ISMG Acquires INE to Advance Global Cyber Readiness Across Every Discipline and Role

Read the press release →

Keep Care Running: Inside HealthSec USA 2026

Twenty-five healthcare and cybersecurity experts convened in Boston to confront the threats hiding behind every connected device, clinical workflow and patient interaction. 

Nobody notices cybersecurity when a hospital is working normally. A physician opens a patient record. A nurse signs into a shared workstation. A medical device sends data to the right system. Care continues. 

But healthcare has almost no tolerance for digital disruption. When identity systems fail, clinicians lose access. When ransomware spreads, procedures are delayed. When patient data leaks through an unnoticed third-party script, the consequences extend far beyond the security team. 

HealthSec USA — held in Boston on June 9 and 10 — brought healthcare practitioners and security experts together to examine how organizations can protect patient care while navigating AI adoption, ransomware, identity modernization, third-party risk and limited budgets. 

Across thirteen sessions, one message kept resurfacing: healthcare cybersecurity cannot be separated from operational resilience. Protecting the technology means protecting the care it enables. 

The AI Attack Surface

Healthcare organizations are adopting AI inside environments that were already difficult to secure. The opening challenge was understanding how those systems change both the attack surface and the speed of an attack. 

The lesson: healthcare cannot treat AI as another software implementation. It introduces new technical risks, new human risks and new governance responsibilities at the same time. 

Identity at the Point of Care

Healthcare identity programs have to secure access without interrupting the people delivering care. That balance becomes especially difficult when clinicians move between shared devices, high-pressure environments and multiple systems throughout the day. 

  • David Quigley of Tampa General Hospital, Rodney Apura of Ping Identity and Steven Ramirez of Renown Health shared lessons from identity modernization programs that improved security, automated account recovery and reduced the burden on help desks. 

These sessions reframed identity as more than an access-control problem. In healthcare, every unnecessary login, lockout and recovery process can become an operational obstacle. 

The strongest identity programs do not simply make unauthorized access harder. They make legitimate access faster and safer. 

Preparing for the Attack

Ransomware readiness cannot begin after systems are encrypted. By then, the organization is already making critical decisions under pressure. 

  • Lee Cullivan of Boston Medical Center outlined a healthcare ransomware response framework built around governance, clearly defined leadership responsibilities and tabletop exercises that improve executive decision-making before an incident occurs. 
  • Heather Costa of Mayo Clinic argued that healthcare organizations must move beyond prevention-focused cybersecurity and design for recovery. That means identifying critical services, planning phased restoration and ensuring teams are operationally ready to bring care systems back online. 
  • Brian Conway of Commvault continued the recovery conversation, explaining how clean data recovery, continuous testing and AI-aware security strategies can help healthcare organizations restore critical systems faster after a breach. 

The distinction matters. Incident response contains the attack. Cyber resilience determines whether the organization can continue delivering care while it recovers. 

Seeing the Whole Environment

Healthcare security teams cannot defend assets they cannot see, software components they do not understand or data flows they do not know exist. 

Together, these sessions exposed healthcare’s visibility problem at three levels: where patient information travels, what assets are operating and what software components those assets contain. 

Visibility is not the most dramatic part of healthcare cybersecurity. It is the foundation beneath almost every effective response. 

Funding What Matters

Healthcare leaders rarely have the luxury of funding every possible control. Security investment competes with clinical technology, staffing, infrastructure and direct patient needs. 

  • Amit Gupta, Esmond Kane, Jesse Ku, Mike Leffer and Nick Sturgeon examined how healthcare organizations can balance cybersecurity spending with patient safety. Their discussion focused on prioritizing material risk, strengthening resilience and applying AI where it can meaningfully improve defense. 

The mature question is no longer whether healthcare should spend more on cybersecurity. It is whether each investment protects the systems, workflows and services the organization most needs to preserve. 

That requires security leaders to translate technical exposure into operational and patient-care consequences. 

HealthSec USA 2026, by the Numbers

  • 5 hours and 30 minutes of healthcare cybersecurity instruction 
  • 25 unique speakers across practitioner briefings and multi-expert discussions 
  • Perspectives from healthcare organizations including Mayo Clinic, Boston Medical Center, Tampa General Hospital and Renown Health 
  • Thirteen topic areas spanning AI security, AI governance, human risk, ransomware, identity modernization, passwordless authentication, third-party tracking, cybersecurity spending, business continuity, asset visibility, recovery and SBOMs 
  • Sessions ranging from 15 to 40 minutes, designed to deliver focused guidance without keynote filler 

The complete program tells one connected story: healthcare cybersecurity is no longer only about preventing a breach. It is about keeping clinicians working, preserving critical services and ensuring patient care continues when technology does not behave as planned. 

Get Every Session — and Every ISMG Event

These sessions are just the beginning. Security Insights by CyberEd puts the entire ISMG events experience — virtual and in person — in one on-demand library, with global event replays, expert-led masterclasses and CPE credits on demand, featuring the CISOs, regulators and security leaders defining the field. 

The scale speaks for itself: 400 events annually, 75,000+ attendees, 500 expert speakers and more than 1,000 sessions. 

And the math is hard to argue with. A single conference can run into the thousands once you add flights, hotels and tickets — plus the days away from your team. Security Insights delivers all of it for just $495 a year, on your schedule, without leaving your desk. 

▶ Stop choosing which event to attend. Get them all. 

Subscribe to Security Insights by CyberEd → 

Related Content