Healthcare IT Staffing & Cybersecurity: Lessons from ViVE 2026 | HealthTech Magazine

Los Angeles, CA – The healthcare industry convened at the ViVE 2026 conference this week to address increasingly critical challenges in cybersecurity and operational resilience. Discussions centered on the need for proactive strategies, particularly for resource-constrained organizations, and the importance of shared learning from recent cyber incidents. The event highlighted a growing recognition that robust IT infrastructure and skilled personnel are no longer simply advantageous, but essential for maintaining patient safety and delivering quality care. Strengthening healthcare security is paramount as systems become more interconnected and vulnerable to evolving threats.

The pressures facing healthcare IT departments are multifaceted. Beyond the constant threat of ransomware and data breaches, organizations are grappling with workforce shortages, budgetary constraints, and the complexities of navigating evolving regulations, such as updates to the Health Insurance Portability and Accountability Act (HIPAA). These challenges are particularly acute in rural communities, where attracting and retaining qualified IT professionals can be exceptionally demanding. The conference underscored the need for innovative solutions and collaborative approaches to mitigate these risks and ensure the continuity of care.

The Strain on Rural Healthcare IT Teams

A key theme emerging from ViVE 2026 was the unique difficulties faced by smaller, rural healthcare facilities. During a session focused on IT teams in these settings, leaders shared strategies for maximizing limited resources and building resilient systems. Scott McEachern, CIO at Southern Coos Hospital and Health Center in Bandon, Oregon, described the importance of upskilling existing staff and creating redundancy in skill sets. Southern Coos Hospital, serving a rural population on the Oregon coast, operates with a lean IT team of just four members, supported by two clinical informaticists. Southern Coos Hospital and Health Center’s approach involves cross-training personnel to handle a wider range of IT tasks, effectively creating “mini-system admins.” McEachern emphasized the need for leadership to “walk the talk,” noting that he has been shadowing at the help desk to better understand the challenges faced by his team and reinforce the value of continuous learning.

Recruitment remains a significant hurdle, particularly in rural areas. Linda Stevenson, chief digital information officer at Fisher-Titus Medical Center in Norwalk, Ohio, highlighted the importance of emphasizing an organization’s mission and culture to attract potential candidates. Fisher-Titus Medical Center, serving a community in northern Ohio, has found success in partnering with local high schools, universities, and community colleges to build a pipeline of IT talent. However, Stevenson acknowledged the challenge of retaining younger employees who may seek more rapid career advancement opportunities elsewhere. “Culture is probably the No. 1 thing to think about,” she stated, emphasizing the importance of fostering a sense of community and purpose within the organization.

Learning from Cyberattacks: A Collaborative Approach

Beyond workforce challenges, ViVE 2026 placed significant emphasis on cybersecurity preparedness and response. A session dedicated to cyber resilience brought together IT and security leaders to share lessons learned from recent incidents. Moderator Anika Gardenhire, now the first chief digital and information officer at Michigan Medicine, drew upon her experience at Ardent Health, where she served as chief digital and transformation officer during a 2023 ransomware attack that disrupted services across the organization on Thanksgiving Day. Michigan Medicine’s Gardenhire described a “cures and consequences” approach to incident response, where IT teams focused on restoring systems (“cures”) while other departments managed the operational and clinical implications (“consequences”). This collaborative framework proved crucial in maintaining patient care during a critical period.

Nate Couture, CISO at the University of Vermont Health Network, shared insights from his organization’s 2020 ransomware attack. University of Vermont Health Network experienced four weeks of IT system outages, but was able to avoid halting patient care due to extensive preparation. Couture noted that their existing emergency management plans, designed for short-term outages or mass casualty events, were not ideally suited to address the complexities of a prolonged ransomware attack. However, the pre-existing relationships built through those planning exercises proved invaluable in navigating the crisis. “We leaned into those relationships, and through that, we were able to get through it,” he explained.

These shared experiences underscore a critical point: cybersecurity is not solely an IT issue, but a shared responsibility requiring collaboration across all departments within a healthcare organization. Effective incident response requires clear communication, well-defined roles, and a willingness to adapt to unforeseen circumstances.

The Evolving Threat Landscape and AI

The discussions at ViVE 2026 likewise acknowledged the rapidly evolving threat landscape, particularly the increasing sophistication of ransomware attacks and the emergence of artificial intelligence (AI) as both a potential tool for cybersecurity and a new avenue for malicious activity. Experts warned that AI-powered attacks could be more targeted, more difficult to detect, and more capable of evading traditional security measures. CDW reports that healthcare organizations must invest in new cybersecurity measures to counter these emerging AI-driven threats. This necessitates a proactive approach to threat intelligence, vulnerability management, and employee training.

the conference addressed the ongoing need to navigate changes linked to HIPAA updates. Staying compliant with evolving privacy and security regulations is a constant challenge for healthcare organizations, requiring ongoing investment in training, technology, and policy development. HealthTech Magazine provides further insights into navigating these complex regulatory requirements.

The Importance of IT Cost Optimization

Alongside security concerns, ViVE 2026 also featured discussions on optimizing IT costs within healthcare organizations. Clearsense is scheduled to present a case study session on this topic, demonstrating strategies for reducing expenses without compromising quality or security. This is particularly relevant in the current economic climate, where many healthcare systems are facing budgetary pressures. Effective IT cost optimization requires a data-driven approach, identifying areas of waste and inefficiency, and leveraging technology to streamline operations.

The conference highlighted the potential of cloud computing, automation, and data analytics to drive down costs and improve efficiency. However, it also cautioned against adopting new technologies without careful consideration of security implications and potential integration challenges.

Key Takeaways:

  • Collaboration is Crucial: Sharing experiences and best practices among healthcare organizations is essential for improving cybersecurity resilience.
  • Rural Healthcare Faces Unique Challenges: Resource-constrained organizations require tailored strategies for workforce development and security preparedness.
  • AI Presents Both Opportunities and Threats: Healthcare organizations must proactively address the cybersecurity implications of artificial intelligence.
  • Proactive Planning is Paramount: Investing in robust incident response plans and regular security assessments is critical for mitigating risk.

Looking ahead, the healthcare industry must continue to prioritize cybersecurity and operational resilience. The ongoing evolution of threats, coupled with the increasing reliance on technology, demands a proactive and collaborative approach. The next major checkpoint for HIPAA updates is scheduled for review in late 2026, with potential changes impacting data privacy and security protocols. Continued vigilance and investment in these areas are essential for protecting patient data and ensuring the delivery of safe, effective care.

What strategies is your organization implementing to address these challenges? Share your thoughts and experiences in the comments below. And please, share this article with your colleagues to help raise awareness of these critical issues.

Leave a Comment