Where Compliance Falls Short: Taking a Proactive Approach to Risk in the Healthcare Industry

Changes to our digital spaces in recent years have led to an increase in IT risk—especially in the healthcare space. With more digitization comes an increased number of risks. Nearly 85% of healthcare data breaches reported to the HHS Office for Civil Rights (OCR) in 2022 were attributed to hacking and IT incidents, according to data from the HHS. With more determined threat actors wanting to exploit patient data, a proactive approach to seeing, understanding and acting on risk is vital to improving the effectiveness of security.

Most organizations think that compliance is the first step to protecting it, but this approach leaves healthcare institutions out of touch when it comes to the threat landscape. Information security leaders and chief information security officers (CISOs) at healthcare facilities need to get in front of the constantly evolving cyber threats that loom over not only their business, but their patient and client data too. Understanding where compliance falls short is vital to creating an agile and responsive risk management program that connects back to business strategy.

The Difference Between a Compliance-Based and Risk-Based Approach
While compliance and risk are two sides of the same coin, they are focused on different issues. Compliance is based on a framework of statutory, regulatory or contractual requirements that are either met or unmet. Risk is focused around managing uncertainty with processes designed to achieve positive business outcomes.

Compliance and risk management programs both help healthcare organizations maintain stability and integrity on multiple levels, which prevent risks to the organization’s legal liability, financial position, reputation and physical assets. Compliance is more prescriptive and results in a more tactical, check-the-box approach. Risk management is predictive, anticipating risks, and requires a strategic approach. While compliance is still the typical starting point in protecting an organization (often due to the fines and regulatory actions associated with noncompliance), focusing exclusively on compliance can leave businesses short-sighted and exposed to unseen risk.

Because the main focus of risk is managing uncertainty, it has specific processes designed to achieve positive business outcomes. This is especially relevant to healthcare. Cyberthreats have become a constant, and with threat actors greater in number and working more creatively to breach organizations, having a proactive approach to risk can make healthcare facilities more adaptable. Risk is measured on a continuum, and whether a risk is acceptable will vary depending on an organization’s risk appetite. Understanding where compliance falls short, and the need to shift from a compliance-based to risk-based approach is vital—and looking at how uncertainty is managed is a crucial step.

Why Traditional Compliance Can Be Inefficient
Compliance audits are point-in-time assessments that appraise the controls already implemented by the organization. The downfall of these assessments is that they don’t focus on how well the organization is protected in real time. When manual processes are involved, it takes too long to start an audit or assess a threat landscape. Oftentimes, by the time an assessment is complete, the data is outdated because of an infrastructure change, regulatory update or new vulnerabilities. A compliance-first approach is no longer adequate to reduce risk and ensure that patient data is secure.

According to the College of Healthcare Information Management Executives’ (CHIME) Digital Health Most Wired Survey, 40% of healthcare organizations still don’t have a dedicated CISO, down 12% from 2021. For those organizations without a CISO, they rely too often on managers and other employees to be vigilant regarding phishing attempts, HIPAA breaches and other compliance threats and violations. Healthcare leaders need to recognize that this kind of compliance isn’t forward-looking and can lead to significant gaps in security. To support this, budgets are growing for a risk-first approach, citing risk management as a business priority almost twice as often as compliance. Security leaders understand that compliance with rules and regulations rarely translates into value-generating business propositions without the addition of a long-range risk management strategy. Compliance often leads to some risk avoidance, but risk management can help healthcare facilities proactively navigate risk, especially in this demanding regulatory environment.

The Value of a Modern Risk-Management Solution
Selecting the right risk management approach is not a one-size-fits-all solution. Within the healthcare industry, businesses may need to focus on different aspects of patient data and security. With a modern risk management program, healthcare organizations can gain high-level insight into their compliance and risk postures and gain visibility into how compliance activities reduce both IT and cyber risk. Not only will this provide deeper insights into risk and compliance, but it will allow healthcare organizations to break down silos, eliminate gaps and reduce any potential or current blind spots. Healthcare organizations should also seek out solutions that report on risk in the context of specific business objectives—helping the C-suite and board understand its value to strategy.

A risk-management program can also include automating tasks associated with risk calculation, giving managers automatic alerts when risk increases. Not only will this reduce any manual errors associated with calculating risk—after all, according to a study by IBM, human error is the main cause of 95% of cyber security breaches—but it will also increase accuracy with automated, cross-object risk scoring. When making this change, it is essential to communicate the new value of risk management so that healthcare leaders can better understand it. This will help show them exactly where and how their investment into risk programs is making the most significant impact—while simultaneously freeing additional time to focus on other valuable hospital-wide objectives.

Cybersecurity leaders in healthcare can deliver better outcomes with less effort by transitioning from a compliance-centric approach to a risk-centric one. Putting cyber risk into business context by using a risk-centric approach allows healthcare CISOs and CIOs to connect risk to the business objectives prioritized by the C-suite and board. With visibility into the organization’s overall risk posture, leaders will have an accurate and relevant view into how their actions and investments are impacting business success.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Busy South Africa Building Integrates Custom Access Control System

    Nicol Corner, based in Bedfordview, Johannesburg, South Africa, is home to a six-star fitness club, prime office space, and an award-winning rooftop restaurant. This is the first building in South Africa to have its glass façade fully incorporate fritted glazing, saving 35% on energy consumption. Nicol Corner (Pty) LTD has developed a landmark with sophisticated design and unique architecture by collaborating with industry-leading partners and specifying world-class equipment throughout the project. This includes installing a high-spec, bespoke security and access control system. Read Now

  • Only 13 Percent of Research Institutions Are Prepared for AI

    A new survey commissioned by SHI International and Dell Technologies underscores the transformative potential of artificial intelligence (AI) while exposing significant gaps in preparedness at many research institutions. Read Now

  • Survey: 70 Percent of Organizations Have Established Dedicated SaaS Security Teams

    Seventy percent of organizations have prioritized investment in SaaS security, establishing dedicated SaaS security teams, despite economic uncertainty and workforce reductions. This was a key finding in the fourth Annual SaaS Security Survey Report: 2025 CISO Plans and Priorities released today by the Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

Featured Cybersecurity

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3