- Passing audits doesn't mean a hospital can contain an active attack, compliance measures documentation, not resilience.
- OT systems (HVAC, lab automation, imaging, infusion pumps) are often unmonitorable and rarely appear in audit frameworks.
- Vendor network access, once embedded in clinical workflows, becomes practically impossible to restrict.
- Zero Trust helps by limiting blast radius: identity-based access, time-limited vendor sessions, OT/IT segmentation.
Summary
On paper, hospital cybersecurity's vitals look stable. Policies documented. Audits passed. Dashboards green.
But structural exposure persists. Large parts of the hospital environment remain invisible: OT systems, vendor connections, legacy infrastructure. Audits measure compliance. They do not measure resilience.
This blog captures what was said in a closed roundtable with hospital CISOs, IT leaders, and auditors, and what it means for anyone responsible for keeping a hospital running under attack.
The Systems Nobody Is Watching
Ask a hospital CISO what they're protecting and they'll describe the obvious: laptops, servers, cloud infrastructure, patient data.
Ask them what worries them most, and the answer shifts. HVAC controllers. Lab automation systems. Imaging workstations running operating systems that predate modern security. Infusion pumps connected to the same network as everything else.
These systems keep patients alive. They also cannot be patched, cannot run endpoint agents, and in many cases produce no logs that anyone is actively reviewing.
In most hospitals, they do not have full visibility into the OT environment. Not because they haven't tried, but because these systems were built to last thirty years, not to be monitored, segmented, and continuously verified.
And because OT rarely appears prominently in audit frameworks, the blind spot is never formally surfaced. It just persists.
The Access Nobody Can Revoke
Medical device vendors require network access to support and maintain their equipment. That's legitimate. What's less comfortable is what happens next.
Once the contract is signed, once the system is embedded in clinical workflows, the hospital's ability to restrict that access effectively disappears.
The cycle repeats across institutions:
- Attempt to limit vendor access
- Face resistance
- Receive a warning that uptime cannot be guaranteed if access is restricted
In a hospital, "uptime cannot be guaranteed" is not a negotiating position. It's a clinical threat.
So the access stays. Broader than it should be. Persistent when it should be time-limited. Connected to systems it does not need to reach.
This is not a failure of your SOC. It's a procurement problem that became a security problem, and it happened before your security team had any say in it.
Audit ≠ Resilience
Here's what an audit confirms: that your controls are documented, your roles are defined, your governance structure exists on paper.
Here's what an audit does not confirm: whether you can contain ransomware spreading through your OT environment at 2am on a Saturday.
Compliance measures documentation. Resilience measures survival. They are not the same standard. Treating them as equivalent is one of the most expensive mistakes in healthcare security.
Want more on Zero Trust, MDR, and managed cybersecurity?
Whitepapers, datasheets, infographics, and the Zero Trust Dictionary, all in one library.
Why Availability Changes Every Decision You Make
In most industries, the CIA triad starts with confidentiality. In healthcare, it starts with availability, and everything else follows from that.
When lab systems go offline, surgeries are postponed. When imaging fails, clinicians work without diagnostic support. When environmental controls malfunction, operating theaters close.
Downtime in a hospital is not a financial inconvenience. It is delayed care. In the worst cases, it is harm.
Every security decision gets made in that context. Patch windows compress. Vendor access stays broad. Segmentation is implemented cautiously.
Each decision is defensible in isolation. Together, they create an exposure profile that does not appear in any quarterly security report, until something forces it to.
The Question Your Board Isn't Asking, But Should Be
"Are we compliant?" is the wrong question. The right question is: if we're under active attack right now, how far can they go?
- How many systems can an attacker reach from a single compromised vendor credential?
- How quickly can you isolate OT from IT if something starts spreading?
- How long before you even know it's happening?
Legacy systems are not going away. Vendor dependencies are not going away. Audits will continue to be passed. So the issue is not perfection. It's containment.
Where Zero Trust Actually Matters
Zero Trust is useful as a discipline for one specific problem: limiting how far disruption travels.
Not eliminating risk. Not replacing legacy systems overnight. Not solving the vendor dependency problem in a single procurement cycle.
But: who can reach what, under what conditions, for how long, and can you answer that question for every system in the building?
In a hospital, the difference between a contained incident and a care-disrupting crisis often comes down to blast radius. Zero Trust is the methodology for making that radius smaller.
FAQ
Why does hospital cybersecurity fail despite passing audits?
Audits measure documentation and governance, not operational resilience. Hospitals can be compliant and still unable to contain an active attack in their OT environment.
What is OT security in healthcare?
OT includes HVAC systems, lab automation, imaging devices, infusion pumps, and building management. These systems support patient care directly, are often unmonitorable, and create visibility gaps.
Why is vendor access such a persistent security problem?
Medical device vendors require network access as a contractual condition. Once clinical systems depend on that access, restricting it becomes a clinical risk decision, baked into procurement before security teams are involved.
What does "Audit ≠ Resilience" mean?
You can satisfy every compliance requirement and still be unable to contain ransomware spreading through your environment. Audits verify documentation. Resilience is measured by damage containment.
How does Zero Trust help hospitals without disrupting care?
By focusing on blast radius reduction: identity-based access controls, time-limited vendor sessions, OT/IT segmentation, and governance that treats implicit trust as risk. The goal is limiting the scope of compromise.