惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Y
Y Combinator Blog
月光博客
月光博客
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
博客园 - 司徒正美
V
Visual Studio Blog
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
The Cloudflare Blog

Forbes - Healthcare

How to Prevent Domestic Violence Deaths UK Smoking Ban Highlights Debate Over The Proper Function Of Government What To Do When Someone You Love Has Cancer Psychedelic Medicine Goes Mainstream: Breakthrough or Bubble? Humana Profits Eclipse $1 Billion As Medicare Costs Ease Slightly What Are Peptides And Why Is Everyone Talking About Them? Tonsillectomy Doesn’t Lead To Illness, But Tonsillitis Just Might Does Retail Pharmacy Have A Tower Records Problem? Precision Radiation Therapy Could Offer New Hope For Hard-To-Treat Cancers Centene’s Obamacare Enrollment Drops By 2 Million After Congress Strips Subsidies RFK Jr.’s Messaging Could Be Impacting Food And Pharmaceutical Choices Over A Million Road Crash Deaths Annually Prompt $350 Million Investment Breast Cancer Screening Tool Avoids Radiation, Compression, Contrast Large Study Finds Benefits Of Doula Care On Postpartum Outcomes TrumpRx Has Signed Deals With Nearly Every Major Drugmaker. Are Prices Actually Falling? America Can’t Lower Healthcare Costs Without A Moonshot Trump’s Orders Elevate The Medical Status Of Psychedelics And Cannabis Mark Cuban’s Cost Plus Drugs, Humana Partner To Take On Employer Drug Costs Cell, Gene And Specialty Drug Costs Intensify For Health Plans U.S. Tennis Participation Continues Growth. Up 54 Percent Since 2019 New AMA Study Finds Burnout Is Decreasing Among Medical Residents And Fellows Daytime Naps May Be A Sign Of Serious Health Problems, Study Reveals New Antibody Drugs Target Disease From Within Concierge Medicine Was Built For The Few. Here’s How To Open It To The Many Burnout in Medicine Is Still Prevalent, With Emergency Medicine Leading Who Is Actually Qualified To Give Advice On Peptides And Who Isn’t What the 49ers Can Teach Leaders About Handling False And Misleading Narratives Do Older Adults Need Routine Colonoscopies Or Low Thyroid Drugs? Your Period, Your Proteins, Your Health Doctors Say Hegseth’s Flu Vaccine Decision Will Weaken Military Readiness
The Cyber Resilience Standard Every Hospital CIO Must Meet
David Chou · 2026-05-17 · via Forbes - Healthcare
Dad and son outdoors

Dad and son having fun outdoors.

getty

Health systems must deliver safe patient care for 30 days or longer without core technology systems. This is no longer a regulatory goal but the minimum operational standard for cyber resilience in healthcare. Most health system CIOs have not planned for this. The Joint Commission and the American Hospital Association started the Cyber Resilience Readiness (CRR) program to help hospitals assess and improve their ability to sustain clinical operations during extended cyber outages.

Cybersecurity is already expensive, with the average healthcare data breach costing $7.42 million. Greater costs come from daily downtime, lost revenue from manual charge capture and billing, and patients unable to access care and treatment.

The CRR program begins with a free self-assessment tool. It asks if your organization can provide safe care if technology fails. The survey covers many areas, but four themes are the top priority for a healthcare CIO.

Cyber Resilience Is Clinical Operations

The assessment highlights a key issue: clinical, business, emergency management, and disaster recovery are often siloed rather than integrated. Typically, IT manages application recovery, emergency management leads incident response, and clinical leadership oversees patient safety. These groups rarely collaborate before a crisis, resulting in last-minute coordination. CIOs should unite these departments proactively to ensure readiness.

The Board Must Be Involved

The CRR assessment asks how often leaders brief the board on cybersecurity and its impacts on patient care. It also asks whether boards distinguish clinical from business continuity. These topics are related but not the same. A CIO who links cyber risk to patient safety, revenue, and regulation will benefit the board.

Downtime Plans Must Work Operationally

The assessment's key takeaway is that downtime plans must be tested realistically across all shifts and service lines—not just annually, and not only in a conference room. Effective testing means running scenarios that stretch 30 days or more. Senior leaders must observe the exercises and act on findings. If drill results are ignored, the effort is wasted. Hospitals that survive cybersecurity events do so because staff have instinctive responses built through repeated, realistic practice.

Inventory Visibility Is Crucial.

Healthcare organizations must keep inventories of all biomedical devices, IoT systems, imaging devices, building controls, software, and anything on the network. They must map all assets to clinical risk. Hospitals have decades of connected technology, but no one department fully owns it all. The CIO must integrate asset visibility, data classification, vendor risk, and business continuity into one model. This includes medical equipment and other hardware on the network that are outside IT control.

The self-assessment does not score your organization; it identifies gaps for action. CIOs must decide who to brief, what to fix, and how fast to act—these choices differentiate compliance from resilience.

What’s Next For CIOs

The CRR program and assessment are a starting point. How a CIO uses its findings determines if it becomes a real advantage. Healthcare CIOs must build business continuity plans that last weeks, not just hours or days. They should run tabletop exercises for manual operations on days 3, 10, and 30.

CIOs should focus on a disaster recovery MVP that requires only the critical systems to keep operations running in a crisis. Full backups can be complex and costly. An MVP focuses on speed, simplicity, and effectiveness. The goal is fast recovery to a minimal but safe level.

Combining the CRR assessment with an MVP program is essential. Healthcare leaders must act now: assess resilience, make key improvements, and ensure teams can provide patient care for 30 days or more under any circumstances. The healthcare CIO can lead this challenge.