By Michael Hiskey
The Nashville Executive Forum delivered exactly what a peer-led executive forum is designed to do: bring a relatively small group of healthcare security leaders together for an honest, candid conversation about the challenges they are actually facing.
Rather than relying on presentations or one-way discussions, the evening began with participants briefly sharing their roles, backgrounds and the most pressing issues on their plates. The group then reviewed the Top 10 issues identified through Health-ISAC’s CISO Summit pre-survey, before spending the majority of the evening digging into the topics that generated the most discussion and disagreement.
What became clear very quickly was that healthcare cybersecurity is sitting at an important inflection point.
AI was everywhere in the conversation—but rarely as a stand-alone “AI topic.” It appeared in discussions about identity, access, vulnerability management, data protection, third-party risk and even the fundamental question of how healthcare organizations will operate in the years ahead.
At the same time, participants acknowledged that many organizations are still dealing with foundational challenges: vulnerability management, DLP and data classification, IGA, legacy Active Directory structures and manual processes.
One participant summed up the frustration in a very Nashville-native way:
“AI is getting my goat.”
Another question captured a broader concern:
“Why is healthcare eight years behind financial services?”
The tension between emerging technology and unfinished foundational work was one of the strongest themes of the evening.
Health-ISAC’s benchmarking data reinforces that reality. 80% of surveyed CISOs identify AI-enabled attacks as a top emerging concern, while IAM is the #1 initiative for the next 12–24 months at 78%, followed by business continuity/disaster recovery at 74%. Supply-chain and third-party risk is already the sector’s #2 identified cyber risk, selected by 64% of respondents.
In other words, healthcare security leaders aren’t simply preparing for the future. They are trying to build that future while simultaneously addressing problems that have been accumulating for years.
Identity generated some of the strongest conversation of the evening.
Participants discussed legacy IGA environments, excessive entitlements, outdated Active Directory roles, service accounts and the difficulty of automating processes that healthcare organizations have traditionally managed manually.
One comment captured the problem particularly well:
“When we have more Active Directory roles than we have people… something is wrong.”
But the discussion quickly moved beyond traditional human identity.
AI agents, service accounts, tokens and other non-human identities are multiplying the identity problem. One example involved an attack touching roughly a dozen non-human identities, including identities created or controlled by servers rather than people.
Traditional approaches—such as simply vaulting and rotating credentials—may not be sufficient for an environment where software can increasingly act autonomously.
PAM was described as having something of a renaissance, but the larger question is architectural: How do healthcare organizations establish identity and authorization models for agents that can act, invoke other systems and potentially create credentials themselves?
One practical idea that resonated was the concept of creating a “golden path.”
Instead of trying to stop the business from adopting AI, security teams can establish a supported route from the identity provider through runtime gateways and other security controls. The goal is to make the secure approach the easiest approach, while still allowing the business to determine appropriate permissions within those guardrails.
That aligns closely with the broader Summit discussion around moving AI governance from “no” to “how.”
The group also discussed the emerging issue of “shadow MCPs”—Model Context Protocol connections or servers being introduced as AI tools and agents proliferate. These can create new integrations, credentials and data paths that security teams may not yet see or govern.
The larger point is difficult to miss: yesterday’s service-account problem could become tomorrow’s agent-identity problem—at a considerably greater scale.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!
Another concept that generated significant interest was the “Minimum Viable Organization.”
Originally framed in the research as the “Minimum Viable Hospital,” the concept was broadened to recognize that Health-ISAC member organizations include hospitals, clinics and other healthcare facilities.
The question is straightforward but difficult:
What must an organization still be capable of doing safely when major systems are unavailable for days—or potentially weeks?
The CISO Summit material intentionally frames the issue around a 14-day EMR and pharmacy outage. That is a very different exercise from traditional disaster-recovery planning.
Participants discussed the limitations of familiar downtime procedures such as manual charting. Those procedures may work for several hours. But what happens after two days? A week? Three weeks?
At that point, recovery cannot simply be measured by how quickly servers come back online. It has to be measured against the organization’s ability to continue providing safe care to vulnerable patients.
The benchmarking data reinforces the concern. Only 22% of organizations rate their NIST “Recover” maturity at Level 4 or 5, while 26% remain at Level 1 or 2. Health-ISAC identifies recovery as the sector’s most urgent maturity gap because, in healthcare, technology downtime can ultimately become a patient-care issue.
The practical question coming out of the Nashville discussion was therefore not simply:
Do we have a recovery plan?
It was closer to:
What can the organization safely continue doing, for how long, and have we actually practiced operating that way?
That is a much more meaningful definition of resilience.
Third-party risk was another recurring topic, but the conversation was clearly beyond the question of whether traditional questionnaires are sufficient.
The harder questions were about dependency.
Who are the critical suppliers behind your critical suppliers? Where are the concentration points? What happens when a SaaS, cloud or healthcare technology provider becomes unavailable? And what leverage does an organization actually have once the contract has been signed?
The Summit survey describes this evolution as moving “Beyond Questionnaires to Active Supply Chain Defense.” That includes fourth-party visibility, concentration-risk analysis, stronger contractual requirements and coordinated incident response.
The Nashville discussion reflected that same shift.
The benchmarking report provides additional context: 64% of CISOs place supply-chain/third-party risk among their top three risks, while 65% cite third-party and supply-chain blind spots as something keeping them up at night.
Yet only 8% outsource TPRM, meaning most healthcare organizations are still trying to manage an increasingly interconnected ecosystem largely with their own internal teams.
The challenge, therefore, is not simply to assess vendors. It is to understand the operational dependencies those vendors create—and what happens when one of those dependencies fails.
Perhaps the most important theme connecting all three discussions was the idea that healthcare security cannot continue solving problems simply by adding friction.
Several comments came back to essentially the same question:
“How do I make people productive?”
That applies to AI adoption, identity, access controls, third parties and clinical workflows.
The security leader’s role increasingly involves creating a safe operating model in which the business can move quickly—not simply creating controls that prevent it from moving.
That becomes even more important when resources are limited.
The benchmarking report shows that 40% of health-sector security programs operate with 10 or fewer FTEs, while half of CISOs identify budget constraints—not talent availability—as their biggest workforce challenge.
The answer cannot simply be adding more people to manually administer more controls.
Automation, architecture, integration and better operating models will increasingly have to do more of the work.
Several comments captured the Nashville conversation particularly well:
“AI is getting my goat.”
“When we have more Active Directory roles than we have people… something is wrong.”
“Why is healthcare eight years behind financial services?”
And perhaps the most important sentiment was less technical:
“This is about patients.”
That statement brought the entire conversation back to Health-ISAC’s core mission.
Identity, AI governance, resilience and third-party risk are cybersecurity problems. But in healthcare, the consequences extend well beyond technology.
They can affect continuity of care, clinical operations and patient safety.
The Nashville discussion suggested a healthcare sector at an interesting point of transition.
Healthcare CISOs are being asked to finish yesterday’s modernization work while governing tomorrow’s technology.
They are cleaning up decades of identity complexity while preparing for autonomous agents. They are improving traditional disaster recovery while contemplating multi-week clinical outages. And they are moving away from static vendor assessments toward a model based on interconnected operational dependencies.
That makes the value of the Health-ISAC community particularly apparent.
Participants repeatedly wanted to know some version of the same questions:
A benchmark can help answer some of those questions, but it cannot provide the full picture. The combination of benchmarking data, the forthcoming CISO Summit discussions and small peer forums such as Nashville creates something more valuable: an opportunity for security leaders to compare real-world experiences and turn individual challenges into shared practices.
And that may ultimately be the story of the Nashville evening.
It wasn’t that the group produced definitive answers to IAM, resilience or TPRM.
It was that participants recognized how remarkably similar their challenges are—and were willing to openly compare notes about what they are actually doing about them.
For a sector facing both rapidly accelerating technology and persistent foundational challenges, that kind of peer-to-peer conversation may be one of the most practical tools available.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!