惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
量子位
雷峰网
雷峰网
宝玉的分享
宝玉的分享
V
Visual Studio Blog
博客园_首页
小众软件
小众软件
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
S
SegmentFault 最新的问题
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学

Forbes - CIO Network

Ralliant’s Amir Kazmi On Wiring AI Into Critical Infrastructure Nvidia Buys Kumo AI To Bring AI Predictions To Business Data Anthropic's Fable 5 AI Model Offers More Power At A Higher Price Argentina Wants To Let AI Own Companies. Here’s What That Means The AI Conversation CEOs Are Not Having Out Loud Moneyball Meets AI: How The New York Jets Are Charting An AI Future How Anthropic, OpenAI and Nvidia Are Driving the AI Economy Wall Street Is About To Test AI's Trillion-Dollar Valuations The VPN Risk Too Many Companies Ignore The Agentic Enterprise Got A Major Upgrade This Summer. OpenAI, Anthropic And The $1 Trillion Question: Who Really Wins From AI? Trump's AI Evaluations Order: Right Policy, Unfinished Governance Trump's AI Order Creates A New Test For Frontier AI—And Public Trust Microsoft Build 2026 Reveals the Future of AI, Data and ERP Artificial Intelligence Positioned To Disrupt $5 Trillion Industry Healthcare CIOs Should Take Note Of Copilot Health Innovation At The Pace Of AI Requires A Different Corporate Metabolism How Expedia Is Reinventing Travel Through AI And Agentic Design The AI Risks CISOs Aren’t Talking About Enough Prat Vemana On Leading Technology, Product And AI Innovation At Target AI Spurs A Cultural Shift In A 1,000-Developer Insurance Company Rewiring Omnicom’s Operating Model For AI At Scale 4 AI Strategy Questions Every Executive Needs To Drive ROI Building A Retail Platform Across Iconic American Brands Why AI Likely Means More Work For Humans AI Flattening Organizations Is The Latest Chapter In A Continuing Story OpenAI And Anthropic Are Testing Two Very Different AI Business Models Why Nvidia Needs More Than GPUs To Win The AI Infrastructure Race Google Wants Gemini To Become The Operating Layer For AI Tokenomics 101: Cost Of Getting Work Done (Not The Cost Of Tokens).
The Cyber Resilience Standard Every Hospital CIO Must Meet
David Chou · 2026-05-17 · via Forbes - CIO Network
Dad and son outdoors

Dad and son having fun outdoors.

getty

Health systems must deliver safe patient care for 30 days or longer without core technology systems. This is no longer a regulatory goal but the minimum operational standard for cyber resilience in healthcare. Most health system CIOs have not planned for this. The Joint Commission and the American Hospital Association started the Cyber Resilience Readiness (CRR) program to help hospitals assess and improve their ability to sustain clinical operations during extended cyber outages.

Cybersecurity is already expensive, with the average healthcare data breach costing $7.42 million. Greater costs come from daily downtime, lost revenue from manual charge capture and billing, and patients unable to access care and treatment.

The CRR program begins with a free self-assessment tool. It asks if your organization can provide safe care if technology fails. The survey covers many areas, but four themes are the top priority for a healthcare CIO.

Cyber Resilience Is Clinical Operations

The assessment highlights a key issue: clinical, business, emergency management, and disaster recovery are often siloed rather than integrated. Typically, IT manages application recovery, emergency management leads incident response, and clinical leadership oversees patient safety. These groups rarely collaborate before a crisis, resulting in last-minute coordination. CIOs should unite these departments proactively to ensure readiness.

The Board Must Be Involved

The CRR assessment asks how often leaders brief the board on cybersecurity and its impacts on patient care. It also asks whether boards distinguish clinical from business continuity. These topics are related but not the same. A CIO who links cyber risk to patient safety, revenue, and regulation will benefit the board.

Downtime Plans Must Work Operationally

The assessment's key takeaway is that downtime plans must be tested realistically across all shifts and service lines—not just annually, and not only in a conference room. Effective testing means running scenarios that stretch 30 days or more. Senior leaders must observe the exercises and act on findings. If drill results are ignored, the effort is wasted. Hospitals that survive cybersecurity events do so because staff have instinctive responses built through repeated, realistic practice.

Inventory Visibility Is Crucial.

Healthcare organizations must keep inventories of all biomedical devices, IoT systems, imaging devices, building controls, software, and anything on the network. They must map all assets to clinical risk. Hospitals have decades of connected technology, but no one department fully owns it all. The CIO must integrate asset visibility, data classification, vendor risk, and business continuity into one model. This includes medical equipment and other hardware on the network that are outside IT control.

The self-assessment does not score your organization; it identifies gaps for action. CIOs must decide who to brief, what to fix, and how fast to act—these choices differentiate compliance from resilience.

What’s Next For CIOs

The CRR program and assessment are a starting point. How a CIO uses its findings determines if it becomes a real advantage. Healthcare CIOs must build business continuity plans that last weeks, not just hours or days. They should run tabletop exercises for manual operations on days 3, 10, and 30.

CIOs should focus on a disaster recovery MVP that requires only the critical systems to keep operations running in a crisis. Full backups can be complex and costly. An MVP focuses on speed, simplicity, and effectiveness. The goal is fast recovery to a minimal but safe level.

Combining the CRR assessment with an MVP program is essential. Healthcare leaders must act now: assess resilience, make key improvements, and ensure teams can provide patient care for 30 days or more under any circumstances. The healthcare CIO can lead this challenge.