Growing reliance on vendors, remote access, and connected technologies is expanding healthcare’s cyber risk and putting greater emphasis on third-party oversight and continuity planning.
By William Hale, senior director of vCISO services at Magna5
Healthcare organizations are learning that a cyberattack does not have to begin inside their own network to affect patient care. In 2026, when third-party vendors CareCloud and Unlimited Technology Systems suffered cyberattacks, the damage went far beyond their own systems. Ultimately, these breaches exposed the sensitive health information of more than 7.5 million individuals, according to the US Department of Health and Human Services.
Those incidents illustrate a larger problem: healthcare organizations rely on a number of external vendors and third-party systems to support operations, all of which present potential cybersecurity vulnerabilities beyond their control. A breach within any one of these external systems can have serious consequences, compromising protected health information and disrupting essential healthcare operations.
For healthcare technology management (HTM) teams, the issue is no longer only whether a device, server, or network is secure. The critical questions are what each technology connects to, who can access it, and what happens to clinical operations when one of those dependencies fails.
The Vendor Ecosystem Has Become Part of the Clinical Environment
Third-party risk is not new to healthcare, but its operational importance has changed.
According to Verizon’s 2025 Data Breach Investigations Report, third-party involvement appeared in 30% of healthcare breaches analyzed, twice the share reported the previous year. This trend matters because healthcare increasingly relies on technology environments that extend well beyond organizational boundaries.
A vendor may support an imaging platform. Another may maintain a connected medical device remotely. A cloud provider may host applications used for scheduling or documentation. A billing company may process revenue-critical information. A software vendor may maintain privileged access so technicians can troubleshoot systems without traveling on-site.
Each relationship creates another pathway into the healthcare environment.
The US Food and Drug Administration (FDA) reinforced this concern in its 2026 medical device cybersecurity guidance, noting that cyber incidents have rendered medical devices and hospital networks inoperable, potentially delaying diagnosis or treatment and causing patient harm. The agency also emphasizes that medical devices increasingly operate within larger ecosystems that include facility networks, other devices, software update servers, and external infrastructure.
That is an important distinction for healthcare technology management professionals. A device may be functioning exactly as designed and still become unavailable because another part of the technology chain has failed. Cybersecurity, therefore, has to be evaluated around the clinical workflow, not just the individual asset.
Approval Is Not the Same as Governance
Healthcare organizations conduct extensive due diligence before selecting technology vendors, but vendor approval is only the beginning. The greater risk often comes later.
Accounts remain active after projects end. Privileged access is granted for troubleshooting and never reduced. Shared credentials survive employee turnover. Remote support tools stay connected continuously out of convenience. Vendors change subcontractors or infrastructure without security teams realizing their organization’s exposure has changed.
A trusted vendor can also suffer its own breach. That is why third-party security should focus less on whether a vendor is considered trustworthy and more on what access the vendor has been given.
Healthcare organizations should be able to answer several basic questions:
- Which vendors can remotely access the environment?
- Which systems, devices, networks, and data can they reach?
- Is multi-factor authentication (MFA) required?
- Are privileges limited to what the vendor actually needs?
- Is access permanent, or can it be time-bound?
- How quickly can access be disabled during an incident or contract termination?
If those answers are unclear, the organization may have a visibility problem before it has a cybersecurity problem.
Connected and AI-Enabled Technology Adds Another Layer
The growing use of artificial intelligence (AI) and connected medical technology makes these access questions more urgent. AI systems rarely operate in isolation. They connect to data repositories, application programming interfaces, cloud infrastructure, identity systems, clinical software, and operational workflows. Each integration creates another dependency and another identity that may require access.
IBM research found that 13% of surveyed organizations reported breaches involving AI models or applications, and 97% of those organizations lacked proper AI access controls.
The lesson for healthcare is not that AI should be avoided. It is that new technology should not be deployed without the same attention to identity, permissions, monitoring, vendor access, and supply-chain security that is applied to other critical systems.
For HTM teams, this can mean working more closely with information technology, cybersecurity, compliance, and clinical leadership before connected or AI-enabled technology becomes embedded into patient care workflows.
Healthcare Growth Can Multiply Inherited Risk
Vendor risk becomes even harder to manage as healthcare organizations acquire practices, consolidate locations, or standardize technology across multiple sites.
Each acquired location may bring legacy applications, unmanaged devices, old vendor accounts, shared credentials, remote access tools, and different cybersecurity practices. What was previously an isolated weakness can become a broader organizational exposure once environments are connected. Cybersecurity should therefore be part of integration planning, not post-acquisition cleanup.
Before connecting a new location, organizations should identify which systems and devices are being inherited, who maintains them, which vendors have access, whether MFA is enforced, how privileged accounts are managed, and whether backups and downtime procedures have been tested.
This is particularly important for technologies supporting direct patient care. A remote vendor connection created years ago for a single site may become much more consequential once that site joins a larger network.
HTM Teams Need Visibility and Continuity Plans
Healthcare organizations cannot eliminate every third-party dependency, but they can reduce the risk those dependencies create. The first step is visibility. Organizations should maintain an inventory of vendors with access to medical devices, networks, applications, cloud platforms, patient information, or remote support tools. Vendors should then be prioritized based on the level of access they hold and the importance of the workflows they support. High-risk relationships deserve stronger controls.
- Limit privileged access. Vendors should receive only the permissions required for their work, and access should be removed when it is no longer necessary.
- Require strong authentication. MFA should be applied wherever remote or privileged access is possible.
- Monitor vendor activity. Authentication failures, unusual access patterns, policy violations, and privileged actions should not disappear into logs nobody reviews.
- Review access regularly. Vendor permissions should be reassessed as contracts, employees, technology, and clinical workflows change.
- Plan for vendor failure. Incident response and downtime planning should address what happens if a critical provider becomes unavailable. Teams should know who to contact, what evidence the vendor can provide, which workflows must continue, and how staff will operate while systems are restored.
A strong cybersecurity program does more than prevent unauthorized access. It helps the organization continue operating when prevention fails.
Cybersecurity Is Becoming a Care Continuity Discipline
HTM has always been concerned with availability, reliability, maintenance, and patient safety. Cybersecurity is increasingly inseparable from those responsibilities.
The FDA’s medical device guidance makes that connection explicit. A cyber incident can make technology unavailable, delay treatment, and affect patient outcomes. As healthcare environments become more interconnected, those consequences may originate far outside the device or network where they ultimately appear.
The next healthcare cyber crisis may begin with a compromised vendor credential, an unmanaged remote support tool, an exposed software dependency, or a breach at a technology provider hundreds of miles away.
Healthcare organizations cannot control every external company they depend on. They can, however, control how much access those companies receive, how that access is monitored, and how prepared clinical teams are when a critical dependency becomes unavailable.
The goal is no longer simply to restore technology after an attack. It is to ensure that patients can continue moving safely through care while the organization responds.
About the author: William Hale, senior director of vCISO Services at Magna5, provides executive cybersecurity leadership for highly regulated industries. He specializes in building actionable security programs, aligning risk management with business goals, and navigating complex compliance frameworks like HIPAA, HITECH, HITRUST, and NIST CSF.
ID 146060903 © Sasinparaksa | Dreamstime.com
