
Share
Healthcare's cybersecurity dashboards are lighting up with more findings than ever, but remediation rates are falling fast. For patients, the gap between spotting a risk and closing it can be the difference between safety and harm.
Picture a hospital's security team staring at a dashboard that's more crowded than it's ever been. Every blinking alert represents a potential doorway into systems that keep patients alive: infusion pumps, electronic health records, the servers that route lab results to the right bed. Finding those doorways is only step one. Someone still has to close them.
That gap between seeing a risk and fixing it is quickly becoming the defining challenge in healthcare cybersecurity, and the numbers show why. Across the first half of 2025, healthcare organizations closed roughly 23% of the risks uncovered during security assessments, according to rolling data from Fortified Health Security based on the NIST Cybersecurity Framework 2.0. By the first half of 2026, that closure rate had collapsed to 6.4%. Meanwhile, critical and high-risk findings climbed 60% over the same period.
Think of it like a home inspection. A thorough inspector might flag a cracked foundation, faulty wiring and a leaky roof. That's useful information, but it doesn't fix anything. If the homeowner never calls a contractor, the house is no safer than before the inspection, and arguably worse off, because now everyone knows exactly where the vulnerabilities are. Hospitals are increasingly good at running the inspection. They're struggling to hire the contractor.
The rise in flagged risks isn't necessarily a sign that healthcare networks are suddenly less secure. It's more a sign that they're finally being measured properly. As more organizations adopt NIST CSF 2.0, a framework that gives healthcare a structured way to identify, categorize and prioritize cyber risk, they're uncovering problems that were always there but never systematically tracked.
Supply-chain risk findings, for instance, are on pace to increase sixfold over 2025 levels, with nearly two-thirds landing in the critical-or-high severity band. Identity and access findings, the kind that determine who can log into which systems and see which patient records, are tracking toward a fourfold increase, with a similarly severe share.
Neither trend means hackers suddenly discovered new ways into hospital networks this year. It means hospitals are finally looking in the right places. That's genuine progress. But a map of every pothole in a city doesn't fill a single one. Without a matching investment in remediation, better visibility risks becoming a liability rather than an asset, especially if that information ends up in the hands of a regulator or plaintiff's attorney after a breach.

Regulatory pressure is likely to intensify that dynamic. No one yet knows the final shape or timing of the next HIPAA Security Rule revision, but the trajectory points toward more required evidence, more accountability and more demonstrated resilience. Anchoring to a recognized framework like NIST CSF 2.0 does double duty here: it helps organizations rank and work through risk internally, and it gives regulators, state attorneys general, cyber-insurers and hospital boards a credible, documented answer when they ask how leadership decided what mattered most.
That documentation matters more than it might seem. When a serious risk surfaces and something goes wrong, an organization needs to walk investigators through how it sized up the exposure, why it tackled problems in the order it did, and what it actually did about it. Building that record against a recognized framework means having the answer on file before an insurer, regulator or breach ever forces the question.
Getting there requires framing this correctly for hospital boards, many of which understandably see cybersecurity spending as a cost center rather than a patient safety investment. A compliance-driven program tends to wait, asking when it legally has to act, sometimes stalling until the HIPAA Security Rule is finalized. A security-driven program asks a different question: what's worth protecting first, for the sake of the patients and the care that depends on it. That reframing can shift a boardroom conversation from "what does this cost us" to "what do we gain by starting now."
None of this works as a one-time push. Remediation has to run like a standing program, not a series of scattered projects that flare up after an audit and fade once the report is filed. That means someone has to own every identified risk, with clear expectations for how quickly it gets addressed. It means an independent check to confirm that a finding marked "closed" is actually closed, not just marked that way on a spreadsheet. It means a real process for formally accepting a certain amount of risk when full remediation isn't feasible right away, a clear picture of which fixes carry hidden dependencies that could make them riskier than the original problem, and an escalation path that kicks in automatically when a critical item lingers too long. Strip away that scaffolding, and even the most thorough assessment becomes little more than a well-organized list of problems nobody solved.
It also means letting go of the idea that a single metric tells the whole story. Mean time to remediate is worth tracking, but on its own it can mislead. A minor issue on an internal system used by three people carries a very different level of danger than an actively exploited flaw sitting on a system exposed to the open internet. The findings that carry real consequence, the ones rated critical, under active attack, or facing outward, deserve their own tracking: how long they've lingered, whether the organization is meeting its own targets, how many exceptions it's carrying, and whether someone other than the person who claimed a fix actually verified it.
The health systems that stay out of the headlines over the next year will likely be the ones that turn every flagged risk into something concrete: a clear sense of what to fix first, a plan sturdy enough to survive real-world complications, and the budget and staff needed to see it through. Assessments have gotten sharper. Now the industry needs to prove it can act on what those assessments reveal, because behind every unresolved finding is a patient whose care depends on a system nobody's gotten around to fixing yet.
Tags
Original Sources
Healthcare’s cybersecurity remediation challenge
↗ https://www.healthcareitnews.com/news/healthcares-cybersecurity-remediation-challenge
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
3 September 2026
22 articles
Related Articles

Fake Citations Generated by AI Are Quietly Shaping Australian Policy Debates
Security & Risk · 6 min

Anthropic Paused AI Training After Claude Took Unauthorized Actions in Cyber Tests
Security & Risk · 5 min

OpenAI Calls for Global "Surge" in Cyber Defense as AI-Powered Attacks Loom
Security & Risk · 5 min
Related Articles

Fake Citations Generated by AI Are Quietly Shaping Australian Policy Debates
Security & Risk · 6 min

Anthropic Paused AI Training After Claude Took Unauthorized Actions in Cyber Tests
Security & Risk · 5 min

OpenAI Calls for Global "Surge" in Cyber Defense as AI-Powered Attacks Loom
Security & Risk · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.