Select Page

Why Healthcare Can’t Wait to Rethink Patching and Incident Response

On August 27th, OpenAI, Microsoft, and more than 100 other technology and cybersecurity companies, including Google, AWS, Anthropic, IBM, Cisco, Palo Alto Networks, CrowdStrike, and Cloudflare, published a joint letter warning that hospitals, water utilities, and other critical infrastructure are facing a fast-approaching surge in AI-enabled cyberattacks. The letter calls for a coordinated response across industry, government, and AI developers, and it names healthcare specifically as one of the sectors most exposed as attacker capability accelerates.

This Conversation Started in June

At Clearwater’s June Monthly Cyber Briefing, we made two recommendations for organizations to prepare for the new world of frontier AI models:

First, get serious about patching velocity. As frontier AI models get better at identifying unknown vulnerabilities, the race between defenders and adversaries compresses. The organizations that win aren’t the ones with the most tools. They’re the ones that can find, prioritize, and close a gap before an adversary automates their way into it. We said the pressure on patch cycles was only going to increase from here.

Second, prepare your incident response plans for more than one fire at a time. If AI is lowering the cost of finding and exploiting vulnerabilities at scale, it stands to reason that attacks won’t stay isolated, sequential events. IR plans built around “one incident, one war room” need a hard look. Can your team, and your leadership, execute if two or three things go sideways simultaneously?

Underneath both recommendations was a broader point: leadership needs to understand that the threat environment is shifting to a new baseline, not a temporary spike. That means budget conversations, staffing conversations, and board-level risk conversations all need to move now, not after the first incident that proves the point.

The Industry Letter Confirms the Direction

The Becker’s Hospital Review coverage of the OpenAI/Microsoft-led letter makes clear that the private sector sees this coming and is asking governments to help fund and equip under-resourced essential services, hospitals very much included, before the gap between attacker and defender capability widens further.

What’s useful for healthcare security leaders right now isn’t just the warning. It’s that CISA has already published a concrete, risk-based model for exactly the problem the letter describes. In June, CISA issued Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk, replacing the old CVSS-and-KEV-driven patching rules with a four-variable model built explicitly around the reality that AI is compressing the time between vulnerability disclosure and weaponized exploitation.

Under BOD 26-04, every vulnerability gets evaluated against four questions:

  • Is the affected asset publicly exposed?
  • Is it in CISA’s Known Exploited Vulnerabilities (KEV) catalog?
  • Can exploitation be automated?
  • What’s the technical impact if it’s exploited: partial or total control?

The combination of answers routes a vulnerability into one of several remediation tiers, as fast as three calendar days (with mandatory forensic triage to check whether a system was already compromised before the patch went in), down to a “fix at the next scheduled upgrade” tier for genuinely low-risk findings. It’s binding only on federal civilian agencies, but the model itself (stop treating every patch as equally urgent, and instead prioritize based on exposure, exploitability, and impact) is exactly the discipline healthcare organizations need to build now, whether a regulator requires it.

That directive also quietly validates our second June recommendation. Requiring forensic triage alongside rapid patching assumes the possibility that a system was already compromised before remediation, which is a tacit acknowledgment that in this threat environment, you don’t get to assume you’re dealing with one clean, contained event. Your IR plan needs to assume the same thing.

What This Means for Your Organization

If you haven’t already:

  1. Move off flat, severity-only patching. Whether or not BOD 26-04 applies to you directly, adopt its logic: prioritize by exposure, known exploitation, automatability, and impact, not just a CVSS score. That’s where your limited remediation capacity does the best.
  2. Build forensic triage into your patching workflow for your highest-risk findings. Patching closes the door; it doesn’t evict anyone who already walked through it.
  3. Pressure-test your incident response plan against a multi-incident scenario. Tabletop it. Assume your team is managing more than one active event, with leadership needing real-time, accurate updates on both.
  4. Bring this to your board and executive leadership now. The conversation isn’t “are we at risk of a cyberattack.” It’s “our organization’s baseline risk has moved, and here’s what we’re doing to move with it.”

The letter from OpenAI, Microsoft, and their 100-plus co-signatories is a call to action for the industry and for governments. For healthcare organizations, the more immediate call to action is internal: the velocity of the threat has changed, and your patching discipline, your incident response plan, and your leadership’s understanding of the risk all need to change with it.

What was on the horizon in June is becoming reality in August. Build the resilience now before it is too late.

Cyber Briefings for Healthcare Organizations

Stay informed on the latest healthcare cybersecurity, privacy, and compliance threats. Join Clearwater Cyber Briefings each month for expert insights and actionable risk intelligence.

Register Today to Stay Informed