The ARPA-H-funded research explores how AI and large-scale simulation could help hospitals prioritize cybersecurity remediation while maintaining continuity of care.


By Alyx Arnett

Siemens Healthineers is taking aim at a familiar problem for hospital cybersecurity teams: how to address vulnerabilities in medical equipment without disrupting the clinical operations that depend on it. The company is researching whether artificial intelligence (AI) and large-scale simulation could help hospitals determine which vulnerabilities to address, when to address them, and what effect those decisions could have on patient care.

The company recently received a $6.9 million Phase I research project contract from the Advanced Research Projects Agency for Health (ARPA-H) to lead the Secure Healthcare Infrastructure Enhancement and Defense, or SHIELD, project. The effort is part of ARPA-H’s Universal Patching and Remediation for Autonomous Defense (UPGRADE) program.

Working with industry and hospital partners, the SHIELD team plans to study how hospitals can better prioritize and time cybersecurity remediation while accounting for the effects on equipment availability, clinical operations, and continuity of care. The research will use AI and exascale simulation to model interactions among medical devices, hospital operations, patients, and clinical staff.

24×7 spoke with Dorin Comaniciu, senior vice president of AI and digital innovation at Siemens Healthineers, about the problem SHIELD is designed to address, what the team plans to develop, and what the research could mean for hospitals and the HTM professionals responsible for connected medical equipment.

What problem did you see in hospitals that convinced you this research was needed?

What we saw was that hospitals often know vulnerabilities exist, but determining what to fix first and how to do it without disrupting patient care is incredibly difficult. These decisions often span IT, HTM, and others, with each department working from different information and priorities. 

Those silos slow down coordination and can leave critical vulnerabilities unresolved for months, even when the risk and fix are known. SHIELD helps bring that information together through a single pane of glass so healthcare organizations can understand the operational and clinical impact of remediation decisions, reduce cyber risk, and keep clinical care running smoothly.

What do you hope will exist at the end of the research?

At the end of the research, we hope hospitals will have a practical platform that can identify vulnerabilities, model the impact of remediation options on patient care and operations, and guide organizations toward the safest path to reduce risk. This decision-support capability would reduce remediation timelines, improve cyber resilience, and help protect patient care while addressing cybersecurity risks.

The project calls for an autonomous cyberthreat solution. What do you envision that system being able to do?

The goal is to give hospitals the information and confidence they need to make faster, better decisions. Over time, more of the analysis, testing, and remediation planning can be automated, while hospital leaders remain in control of whether and how changes are deployed. In simple terms, we want hospitals to move from reactive to proactive by understanding risk and acting before patient care is affected.

How are the hospital partners shaping what you’re developing?

Our hospital partners are essential because they provide real-world insight into how clinical workflows, staffing constraints, maintenance processes, and patient care requirements influence cybersecurity decisions in practice. What we’re learning is that cybersecurity decisions in hospitals are rarely just technical decisions. Every remediation can have downstream impacts on clinical operations, equipment availability, and patient care. By working directly with hospitals, we can better understand those tradeoffs so SHIELD will work in actual hospital environments.

What are the major hurdles to moving from today’s largely manual processes toward autonomous remediation?

The biggest challenge is the complexity of hospital environments. Hospitals may have thousands of connected devices from different vendors, legacy systems, and limited visibility into how those systems interact. Creating accurate digital representations of those environments and reliably predicting the effect of a remediation at scale is difficult on its own. 

On top of that, hospitals must balance cybersecurity, system uptime, staffing constraints, clinical priorities, and patient safety every time they consider a change. SHIELD is focused on building an accurate operational twin of a hospital’s clinical and IT operations, bringing all of this information together and leveraging the power of AI and exascale simulations to help organizations understand those tradeoffs in seconds so they can make faster, more informed decisions with confidence.

How will you determine whether SHIELD has been successful? 

Success means helping hospitals make better remediation decisions faster and with greater confidence. A key milestone is significantly reducing the time from vulnerability identification to remediation down from the current baseline of over a year, while minimizing disruption to patient care. Just as important is demonstrating that hospitals can use the platform to balance cybersecurity risk, operational requirements, and patient safety more effectively than they can today.

What could the research ultimately mean for hospitals and the HTM professionals responsible for maintaining connected medical equipment?

Hospitals will be able to make cybersecurity decisions in the context of patient care rather than in isolation. Today, vulnerability management is often driven by technical information alone, but hospitals have to consider how those decisions affect clinical workflows, equipment availability, staffing, and operations. 

SHIELD aims to provide that broader context, helping HTM professionals, cybersecurity teams, and hospital leaders understand not only where risk exists, but also the likely impact of different remediation choices. The result would be more informed decisions, faster remediation, and a stronger ability to reduce cyber risk while maintaining continuity of care.

What happens after Phase I? 

The longer-term vision is much bigger than helping a single hospital decide how to remediate a vulnerability. We envision a future where healthcare organizations can model how care is delivered across an entire region and understand how cyber events, equipment outages, or remediation decisions ripple through the broader healthcare ecosystem. If a critical system becomes unavailable at one hospital, what happens to patient flow, emergency services, specialty care, and neighboring facilities? How does a decision in one part of the system affect capacity and care delivery elsewhere? 

The opportunity is to create a predictive environment that helps healthcare leaders understand those interdependencies, test scenarios before they occur, and make decisions that optimize resilience across the healthcare system as a whole by utilizing AI at scale.

Photo credit: Siemens Healthineers