Select Page

Why Healthcare Can’t Wait to Rethink Patching and Incident Response

A New Paradigm is Now with AI-enabled Cyber Attacks

On August 27th, OpenAI, Microsoft, and more than 100 other technology and cybersecurity companies, including Google, AWS, Anthropic, IBM, Cisco, Palo Alto Networks, CrowdStrike, and Cloudflare, published a joint letter warning that hospitals, water utilities, and other critical infrastructure are facing a fast-approaching surge in AI-enabled cyberattacks. The letter calls for a coordinated response across industry, government, and AI developers, and names healthcare specifically as one of the most exposed sectors as attacker capability accelerates. A warning that healthcare can’t wait to rethink patching strategies.

This Conversation Started in June

At Clearwater’s June Monthly Cyber Briefing, we made two recommendations for organizations to prepare for the new world of frontier AI models:

First, take patching velocity seriously. As frontier AI models get better at identifying unknown vulnerabilities, the race between defenders and adversaries compresses. The organizations that win aren’t the ones with the most tools. They’re the ones that can find, prioritize, and close a gap before an adversary automates their way into it. We said the pressure on patch cycles was only going to increase from here.

Second, prepare your incident response plans for more than one fire at a time. If AI is lowering the cost of finding and exploiting vulnerabilities at scale, it stands to reason that attacks won’t stay isolated, sequential events. IR plans built around “one incident, one war room” need a hard look. Can your team, and your leadership, execute if two or three things go sideways simultaneously?

Underneath both recommendations was a broader point: leadership needs to understand that the threat environment is shifting to a new baseline, not a temporary spike. That means budget conversations, staffing conversations, and board-level risk conversations all need to move now, not after the first incident that proves the point.

The Industry Letter Confirms the Direction

The Becker’s Hospital Review coverage of the OpenAI/Microsoft-led letter makes clear that the private sector sees this coming and is asking governments to help fund and equip under-resourced essential services, hospitals very much included, before the gap between attacker and defender capability widens further.

What’s useful for healthcare security leaders right now isn’t just the warning. It’s that CISA has already published a concrete, risk-based model for exactly the problem the letter describes. In June, CISA issued Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk, replacing the old CVSS-and-KEV-driven patching rules with a four-variable model built explicitly around the reality that AI is compressing the time between vulnerability disclosure and weaponized exploitation.

Under BOD 26-04, every vulnerability gets evaluated against four questions:

  • Is the affected asset publicly exposed?
  • Is it in CISA’s Known Exploited Vulnerabilities (KEV) catalog?
  • Can exploitation be automated?
  • What’s the technical impact if it’s exploited: partial or total control?

The combination of answers routes a vulnerability into one of several remediation tiers, as fast as three calendar days (with mandatory forensic triage to check whether a system was already compromised before the patch went in), down to a “fix at the next scheduled upgrade” tier for genuinely low-risk findings. It’s binding only on federal civilian agencies, but the model itself (stop treating every patch as equally urgent, and instead prioritize based on exposure, exploitability, and impact) is exactly the discipline healthcare organizations need to build now, whether a regulator requires it.

That directive also quietly validates our second June recommendation. Requiring forensic triage alongside rapid patching assumes the possibility that a system was already compromised before remediation, which is a tacit acknowledgment that in this threat environment, you don’t get to assume you’re dealing with one clean, contained event. Your IR plan needs to assume the same thing.

What This Means for Your Organization

If you haven’t already, take these actions:

  • Move off flat, severity-only patching. Whether or not BOD 26-04 applies to you directly, adopt its logic: prioritize by exposure, known exploitation, automatability, and impact, not just a CVSS score. That’s where your limited remediation capacity does the best.
  • Build forensic triage into your patching workflow for your highest-risk findings. Patching closes the door; it doesn’t evict anyone who already walked through it.
  • Pressure-test your incident response plan against a multi-incident scenario. Tabletop it. Assume your team is managing more than one active event, with leadership needing real-time, accurate updates on both.

Cyber Briefings for Healthcare Organizations

Stay informed on the latest healthcare cybersecurity, privacy, and compliance threats. Join Clearwater Cyber Briefings each month for expert insights and actionable risk intelligence.

Register Today to Stay Informed