AI is helping attackers find and exploit weak spots faster. Itโ€™s also giving HTM and security teams new ways to strengthen their defenses.


By Skip Sorrels, Field CTO and CISO at Claroty

Artificial intelligence (AI) is changing cybersecurity at a pace healthcare organizations have never experienced. For healthcare technology management (HTM) professionals, the stakes are especially high because the systems they protect are not just computers. They are infusion pumps, imaging systems, patient monitors, laboratory equipment, and other connected medical devices that directly support patient care.

The White Houseโ€™s Executive Order on AI and security recognizes this reality. The order specifically calls for facilitating access to cybersecurity tools and services, including advanced AI capabilities where appropriate, for critical infrastructure operators such as rural hospitals. AI is also creating an imbalance between attackers and defenders. Attackers can use increasingly sophisticated AI capabilities to accelerate vulnerability discovery, automate reconnaissance, and compress the time between finding a weakness and attempting to exploit it. Defenders, meanwhile, are still often working with fragmented asset inventories, legacy systems, and manual processes.

For medical device cybersecurity, that imbalance creates a difficult question: How can HTM and security teams use AI to move faster without sacrificing the operational context and precision required to protect patient care?

AI Is Speeding Up Cyberattacks

Healthcare organizations have spent years improving the security of traditional IT environments. As those environments become more difficult to penetrate, attackers are increasingly looking for opportunities in the cyber-physical systems that support patient care.

Medical devices are an attractive target because they are often connected to broader hospital networks but operate under constraints that traditional IT endpoints do not. Many run legacy operating systems, cannot be patched immediately without disrupting care, and cannot support conventional endpoint security agents. That makes a compromised medical device fundamentally different from a compromised laptop. An attacker who gains access to an employee endpoint may be looking for data or credentials. An attacker who reaches a clinical device can potentially disrupt the systems clinicians depend on to deliver care.

AI gives attackers new ways to identify weaknesses and act faster. Frontier AI is compressing the time between vulnerability discovery and exploitation, changing the defensive timeline for critical infrastructure. HTM teams therefore cannot afford to think about cybersecurity as a periodic assessment. Medical device security increasingly requires continuous visibility into devices, vulnerabilities, and emerging threats.

AI Can Also Give Defenders an Advantage

AI can also help defenders make sense of medical device environments that have historically been difficult to manage manually. The first requirement is visibility. You cannot protect what you do not know exists. Yet maintaining an accurate inventory of connected medical devices has historically been difficult. Clinical engineering and security teams may maintain separate records, while devices are constantly being moved, replaced, upgraded, or connected to new systems. AI can help shift this process from reactive inventory management toward continuous asset visibility.

Instead of simply identifying that a device exists, AI-driven security capabilities can help security and HTM teams understand what the device is, how it communicates, what software or firmware it is running, what it should be communicating with and how its current state compares with its expected behavior. That context matters because not every vulnerability deserves the same response. A vulnerability on a device sitting in a nonclinical environment is not necessarily equivalent to the same vulnerability affecting an infusion pump supporting active patient care.

Traditional vulnerability management can leave teams with enormous lists of technical findings. HTM professionals need to know which exposures create the greatest operational and patient-safety risk. AI can help accelerate that analysis by bringing together asset identity, vulnerability information, network behavior, and clinical context so teams can prioritize the exposures that pose the greatest risk.

For HTM teams, this creates an opportunity to โ€œshift left.โ€ AI can handle more of the work involved in collecting, correlating, and prioritizing information, allowing HTM professionals to focus on decisions that require their expertise. HTM and security professionals need to remain in the loop when AI is used to assess risk or inform action, particularly when decisions could affect clinical operations or patient care.

AI Doesnโ€™t Eliminate the Need for Medical Device Context

This is where healthcare differs from traditional enterprise cybersecurity. A security team cannot simply identify a vulnerable medical device and immediately take it offline or deploy a software agent. The device may be actively supporting a patient. A patch may require manufacturer validation. A configuration change could affect clinical workflows. AI can automate some of the work behind cybersecurity decisions, but HTM and security professionals still need to determine what action is appropriate.

HTM and security teams still need to understand the operational role of each device, its lifecycle, its dependencies, and the potential impact of taking action. This is particularly important as medical device manufacturers increasingly adopt stronger encryption. Encryption is essential for protecting sensitive healthcare information, but it creates a new visibility challenge. As medical device communications become more heavily encrypted, traditional passive monitoring techniques can lose access to important context, including device identity, software versions, and configuration information. The challenge is maintaining that visibility without compromising encryption or security.

Secure interoperability and standardized mechanisms for exchanging device context can help clinical engineering and security teams maintain an accurate picture of their medical device environments even as network traffic becomes increasingly opaque. That will become more important as healthcare organizations pursue both stronger privacy protections and more sophisticated cybersecurity.

Lifecycle Management Has to Become Cybersecurity Management

HTM teams also need to consider cybersecurity across the medical device lifecycle. Cybersecurity cannot be something added after procurement or addressed only when a vulnerability becomes headline news. Security needs to be considered throughout the lifecycle, from acquisition and deployment to maintenance, replacement, and retirement.

Teams first need comprehensive asset visibility. They need to know what devices they have, where those devices are located, what software they are running, and how they fit into clinical workflows.

They also need to manage exposures based on actual risk. Rather than treating every vulnerability as an equal emergency, organizations need to assess vulnerabilities based on the likelihood of exploitation, the characteristics of the device, and the operational consequences of compromise.

HTM and security teams need to work together. Clinical engineers understand how devices function and how they fit into patient care. Security teams understand threats, vulnerabilities, and attack paths. Neither team can fully secure connected medical devices in isolation.

What AI Means for HTM

The White Houseโ€™s recognition of rural hospitals in its AI cybersecurity strategy highlights the resource constraints many healthcare organizations face. Organizations with the fewest resources are often managing some of the most consequential technology. AI could help resource-constrained organizations manage that technology more effectively, but its use has to account for the clinical environments in which these devices operate.

AI can provide HTM professionals with better visibility and context while reducing the time spent collecting and analyzing information. Decisions that affect clinical operations and patient care still require human judgment.

Attackers can use AI to find and exploit weaknesses faster, while defenders can use it to understand increasingly complex medical device environments. Using AI effectively will depend on a strong foundation of asset visibility, exposure management, and operational context.

HTM teams need to continuously assess medical device cybersecurity rather than relying on periodic inventories or annual vulnerability reviews. As AI is accelerating both the threat and the defense, HTM teams will need to adapt how they identify and manage risk while keeping patient care at the center of those decisions.

IDย 286356186ย |ย Aiย ยฉย Nattapon Kongbunmeeย |ย Dreamstime.com