection, third-party risk management, particularly with AI partners handling PHI, and catching control gaps before they lead to public breaches.
DJ: How do healthcare organizations balance smooth data interoperability with strict privacy demands?
Shah: Access issues usually stem from failing to revoke permissions over time rather than granting them in the first place. Accounts are often set up for temporary needs and left open indefinitely. Current risks are increasing as healthcare organizations connect more systems, APIs, data warehouses and AI-enabled tools, creating more places where PHI can move outside intended controls if ownership and monitoring are weak. The solution is straightforward: enforce least privilege, implement time-bound permissions, verify business associate and vendor safeguards, and assign an explicit owner to every API integration. System interoperability does not require open-ended connection points.
DJ: What role do zero-trust architectures and access controls play in current healthcare IT strategies?
Shah: Treating identity as the modern security perimeter is now a daily operational requirement. Every access request requires verification, permissions remain tight and credentials cycle regularly. Current risks include credential theft, MFA fatigue, privileged account misuse, stale service accounts and non-human identities that can persist unnoticed across cloud and production environments. As non-human identities, like automated AI agents and system integrations, act on behalf of users, they require the same level of oversight, lifecycle management and scrutiny as employees.
DJ: How can health IT teams maintain regulatory compliance without slowing down everyday operations?
Shah: Compliance can no longer function as a year-end audit drill. Recent data show that 53% of life sciences and technology leaders are more risk-averse today regarding compliance than they were five years ago, driving a major shift toward automated monitoring, policy-as-code, layered defense controls and continuous evidence collection. Current risks include audit evidence gaps, delayed patching, incomplete vendor reviews, rapid AI adoption without clear governance, and evolving privacy requirements around PHI and cross-border data handling. Security teams must also evaluate new software before deployment; supply chain risks including integrating technologies; reviewing an AI vendor after launch creates simultaneous compliance and security risks.
DJ: What key lessons from recent data breaches are reshaping security practices and investments?
Shah: Eventually, a third-party vendor, credential or API configuration will fail. Current breach lessons show that healthcare risk is often amplified by vendor concentration, file-transfer tools, cloud platforms, misconfigured APIs and delayed incident reporting from downstream partners. Investments that yield the best results focus on limiting the blast radius through network segmentation, tightly scoped permissions, immutable logs, rapid credential revocation and strict vendor access boundaries. Organizations are pushing partners to provide proof of active controls and commit to immediate incident reporting. Prevention remains necessary, but containment is what prevents widespread damage.
