
Why do we care about cybersecurity in healthcare
There is a clear bottom line for what #cybersecurity or rather #cyberresilience in #healthcare is about.
Cyber resilience is no longer about protecting systems.
It’s about protecting care.
And – it’s a leadership issue.
Speaking at the Australasian Institute of Digital Health (AIDH) WA Digital Health Summit 2026 in Perth, yesterday, alongside Professor David Playford, a clinical leader, colleague and client, we explored a two-way perspective of how to lead a successful clinical practice in the age of “cyber insecurity”.
Where Leadership teams get stuck
What we consistently see across general, and specialist clinical practice is this: digital systems have become mission-critical aspect of patient care delivery—yet cyber risk is still treated as an IT concern, not a clinical one.
Where leadership teams get stuck is at the intersection of care delivery and technology. When practice management systems, imaging platforms or communications tools fail, the impact isn’t abstract. Appointments stall. Clinicians improvise. Staff confidence drops. Continuity of care is compromised.
Our topic reflected on how healthcare practices and specialist clinics actually operate today, navigating risk and governance in a new digital world. Our goal was to show some practical scenarios for building a cyber-resilient culture in general and specialist clinical practice.
Here are top three takeaways:
1. Risk
Today’s dependency on digital systems creates vulnerability. A small disruption in any link — an imaging gateway, a credential, a cloud app, even a vendor update — can ripple quickly into appointment flow, diagnostic accuracy, and patient communication.
To pressure‑test your clinic’s vulnerability, ask yourself: “Could I or everyone in my team explain our practice’s cyber governance approach in 60 seconds?”
2. Governance
Governance is often the most confusing area. But good governance doesn’t require big budgets — it requires clarity. It becomes very clear when using a role‑based model. When roles are explicit, clinical teams stop guessing. That reduces friction and raises confidence. The result is consistency — the core of good governance.
a) Clinicians— Data stewardship in daily practice: accurate entry, appropriate sharing, and early reporting of incidents or near‑misses.
b) Practice Managers— Vendor due diligence, onboarding/off‑boarding, access controls, training cadence, and operational checks.
c) Owners/Directors— Oversight and risk acceptance; ensuring APP and NDB obligations are met; approving governance decisions; endorsing incident response plans and insurance.
d) Vendors & Technology Partners— Controls, patching, monitoring, vulnerability management, and documented compliance evidence.
3. Culture
Think of culture as a protective control. The shift happens when people understand why digital safety helps patients — not just what the policy says. When teams see the patient benefit, behaviours change faster — and they stick.
Conclusion
Technology is a great enabler. In every era of healthcare, progress in science and technology (now coming from outside the medical field) has helped save patients’ lives and improve the quality of life for patients and healthcare providers.
Today, the amazing advancements in technology pose a serious and constant cybersecurity threat to both and it is our duty to work together to build cyber-resilience.
As much as I would like to say that we have the technology to prevent any threat, I can only repeat the famous words, often attributed to the legendary Peter Drucker, “culture eats strategy for breakfast”.
If you want to discuss how this can work for your organisation, please reach out to me and my team.
Jim Kay>
Jim Kay can address your upcoming industry event or a Board Meeting