Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Healthcare Orgs Can Secure Their Health Data with Workforce & Regulatory Enhancements

Healthcare organizations face escalating cyber threats to patient data and must address both workforce shortfalls and evolving regulatory frameworks to strengthen their security posture. Robin Berthier, Ph.D. outlines how staffing gaps and insufficient compliance structures leave health data vulnerable. Combining targeted workforce development with updated regulations is presented as essential to protecting sensitive healthcare information.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Promoted content from Experts Talk on MarketScale.

By Robin Berthier, Ph.D. · Cybersecurity in HealthcareHealthcare TechnologiesNetwork PerceptionPatient Privacy
Share

Key takeaways

01

Staffing gaps in cybersecurity roles leave healthcare organizations exposed to data breaches and ransomware attacks.

02

Regulatory frameworks must evolve to keep pace with the increasingly sophisticated threat landscape targeting health data.

03

A combined approach addressing both workforce capacity and compliance requirements is critical for sustainable healthcare cybersecurity.

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

The healthcare industry faces a rising wave of cyberattacks, highlighting the critical urgency to fortify cyber defenses. These breaches threaten the integrity and availability of essential healthcare services and sensitive health data, intensifying the need for robust cybersecurity measures. This urgency is partly driven by the complex nature of healthcare technologies and the limited cybersecurity workforce capable of managing these challenges.

The healthcare industry faces a rising wave of cyberattacks, highlighting the critical urgency to fortify cyber defenses.

Given the high stakes of protecting sensitive health data, how can healthcare organizations better prepare to face these growing threats?

In a recent Expert's Talk episode, Robin Berthier, the CEO and co-founder of Network Perception shares his insights on the pressing need for robust cybersecurity defenses in the healthcare industry. He highlights the crucial role of strategic regulations, the importance of understanding the intricate healthcare IT landscape, and the need for a skilled cybersecurity workforce to implement effective protections.

Key takeaways:

  1. Regulation as a Catalyst: Without stringent regulations akin to those in other critical sectors, healthcare organizations may lack the motivation to align their resources adequately with cybersecurity needs.
  2. Visibility and Complexity: Gaining clear visibility over existing IT assets and understanding the intricate interactions between applications and equipment are crucial first steps toward effective cybersecurity.
  3. Workforce Challenges: The scarcity of skilled cybersecurity professionals within healthcare further complicates the implementation of best practices and sophisticated defense mechanisms.
  4. Board-Level Engagement: Recently, cybersecurity discussions have ascended to the board level in many organizations, signaling a shift towards more strategic and governed approaches.
  5. Risk Prioritization: With limited resources, healthcare providers must prioritize risks, focusing on the most critical areas that could impact patient safety and data integrity.
Video TranscriptExpand ↓

You know, it's I I don't see, out outside of really having regulation, I don't see a solution for making those resources more aligned with the need. I mean, we keep hearing those three problems from the organization we're working with. Like one is this greater sense of urgency around just gaining visibility over what we have. Second, to understand the the complexity. Like, you you mentioned, like, how complex those applications and equipment were interacting with each other. So it's it's really hard for an organization now to do just risk assessment on on top of that complexity. And then the third challenge is the limited workforce. You're right. Like, it's just one person often, and they don't have the resources or the staff to be able to just adopt the best practice cybersecurity solutions. So other than regulation, that's why I mentioned the TSFCE directives in the oil and gas pipeline and have experience on the electric side with the NERC SIP, which is the most punitive OT cybersecurity framework in the US. Like, if you don't comply, you you get fined up to one million dollar per day. But but without that big hammer, I just don't see, organizations having the the capacity to allocate more budget or or or Yeah. Interest to those those internal, internal fights. Yep. I agree fully. Yeah. And I I should say, you know, risk prioritization is always the name of the game, right, particularly for Sysco. They have limited resources and and many things they have to do for the business. So it's it's constantly a a juggernaut for sure. The good news there is that we are seeing I mean, we've seen a shift last year where that discussion, reached the the board level in any organization. I think the visibility on those breaches is helping. I was really pleased to see the new version of the NIST CSF really emphasizing governance, so putting responsibility at at the highest level in organization to to take cybersecurity seriously.

Experts Talk

Part of this channel

Experts Talk

Industry experts debate the ideas that drive B2B decisions.

Visit the channel

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

RB
Robin Berthier, Ph.D.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

Direct-to-consumer telehealth raises spending, even as ASC investment surges

Direct-to-consumer telehealth raises spending, even as ASC investment surges

A Health Affairs analysis of commercial claims data (2011–13) found 12% of direct-to-consumer telehealth visits replaced visits to other providers and 88% represented new utilization, with net annual spending on acute respiratory illness increasing $45 per telehealth user. Separately, MobiHealthNews reported on August 31, 2026, via a HIMSSCast episode, that Erik Tellefson of Capital One said ambulatory surgery centers “represent one of the clearest growth structures in American healthcare.”

  • 01The most actionable benchmark for finance teams evaluating DTC telehealth is substitution rate, not visit growth. Health Affairs measured 12% substitution and 88% new utilization in commercial claims for acute respiratory illness.
  • 02The $45 per-user net annual spend increase in the Health Affairs analysis is small enough to hide in PMPM reporting but large enough to matter at scale, and it should be stress-tested against virtual-visit eligibility rules and repeat-use patterns.

Sep 2, 2026

HFMA’s new chair is a hospital CFO as Medicare reporting gets more detailed and revenue cycle work gets more technical

HFMA’s new chair is a hospital CFO as Medicare reporting gets more detailed and revenue cycle work gets more technical

HFMA named Corewell Health CFO Matthew E. Cox as its national chair effective June 1, 2026, while elevating revenue cycle and reimbursement leaders to its board, according to HFMA’s GlobeNewswire announcement. The association’s own coverage of CMS’s FY 2027 IPPS/LTCH PPS final rule summary and new Medicare cost-reporting requirements such as Worksheet S-12 indicates a compliance workload that is increasingly data- and documentation-heavy for hospital finance and reporting teams. In parallel, HFMA’s certification catalog, including the Certified Hospital Cost Report Specialist (CHCRS) and Certified Specialist Payment & Reimbursement (CSPR), points to how health systems are professionalizing the skill sets needed to operationalize reimbursement policy changes. For operators, the practical consequence shows up in staffing models, audit readiness, and the data plumbing needed to produce defensible cost reports and faster revenue cycle decisions.

  • 01HFMA’s board slate now visibly includes roles that control the work: a system CFO (Corewell Health) and a chief revenue officer overseeing $7 billion in patient revenue at Orlando Health, per GlobeNewswire. That’s a signal that cost reporting and revenue cycle execution are board-level concerns, not back-office chores.
  • 02Medicare cost reporting is moving toward more granular worksheets and documentation, and each new CMS reporting requirement becomes a data-integration project before it becomes a policy memo, per HFMA’s reporting on Worksheet S-12 and its FY 2027 IPPS/LTCH PPS coverage.
  • 03HFMA’s CHCRS, CRCR, and CSPR credentials provide a concrete way to benchmark internal capability: if cost report preparation, managed care contract terms, and prior auth workflows live in different teams, credentialing can reveal where handoffs are breaking down.

Sep 2, 2026

FDA QMSR ties supplier contracts to inspection prep

FDA QMSR ties supplier contracts to inspection prep

FDA’s Quality Management System Regulation (QMSR) took effect Feb. 2, 2026, incorporating ISO 13485:2016 into 21 CFR Part 820 and shifting inspections to a process-based model under Compliance Program 7382.850, according to MD+DI. That change is starting to show up outside the quality department: medical device OEMs are being pushed to spell out documentation, audit support, and change-control responsibilities in contract manufacturing agreements, as Medical Design and Outsourcing described. Two recent partnership moves, Ratio Therapeutics expanding radiopharmaceutical manufacturing with PharmaLogic in Idaho Falls and Menicon shifting U.S. Rose K manufacturing access to three partners after concluding a prior arrangement, illustrate how multi-party supply chains now need contract terms that map directly to integrated QMS evidence. The operational consequence is simple: under CP 7382.850, a complaint, supplier nonconformance, or process change can pull investigators across CAPA, risk management, purchasing, and design records in one thread, so contracts and quality records have to be built to travel together.

  • 01Under FDA CP 7382.850, inspection risk increasingly sits in the “handoffs” between complaint handling, CAPA, supplier controls, and the Risk Management File, so quality evidence has to be assembled end-to-end, not by department.
  • 02For OEMs outsourcing manufacturing, the most useful contract test in 2026 is whether each clause produces inspectable artifacts, who owns them, where they live, and how fast they can be produced during an audit.
  • 03Multi-partner manufacturing models, like Menicon’s three-partner Rose K availability and Ratio’s capacity expansion with PharmaLogic, raise the bar on configuration control, supplier risk classification, and change notification across sites.

Sep 2, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

RB
Robin Berthier, Ph.D.

CEO and Co-Founder at Network Perception

Robin Berthier, Ph.D. is the CEO and co-founder of Network Perception, a cybersecurity company focused on network security analysis and compliance for critical infrastructure. He holds a Ph.D. in computer science and has extensive research and industry experience in network security and intrusion detection. Berthier is a recognized expert in operational technology (OT) security and healthcare cybersecurity.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512