惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
量子位
GbyAI
GbyAI
腾讯CDC
T
Tailwind CSS Blog
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
Jina AI
Jina AI
IT之家
IT之家
Y
Y Combinator Blog

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
The Cyber Resilience Standard Every Hospital CIO Must Meet
David Chou · 2026-05-17 · via Forbes - Innovation
Dad and son outdoors

Dad and son having fun outdoors.

getty

Health systems must deliver safe patient care for 30 days or longer without core technology systems. This is no longer a regulatory goal but the minimum operational standard for cyber resilience in healthcare. Most health system CIOs have not planned for this. The Joint Commission and the American Hospital Association started the Cyber Resilience Readiness (CRR) program to help hospitals assess and improve their ability to sustain clinical operations during extended cyber outages.

Cybersecurity is already expensive, with the average healthcare data breach costing $7.42 million. Greater costs come from daily downtime, lost revenue from manual charge capture and billing, and patients unable to access care and treatment.

The CRR program begins with a free self-assessment tool. It asks if your organization can provide safe care if technology fails. The survey covers many areas, but four themes are the top priority for a healthcare CIO.

Cyber Resilience Is Clinical Operations

The assessment highlights a key issue: clinical, business, emergency management, and disaster recovery are often siloed rather than integrated. Typically, IT manages application recovery, emergency management leads incident response, and clinical leadership oversees patient safety. These groups rarely collaborate before a crisis, resulting in last-minute coordination. CIOs should unite these departments proactively to ensure readiness.

The Board Must Be Involved

The CRR assessment asks how often leaders brief the board on cybersecurity and its impacts on patient care. It also asks whether boards distinguish clinical from business continuity. These topics are related but not the same. A CIO who links cyber risk to patient safety, revenue, and regulation will benefit the board.

Downtime Plans Must Work Operationally

The assessment's key takeaway is that downtime plans must be tested realistically across all shifts and service lines—not just annually, and not only in a conference room. Effective testing means running scenarios that stretch 30 days or more. Senior leaders must observe the exercises and act on findings. If drill results are ignored, the effort is wasted. Hospitals that survive cybersecurity events do so because staff have instinctive responses built through repeated, realistic practice.

Inventory Visibility Is Crucial.

Healthcare organizations must keep inventories of all biomedical devices, IoT systems, imaging devices, building controls, software, and anything on the network. They must map all assets to clinical risk. Hospitals have decades of connected technology, but no one department fully owns it all. The CIO must integrate asset visibility, data classification, vendor risk, and business continuity into one model. This includes medical equipment and other hardware on the network that are outside IT control.

The self-assessment does not score your organization; it identifies gaps for action. CIOs must decide who to brief, what to fix, and how fast to act—these choices differentiate compliance from resilience.

What’s Next For CIOs

The CRR program and assessment are a starting point. How a CIO uses its findings determines if it becomes a real advantage. Healthcare CIOs must build business continuity plans that last weeks, not just hours or days. They should run tabletop exercises for manual operations on days 3, 10, and 30.

CIOs should focus on a disaster recovery MVP that requires only the critical systems to keep operations running in a crisis. Full backups can be complex and costly. An MVP focuses on speed, simplicity, and effectiveness. The goal is fast recovery to a minimal but safe level.

Combining the CRR assessment with an MVP program is essential. Healthcare leaders must act now: assess resilience, make key improvements, and ensure teams can provide patient care for 30 days or more under any circumstances. The healthcare CIO can lead this challenge.