Express Healthcare

The Cybersecurity Imperative

As healthcare becomes more connected and data-driven, cybersecurity is emerging as a strategic investment for hospitals. Rising cyber threats, expanding digital infrastructure and growing regulatory expectations are prompting healthcare organisations to strengthen their cyber defences 

0 0

Walk into any hospital today and you will find a very different building from the one that stood there a decade ago. Patient records live on screens instead of paper files. Diagnosis happens with the help of AI tools. Infusion pumps and monitors talk to the network. Doctors consult patients over video calls from another city. All of this has made care faster, more accurate and more accessible. But it has also opened many new doors, and hospitals across India are now investing in cybersecurity like never before to make sure those doors stay shut to the wrong people.

It is crucial to understand what is fuelling this spend, where the money should go, and what still needs fixing.

Why the spend is going up

The simplest explanation is that hospitals have far more to protect than they did a few years ago. 

Independent data backs this up. IBM’s 2025 Cost of a Data Breach Report found healthcare to be the costliest sector to breach of any industry, a title it has now held for well over a decade, with the average incident taking close to 279 days to even detect. That combination of high cost and slow detection is exactly what is pushing budgets upward.

Bipin Kumar Chaudhary, CIO, Fortis Healthcare, points out that “ransomware attacks on healthcare institutions, growing regulatory expectations around data privacy, and the critical need to ensure uninterrupted patient care are prompting organisations to make cybersecurity a board-level priority.” As he puts it, “Investments are increasingly being driven by the need for resilience rather than compliance alone.”

That word, resilience, comes up again and again in this conversation, and it points to a deeper change in how attacks are actually unfolding.

Rajnish Gupta, Managing Director, Tenable India, believes the risk itself has changed in nature. “Attack sophistication is the single biggest driver of cybersecurity investments in healthcare, and AI is steering this shift,” he says.

What makes healthcare different from any other sector, he adds, is this, “The stakes are higher in the healthcare sector, since it involves human lives. A disrupted radiology system can delay a diagnosis. A manipulated lab result can change a treatment decision.”

It is this human dimension, patient safety rather than data alone, that keeps surfacing as the real reason boards are paying attention.

Anirban Mukherji, Founder and CEO, miniOrange, agrees that the human cost is what has changed the conversation in boardrooms. “A ransomware attack on a hospital doesn’t just impact data- it can disrupt patient care and clinical operations,” he says.

And the scale of exposure only grows as more devices join the hospital network. Vipin Varma, SVP-Cybersecurity, CitiusTech, brings a number to the table that puts the scale of the challenge in perspective: “A modern intensive care unit (ICU) bed can have 35–40 network-connected medical devices.”

When every one of those devices is a potential entry point, the case for higher investment writes itself.

Jivitesh Bansal, VP-Engineering, PB Health, sums up the everyday stakes for clinical teams. “A cyberattack can stall a clinical workflow mid-treatment, push back a surgery, or knock a hospital’s systems offline when a patient needs care right now,” he says.

Taken together, these views point to one conclusion: healthcare’s cybersecurity spend is rising because the sector’s risk profile has changed faster than its defences have, and hospitals are now racing to catch up.

Where the money should go first

With budgets growing, the next question every hospital is asking is where to spend first. Most experts agree that the basics deserve first claim on the budget, not the newest tool in the market.

This is where hospital and vendor leaders converge almost entirely, even though they are speaking from different chairs.

Surjeet Thakur, Founder and CEO, TrioTree Technologies, keeps it simple: hospitals should focus on “identity and access management, multi-factor authentication, endpoint protection, secure data backup, security monitoring, and vulnerability assessments. These areas should form the core of every cybersecurity budget.”

Speaking from inside a hospital rather than a vendor’s boardroom, Chaudhary takes a similar view on where to start. “Hospitals should focus on strengthening their foundational cybersecurity capabilities before investing in niche solutions. Priority areas include identity and access management, endpoint detection and response, security monitoring, vulnerability management, data protection and cyber recovery.”

Beyond the fundamentals, one area keeps getting overlooked: what happens after an attack has already happened.

Praveer Kochhar, CPO and Co-Founder, KOGO AI, brings the conversation to a subject hospitals often overlook until it is too late: recovery. “The real cost of an attack on a hospital isn’t just the breach, it’s the hours of clinical downtime while systems are rebuilt. Most hospitals also fall for what we call the backup mirage: “backup successful” shows up green on a dashboard, but that’s not the same as restorable under fire. Nobody finds out the difference until they’re mid-incident and the restore fails. A hospital that hasn’t rehearsed its recovery is betting patient care on a document it’s never opened under pressure.”

With AI now sitting inside clinical and administrative workflows, a newer line item is also demanding budget of its own.

For Varma, the newest priority on the list is AI itself. “The first priority should be AI security. As hospitals increasingly adopt AI to improve operational efficiency, clinical decision-making, and administrative workflows, organisations must ensure that AI applications are developed, deployed, and governed securely.” 

Bansal puts it just as plainly: “Hospitals have to prioritise core cybersecurity fundamentals over shiny new tools.” 

The pattern across all five views is hard to miss: get identity, backup and recovery right before chasing anything more advanced.

How AI, cloud and connected devices are changing the game

Every expert agreed that AI, cloud computing and connected medical devices have changed what cybersecurity means in a hospital setting, and not always for the simple reason of adding new tools to defend.

The interesting part is that the same technologies reshaping patient care are also reshaping the threat itself, on both sides of the fight.

Sachhin Gajjaer, Founder and CEO, Sattrix describes it as a battle being fought with the same weapons on both sides. “AI is a double-edged force: attackers now use it to craft convincing phishing, deepfakes, and fastermutating malware, while defenders lean on it for anomaly detection and automated response,” he says, summing up the moment with a line of his own: “AI to AI is the new cyber mantra for any critical and sensitive organisation.”

That double-edged nature is not just about tools attacking tools. It is also changing the basic question a security team has to ask.

Kochhar frames the shift in a different way. Where security teams once asked whether a system could be hacked, they must now ask something new. “The security question changes from ‘can someone read this data’ to ‘can someone get an autonomous system to act on their behalf,'” he says.

Part of what makes this harder to govern is how quickly AI tools are now being built and adopted inside hospitals, often outside the IT department’s usual purview.

Varma also sees AI reshaping the job of the security team from the ground up, since “AI application development has become significantly faster and less expensive, enabling business users and citizen developers to build AI agents and applications within days using low-code or no-code platforms and vibe coding.”

For clinical staff on the ground, though, the shift is felt in much simpler terms.

Dr Ashish Chandra, Chief Operating Officer, ISIC Multispeciality Hospital, sums up the everyday reality for clinical teams well. “AI can help identify unusual activity and detect threats faster, but cybercriminals can also use AI to create more advanced attacks,” he says, adding that hospitals now “need a security approach that protects not just computers and networks, but the entire digital healthcare ecosystem.”

The gaps that remain, even with higher spending

Bigger budgets do not automatically mean fewer weak spots, and every expert flagged at least one gap that money alone cannot close. This is perhaps the most important message for hospital leadership, since it means the size of the cheque is not, by itself, the answer.

Gupta believes the mismatch between spend and outcome comes down to pace. “The strategies aren’t keeping pace with the technological change,” he says, pointing out that “every new piece of connected equipment a hospital brings in creates a new blind spot that most traditional tools weren’t built to see.”

That pace problem shows up most starkly in how long a breach can go unnoticed.

Gajjaer’s list of gaps includes an uncomfortable but familiar one: response time. “The sector still averages 8+ months to identify a breach,” he notes, and many hospitals “have bought tools but lack the 24/7 monitoring, tuned alerting, and trained analysts to act on them.”

Not every gap is technical, though. Some of it comes down to how cybersecurity is treated inside the organisation.

Mukherji points to a gap in mindset rather than technology. “Many organisations continue to view cybersecurity as a technology problem rather than an organisational responsibility,” he says. “Security must be integrated into governance, operations, procurement and clinical workflows.”

A newer and quieter version of that same mindset gap has arrived with AI itself.

Varma highlights a newer and quieter risk that has crept in alongside AI adoption. “Individual clinicians, administrators, and business users are increasingly deploying AI tools independently, often without centralised oversight,” he says. As he warns, “Even seemingly simple tools such as AI-powered transcription services may transmit protected healthcare information to external platforms” if left ungoverned.

On the regulatory side, awareness itself is a gap. Gupta also flags a compliance blind spot that hasn’t had the same attention as the technical one. “Familiarity with the DPDP Act and its newly notified Rules sits only at roughly 28 per cent among Indian healthcare organisations,” he says. “DPDP isn’t just about avoiding penalties; it’s about handling patient data with the care it actually demands.”

And underneath every one of these gaps sits a much more basic problem.

Bansal points to something more basic than any tool: visibility. “You can’t secure what you don’t know you have, and this is one of those unglamorous problems that doesn’t get the attention it deserves until something goes wrong,” he says.

What smaller hospitals can do with a smaller budget

Not every hospital has a large IT team or a large security budget, and the good news from every expert is that strong cybersecurity does not have to cost a fortune.

This is arguably the most reassuring theme to come out of this conversation, since it means smaller hospitals are not locked out of good security simply because they cannot match a large network’s spend.

“Cybersecurity does not require higher expenditure; what is important is that appropriate measures are taken,” says Thakur, who recommends that mid-size hospitals start with “multi-factor authentication, data backup, endpoint protection, software updates, and educational programmes for employees.”

A hospital administrator hears this slightly differently, but arrives at the same starting point. Dr Chandra echoes the same idea from a hospital administrator’s chair. “Smaller hospitals do not necessarily need expensive technology to improve cybersecurity,” he says. “They should first identify their most critical systems and protect them with basic measures such as strong passwords, multi-factor authentication, regular data backups and timely software updates.”

Before spending anything at all, though, clarity on what actually needs protecting comes first.

Mukherji suggests starting with clarity rather than a shopping list. “Smaller hospitals don’t necessarily need the largest budgets- they need the right priorities,” he says, recommending “a realistic risk assessment to identify the systems and data that are most critical to patient care” as the first step.

Once priorities are clear, smaller hospitals also have a shortcut available that larger networks often build in-house. Gajjaer points to outside help as a smart shortcut for smaller teams. “Mid-sized and smaller hospitals get the most protection per dollar by focusing on fundamentals rather than expensive tooling,” he says, and can lean on “managed detection and-response and co-managed SOC & compliance providers” to get round-the-clock coverage without building a large team from scratch.

None of this, however, should be mistaken for smaller hospitals facing a smaller threat.

Kochhar reminds smaller hospitals not to underestimate the threat they face. “Smaller hospitals do not mean they will only face smaller attacks,” he says, even if their budgets will naturally look different from a large hospital network’s.

Bansal points out that strong security does not have to mean a large spend. “The good news is that some of the highest-impact measures aren’t expensive: multi-factor authentication, backups that get tested regularly (not just scheduled and forgotten), patching internet-facing systems promptly, and basic staff awareness training,” he says.

What the next three to five years look like

Every expert sees cybersecurity moving from an IT line item to a permanent part of how hospitals plan and grow, and the outlook, despite the challenges, is a positive one.

What stands out is how similar the direction of travel sounds, whether the view comes from inside a hospital or from a security vendor.

Chaudhary sees this shift already underway. As he puts it, “cybersecurity is evolving from a technology requirement to a patient safety and business resilience imperative,” and he expects hospitals to invest more in “AI-driven threat detection, Zero Trust architectures, cloud security, medical device security and automated cyber recovery capabilities.”

Regulation is expected to keep pushing in the same direction. Thakur expects regulation and scale to work together to keep budgets climbing. In his words, “investments in the area of cybersecurity in healthcare will become an integral element of the digital health planning process in India instead of being simply another IT expense that organisations incur.”

Dr Chandra agrees the mindset will shift from a compliance checkbox to something more central, saying “cybersecurity spending in healthcare is likely to become a core part of strategic and operational planning rather than a separate IT expense.”

Some go further still, predicting that the very idea of cybersecurity as a separate function will start to fade. 

Bansal takes the long view. “My sense is that cybersecurity stops being a ‘function’ over the next few years and just becomes part of how healthcare technology is built, full stop,” he says, expecting more investment to flow into “AI-powered threat detection, zero trust architectures, identity-centric security, and automated response.” 

And as AI itself becomes part of the hospital’s everyday toolkit, securing it is expected to become a budget line of its own.

Varma offers a striking way to think about where budgets are headed. “An increasingly common observation is that the cost of securing an AI application can exceed the cost of building it,” he says, expecting cybersecurity’s share of the technology budget to keep climbing over the next few years.

And Kochhar leaves hospitals with a simple choice to make now rather than later. “The hospitals that make this shift will stop finding out about their weak points during an actual incident,” he says.

The bottom line

The message from every corner of the industry is remarkably consistent. Digitisation has made healthcare better for patients, and it has also made cybersecurity a permanent part of running a hospital, not a onetime project. The hospitals that treat it as a shared responsibility across technology, people and leadership, and that build in resilience rather than chase compliance alone, are the ones best placed to keep patient care running no matter what comes their way. For an industry built around protecting life, protecting the systems that make modern care possible is simply the next natural step.



[email protected]
[email protected] 

 

- Advertisement -

Leave A Reply

Your email address will not be published.