Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Balancing Cybersecurity and Privacy: Why the Healthcare Industry Needs Stronger Laws to Protect Patient Privacy

The healthcare industry is under pressure to enhance legal frameworks protecting patient data due to increasing digital vulnerabilities. Discussions are focusing on increasing cybersecurity measures as patient data becomes more digitized. Strengthening partnerships between public entities and private healthcare providers is viewed as a crucial step in addressing these concerns.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

By Davy Wittock · CisaCybersecurity in HealthcareDavy WittockFlux
Share

Key takeaways

01

Healthcare leaders need stronger legal frameworks for data protection.

02

Digital vulnerabilities emphasize the need for enhanced cybersecurity measures.

03

Partnerships between public and private sectors are crucial for data security.

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

As healthcare institutions continue to digitize their patient data, the cybersecurity measures safeguarding this sensitive information have surged to the forefront of industry discussions. The discussion has been further ignited by the new directives aimed at strengthening the partnership between public entities and private healthcare providers. Navigating the complex relationship between cybersecurity and privacy has never been more critical, prompting industry experts to weigh in on the best path forward. This dialogue arrives at a pivotal moment when the integration of technology in healthcare is rapidly expanding, raising both possibilities and risks.

How can healthcare organizations enhance their cybersecurity frameworks without compromising patient privacy? This question is central to the ongoing debate.

Davy Wittock, Chief Business Officer at Flux, provides insight into the complex relationship between cybersecurity and privacy within the healthcare sector. His analysis highlights effective strategies for navigating these challenges, emphasizing the importance of a balanced approach.

Key Takeaways from Wittock's Insights:

Advocacy for Stronger Laws: The role of the Cybersecurity and Infrastructure Security Agency (CISA) in pushing for more stringent cybersecurity measures and the advocacy for robust legal frameworks to protect patient data.

Risks of Government Overreach: A critical caution against too much government involvement in healthcare cybersecurity, noting the potential risks to individual privacy.

Importance of Existing Laws: The need to adhere strictly to existing privacy laws, such as HIPAA, to prevent unauthorized access to sensitive patient information.

Transparency and Controls: The necessity of transparency regarding data access and the implementation of strict controls and checks to safeguard data.

Mitigation Strategies: Anonymizing patient data as a preventative measure against cyberattacks, ensuring that access to data does not compromise patient privacy.

Through Wittock's analysis, it becomes evident that balancing effective cybersecurity measures with the imperative to protect patient privacy is not just a technical challenge, but also a legal and ethical one.

Video TranscriptExpand ↓

I think FISA does have a vital role to play. They can also even ultimately advocate for stronger laws, maybe help enforce more rigorous security measures. You have to be careful when it comes to public private partnerships like this, because I do want to advocate for a more robust cybersecurity framework. But we have to keep in mind that we're dealing with health care because we're dealing with very private data. It's a crucial point that we find a good balance between effective cybersecurity measures and protecting everybody. But keep in mind that we are still dealing with very, very individual privacy pieces here too. Patient data. We have to be careful that we don't get into a situation where there's government overreach, especially when you start involving the government in your cybersecurity. You should be concerned with that data. It is very highly sensitive. And if the government gets access to this data, does that not lead to a violation of the privacy? So to mitigate this, we need to make sure that existing laws that are already in place, such as HIPAA, are followed correctly. If not, we're risking that we basically might be exposing patient health information. And that is that would be a big issue if it gets to that. So we have to make sure that even though we should include folks like Sysa, that we don't get to a point where they get access to everything. So there's definitely a need for transparency when it comes to involving an organization like Saisa. And, we make sure that it's very clear on what data they're accessing and how that is protected and who's accessing it. That all needs to be controlled. And we have to make sure that there's clear checks and balances ultimately. So how could we do that? Well, the first mitigation point, any cybersecurity piece is how do you prevent an attack? And what we could do from a health care sense is we can ultimately give them access to data, but we can always anonymize it. That way we can go through anonymize data, but also look at workflows. Where are the risks and the pain points when it comes to cyber security?

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

DW
Davy Wittock

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

Accenture will keep supporting Australia’s My Health Record under a new three-year contract. ADHA is moving the platform to a multi-supplier operating model. The shift raises questions about shared integration discipline, tooling, and accountability when changes hit production.

  • 01Multi-supplier delivery is spreading across national-scale health platforms, as ADHA's My Health Record shift shows, moving risk from vendor selection to integration, runbooks, and accountability.
  • 02GenAI model upgrades are arriving with healthcare-specific claims, but the procurement work moves to evidence, safety controls, and monitoring once models sit inside clinical workflows.
  • 03Embedded AI expands the cyber asset inventory problem: if teams cannot discover the AI components across endpoints and devices, they cannot reliably secure or audit them.

Sep 7, 2026

Hospitals need a shortlist as cardiology AI clearances hit 225

Hospitals need a shortlist as cardiology AI clearances hit 225

Cardiology now has 225 FDA-cleared AI algorithms when imaging is included. That volume is the problem. Health systems now need tighter governance, integration checks, and clinical workflow evidence to decide what ships.

  • 01The useful benchmark for governance committees is scale: FDA-cleared AI totals 1,524 overall, with radiology at 1,163 and cardiology at 225 when CV imaging is included, according to Cardiovascular Business.
  • 02Procurement risk is shifting from “is it cleared?” to “where does it run?” because new clearances span cath lab guidance, echo quantification, remote monitoring, and image assessment tools that touch different systems of record.
  • 03AliveCor shows the long game: Healio reported 510(k) clearance for an ECG AI suite in 2020, and Cardiovascular Business listed a new clearance in 2026, a reminder to vet update cadence and post-clearance support.

Sep 7, 2026

OpenAI’s ChatGPT for Healthcare is getting wired into Epic

OpenAI’s ChatGPT for Healthcare is getting wired into Epic

ChatGPT for Healthcare can now read from Epic. UCSF Health is piloting the read-only integration, according to Fierce Healthcare and Becker’s Hospital Review. For CIOs, the work is permissions, auditability, and clinical validation in Epic workflows.

  • 01The “read-only” label doesn’t remove governance work, it moves it to permissions mapping, audit logs, and connector scope design inside Epic-supported workflows.
  • 02OpenAI’s published clinician review results (99.1% rated safe across 4,363 ratings) are a useful benchmark, but they still need local validation on your own note templates, meds workflows, and specialty mix.

Sep 7, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

DW
Davy Wittock

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512