Connect with us

Hi, what are you looking for?

Technology

Why Healthcare Cybersecurity and Secure Health Information Systems Are a Matter of National Importance

Why Healthcare Cybersecurity and Secure Health Information Systems Are a Matter of National Importance

The professionals protecting electronic health records, cloud infrastructure, digital identities, and healthcare networks are quietly safeguarding the systems on which modern patient care and public health depend

Every time a physician opens an electronic health record, a laboratory sends a result, a pharmacy receives a prescription, or a public health professional analyzes health data, an enormous digital infrastructure is working behind the scenes. Most patients will never see the networks, databases, identity systems, cloud platforms, and security controls supporting those interactions. Yet the confidentiality, accuracy, and availability of health information increasingly depend on them. As healthcare becomes more interconnected and technology-dependent, protecting that infrastructure is no longer simply an information technology responsibility. It is becoming essential to protecting healthcare delivery and public health.

My own path into this field began with public health rather than cybersecurity. I earned my bachelor’s degree in public health and worked in public health research, where I managed structured datasets, conducted data-quality checks, and worked with information used to understand population health. I later worked as a Medical Record Officer, managing health-information workflows involving medical records, ICD-10 coding, insurance data validation, reporting, and electronic health record quality control. Those experiences taught me an important lesson: healthcare decisions are only as dependable as the information supporting them. If health information is inaccurate, unavailable, or accessible to people who should not have it, the problem extends far beyond a computer system.

That realization eventually led me deeper into information technology. I pursued a Master of Science in Information Technology Management at Webster University and expanded my work into networking and security. Today, my professional experience includes supporting enterprise network operations involving firewalls, VPNs, routing, DNS, access policies, and secure connectivity. My research brings those two sides of my career together. I focus on healthcare cybersecurity, identity and access management, cloud security, HIPAA, health information management, and the broader challenge of making healthcare information systems secure without preventing legitimate information from reaching the professionals who need it.

This work matters nationally because healthcare now depends on digital systems. Electronic health records, laboratory platforms, pharmacy systems, insurance systems, public health databases, remote-access technologies, and cloud applications have become part of the infrastructure that healthcare runs on. A disruption to these systems can therefore become more than an IT incident. When critical information is unavailable, corrupted, or improperly disclosed, the consequences can affect healthcare organizations, professionals, patients, and communities. Protecting digital healthcare infrastructure should therefore be understood as part of protecting healthcare’s resilience.

One of the most important challenges is identity. In a healthcare environment, physicians, nurses, administrators, researchers, contractors, vendors, and other personnel may require access to different systems and different categories of information. The central question sounds simple: who should be allowed to access what? In practice, answering it consistently across complex organizations is difficult. Employees change roles, contractors complete assignments, responsibilities evolve, and permissions can accumulate over time. This is why identity governance and least-privilege access are becoming increasingly important. Security is not only about preventing an outsider from entering a network. It is also about ensuring that legitimate users receive the access they actually need, that access remains appropriate, and that unnecessary privileges do not persist indefinitely.

Cloud computing adds another dimension to this challenge. Healthcare organizations are increasingly operating in environments that extend beyond traditional on-premises infrastructure. Cloud platforms can provide capabilities for scalability, monitoring, logging, identity management, resilience, and modernization, but moving workloads to the cloud does not automatically make them secure. Permissions still have to be governed. Networks still need careful design. Activity must be monitored, and sensitive information must be protected. My interest in cloud security therefore centers not simply on migration, but on secure migration: designing identity, access, monitoring, data protection, and resilience into modernization efforts from the beginning rather than treating cybersecurity as something to add later.

This challenge also explains my interest in modernizing healthcare security requirements. Healthcare technology has evolved rapidly. Organizations now operate across cloud platforms, remote connections, interconnected applications, third-party services, and increasingly complex digital ecosystems. Security practices must evolve with those environments. In my recent work on the divide between public health and cloud security, I have focused particularly on the workforce implications of healthcare cybersecurity modernization. Public health professionals understand health systems, populations, and the significance of health information. Cloud and cybersecurity professionals understand infrastructure, identity, access controls, networks, monitoring, and technical risk. Modern healthcare increasingly needs professionals who can communicate across both worlds.

Data quality is another part of this conversation that deserves more attention. Cybersecurity is frequently discussed in terms of preventing information theft, but protecting confidentiality is only part of information security. Healthcare professionals also need information that is accurate and available. My work on quality-control frameworks for electronic health record data workflows grew out of this concern. A health-information system cannot be considered fully trustworthy merely because unauthorized users cannot access it. If the information inside that system is incomplete, inconsistent, incorrectly entered, or unavailable when needed, the organization faces a different but equally important information-management problem. Security, data quality, and health-information governance therefore need to be considered together.

Emerging artificial intelligence technologies will make these questions even more urgent. I have participated in research examining local large language models for natural-language-to-SQL querying, an approach that can make structured databases accessible through ordinary language. Technologies like these have significant potential, including reducing technical barriers to interacting with complex information systems. But in healthcare, easier access to data must be accompanied by stronger governance. Who is authorized to ask the question? What information is the model permitted to retrieve? How do we verify that the generated query is correct? Could sensitive information be exposed through an otherwise convenient interface? As AI becomes more deeply integrated into information systems, organizations should address these questions during system design rather than after deployment.

The challenge is particularly significant for organizations operating with limited resources. Not every healthcare organization has a large cybersecurity department or the budget to replace legacy infrastructure continually. Smaller organizations may face competing priorities, limited specialized staff, and systems built long before today’s cybersecurity environment. But improving security doesn’t always start with buying the most expensive technology. Understanding what information and systems an organization has, applying appropriate access controls, reviewing user privileges, maintaining reliable backups, strengthening authentication, monitoring critical activity, documenting changes, and establishing clear incident procedures are foundational practices that can strengthen security and resilience.

The human workforce remains central to all of this. Technology alone cannot solve healthcare cybersecurity. People configure systems, approve access, respond to incidents, handle sensitive information, interpret alerts, and make everyday decisions that determine whether policies work in practice. At the same time, cybersecurity teams need to understand healthcare workflows. A security control that looks ideal from a purely technical perspective can create operational problems if it prevents clinicians or other authorized professionals from getting information they legitimately need. The goal should therefore be to make secure behavior practical behavior, designing systems in which strong protection and efficient healthcare operations reinforce rather than undermine one another.

This is why I see the intersection of public health and information technology as increasingly important. My career has allowed me to encounter health information from several perspectives: as population-health research data, as medical records that require accuracy and confidentiality, and as digital information moving through networks and information systems that must be protected. Those experiences have convinced me that the next generation of cybersecurity challenges cannot be addressed by technical expertise alone or by healthcare expertise alone. We need professionals who can understand both the information being protected and the technology protecting it.

The public rarely sees this infrastructure when it works properly. Patients see their physician, receive their laboratory results, collect their prescriptions, and assume the necessary information will be there. Behind those ordinary interactions are databases, networks, cloud services, identity systems, security controls, and professionals working to keep them dependable. That reliability is not automatic. It has to be designed, monitored, governed, and continuously improved.

As healthcare becomes more digital, interconnected, cloud-based, and increasingly influenced by artificial intelligence, protecting health information while keeping it appropriately accessible will become even more consequential. Secure identity governance, resilient cloud infrastructure, reliable electronic health records, strong data-quality practices, and cybersecurity-aware healthcare workforces are not merely technical improvements. They are components of a healthcare system that can maintain public trust and function reliably in an increasingly digital society.

Investing in secure and interoperable healthcare information infrastructure, and in professionals who understand both healthcare and the technologies supporting it, should therefore not be viewed as a secondary IT priority. It is part of strengthening healthcare’s resilience. As digital systems have become inseparable from the delivery and management of health services, protecting them has become a matter of broader public and national importance.

Ambika Baniya Bhandari is a healthcare IT and cybersecurity researcher and information technology professional with an academic background in Public Health and Information Technology Management. Her work and research interests span healthcare cybersecurity, identity and access management, cloud security, Zero Trust, HIPAA, electronic health record data quality, and secure health information management. She holds a Master of Science in Information Technology Management from Webster University and a bachelor’s degree in public health from Pokhara University.






Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Technology

Share Share Share Share Email Artificial intelligence is making it easier to create convincing websites, marketing material, emails and online content at a speed...

Technology

Share Share Share Share Email Cybersecurity is a rapidly evolving field shaped by artificial intelligence, cloud computing, remote work, connected devices, data protection requirements,...

Technology

Share Share Share Share Email Healthcare equipment is expensive. That is one reason more hospitals, clinics, and medical groups are looking at refurbished equipment....

Technology

Share Share Share Share Email Business email compromise cost organizations $3.05 billion in reported losses in 2025, according to the FBI’s Internet Crime Complaint...