Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Mike Donahue,
Chief Delivery Officer, CloudWave
As the
healthcare industry continues to navigate increasingly complex technology
infrastructure requirements, 2025 promises to be a transformative year for
cybersecurity, cloud adoption, and regulatory shifts. The growing threat of
cyberattacks, coupled with evolving patient care needs and stringent regulatory
requirements, demands a proactive and patient-centric approach to healthcare
IT. From shifting cybersecurity accountability to embracing artificial intelligence
and public cloud solutions, healthcare organizations must prioritize
innovation, collaboration, and resilience to stay ahead of emerging challenges.
The Landscape of
Cybersecurity Accountability in Healthcare is Shifting
As healthcare organizations face a growing litany of
cybersecurity issues, a trend is emerging to place greater responsibility directly
on executives for their actions. This
shift is driven by increasing attacks, related litigation, and proposed
regulations such as The Department of Health and
Human Services (HHS) Health Infrastructure Security and Accountability Act.
The proposed bill
includes requirements for HHS to proactively audit the cybersecurity practices
of at least 20 regulated entities annually and gives HHS the authority to levy
fines. It contains
provisions that hold healthcare executives legally accountable for their
organization’s cybersecurity practices, requiring leaders to certify
their institutions’ compliance with the new minimum standards on a yearly
basis. Those who
misreport their organization’s cybersecurity status may face jail time, marking
a significant escalation in executive accountability.
I believe
this will lead executives to increasingly adopt proactive measures and foster an
enterprise-wide culture of security awareness to help more effectively
safeguard their organizations and uphold accountability in the face of growing
cyber threats.
Hospitals
will Adopt a Patient-First Cybersecurity Approach
As healthcare
cybersecurity threats evolve, a patient-first cybersecurity approach will
become increasingly important in 2025. This involves a strategy shift from IT-centric
to patient-centric cybersecurity practices that focus on mitigating the impact
of cyberattacks on patient care rather than just protecting data. To be
successful, this must entail a more holistic and people-focused approach
over traditional methods, regulations, and frameworks and require collaboration between
IT, clinical, and executive teams.
This
multi-departmental approach helps address the gap between prioritizing patient
impacts versus the data in an attack response. For example, one area that is
evolving to address this is tabletop simulations that test a team’s response to
an attack in a real-world simulation. Tabletops that expand beyond the
traditional IT focus to include executive and clinical teams are becoming more
common. This type of exercise gives a broad organizational view for everyone
involved to better understand the widespread impact of a cyber event and its
unique role in response, including what happens during prolonged downtime.
By
prioritizing patient safety and well-being, healthcare organizations can better
protect themselves against cyber threats and ensure continuity of care.
Preparing
for the Inevitable: The Shift from Detection to Prevention in Healthcare
Cybersecurity
The
healthcare industry is on the threshold of a significant shift in its approach
to cybersecurity. For years, healthcare cyber strategies have been primarily
focused on threat detection, with a checklist approach to meeting regulatory
requirements. However, this reactive approach has proven ineffective in
preventing cyberattacks, particularly ransomware attacks that have increasingly
devastated healthcare organizations. It centers on responding to attacks rather
than measures to prevent them.
In
2025, I expect to see a more proactive approach to cybersecurity that
emphasizes prevention, response, and detection. This will involve using
advanced technologies such as artificial intelligence (AI) and security
orchestration, automation, and response (SOAR). It will also embody the
“red teaming” concept, a proactive approach to cybersecurity that
involves simulating cyberattacks to test an organization’s defenses. By
identifying vulnerabilities and testing responses, healthcare organizations can
refine their technical capabilities and playbooks, enabling them to take more
immediate action to stop cyberattacks.
In
addition to proactive prevention, healthcare organizations must prepare for the
worst-case scenario – a successful cyberattack. This involves developing
incident response plans and conducting tabletop exercises that better educate
clinical teams on responding to a cyberattack by answering questions such as
what happens when critical patient care systems such as the EHR go down? These
exercises also enable organizations to identify gaps in their response plans to
ensure that the entire healthcare ecosystem can continue to operate with a
focus on patient care in the face of a cyberattack. This includes functional
areas such as supply chain management, clinical operations, financial
operations, and IT operations working together in an incident response.
Cyber
liability insurance providers will also increasingly require healthcare
organizations to demonstrate evidence of proactive measures to prevent
cyberattacks, further emphasizing the importance of this approach.
Supply
Chain Attacks in Healthcare Will be a Growing Threat in
2025
While
ransomware attacks dominate healthcare discussions, supply chain attacks pose
an equally significant and growing threat. Any organization that healthcare
providers depend on for supplies, services, software, or hardware can be a
potential supply chain risk. The consequences of a supply chain attack can be
severe, with disruptions to operational continuity, patient care, and even
financial stability.
According
to recent data, there has been a triple-digit year-over-year increase in supply
chain attacks impacting healthcare operations. Despite this growing threat,
only a small percentage have documented steps to prevent and respond to a
supply chain attack. Supply chain attacks will continue to rise in frequency
and severity, with more healthcare organizations falling victim to them.
To
address these challenges, healthcare organizations must consider the broader
supply chain ecosystem beyond their internal IT departments and develop
comprehensive incident response plans that involve the entire organization.
Healthcare organizations will invest more in supply chain security by implementing
advanced security measures, utilizing third-party risk management platforms,
conducting regular risk assessments, taking proactive steps to mitigate risks,
and ultimately ensuring the continuity of patient care.
Broader
Adoption of Targeted Use Cases for AI in Healthcare
As AI
technology continues to evolve beyond early generative AI applications, I
expect to see broader adoption of industry-focused, targeted use cases for AI
in healthcare in 2025. These will include tools that enhance decision-making,
improve operational efficiency, and deliver better care and patient engagement.
Some of the key
use cases that are expected to gain traction include:
- Point solutions: AI-powered tools to help
hospitals and healthcare systems enhance their financial performance by
streamlining documentation, better preparing physicians to optimize visits,
decreasing documentation time, and reducing time-to-revenue. - Partner ecosystem applications:
Healthcare organizations increasingly adopt AI-powered solutions through
partnerships with electronic health record (EHR) vendors, such as
MEDITECH, Cerner, and Epic. - Ambient listening: AI-powered ambient listening
technology will improve clinical documentation and reduce administrative
burdens on physicians. This technology uses AI to capture and
summarize conversations between patients and physicians.
It translates the information directly into the medical record, increasing
the quality and the insights and decreasing provider documentation
requirements.
However,
several barriers in healthcare still must be addressed for broader adoption,
including security and privacy concerns, as well as regulatory and ethical
considerations. For example, in the case of ambient listening, a provider talking
to a patient generates protected health information (PHI). These are new assets
on a healthcare organization’s network and, unfortunately, create another
target sector for bad actors to go after.
Working
with partners that understand the complex healthcare ecosystem to secure and
optimize the network can help address these challenges so
healthcare organizations can focus on managing day-to-day operations, making
providers happier and more productive while improving patient outcomes,
enhancing operational efficiency, and reducing costs.
Increased
Regulatory Focus on Healthcare in 2025
There was a great
deal of government activity regarding cybersecurity in healthcare in 2024,
driven by growing concerns amid an increasingly volatile threat landscape. The
healthcare industry can expect a stronger regulatory focus to continue in 2025.
For example, at
the state level, all eyes are on New York’s recently approved cybersecurity
regulations to set a precedent. Expect more states to propose and enact similar
legislation. I also expect New York’s regulations to expand beyond hospitals to
include other healthcare organizations, such as clinics and medical groups.
Regarding
federal initiatives, The U.S. Department of Health and Human Services (HHS)
will likely provide more clarity and guidance on cybersecurity regulations,
including the “HPH Cybersecurity Performance Goals” issued in early
2024. Throughout 2025, healthcare organizations must prioritize investments in
cybersecurity measures and risk management strategies to maintain compliance.
A Resurgence
of Public Cloud Consumption in Healthcare
The cloud has
already revolutionized healthcare IT infrastructure, offering numerous benefits
that enhance the delivery of patient care. However, healthcare organizations
still face significant IT challenges in adopting the cloud, including growing technical
complexity, regulatory compliance, and security concerns. In 2025, as public
cloud providers continue to evolve to address security and compliance
challenges associated with managing sensitive healthcare data and offer more
robust healthcare-specific solutions, I expect to see a resurgence of public
cloud consumption in healthcare. Both “lift and shift” scenarios,
where existing applications are migrated to the cloud and newer technology
adoptions, will fuel this resurgence.
The lift and
shift strategy offers a less disruptive way for organizations to leverage cloud
benefits such as scalability, reduced maintenance, and cost optimization.
Meanwhile, cloud-native applications like artificial intelligence, telemedicine
platforms, genomics, and personalized medicine are becoming increasingly
popular.
One of the
primary advantages of public clouds in these scenarios is cost optimization, with
a pay-as-you-go pricing model that makes it an attractive option for many
hospitals facing budget constraints. However, concerns about data privacy,
compliance, and the complexity of migrating legacy systems persist. To overcome
these challenges, healthcare leaders must strike a delicate balance that
requires informed decision-making to optimize resources and align IT
investments with strategic objectives. Many healthcare organizations will opt
for a multi-cloud strategy to leverage the strengths of different cloud
providers, ensure vendor neutrality, and mitigate risks.
A managed cloud
services provider can help in this process by evaluating the best model and
location for workloads, including the public cloud, based on technology needs
with a focus on performance and latency, regulatory requirements, and cost. As
public cloud consumption grows, partnering with a managed cloud services
provider to leverage the expertise, infrastructure, and
economies of scale required to support healthcare IT offers a multitude
of additional benefits-allowing hospitals to focus more of their efforts on
patient care initiatives rather than the complexities of IT infrastructure.
As
healthcare organizations navigate the evolving cybersecurity, cloud, and regulatory
landscape in 2025, prioritizing proactive measures, collaboration, and
patient-centric approaches will be crucial to success. By investing in robust cybersecurity
and cloud solutions, healthcare leaders can safeguard their organizations,
enhance patient care, and drive growth.
##
ABOUT THE AUTHOR
Mike Donahue
leads a dynamic team dedicated to delivering innovative, secure healthcare IT
solutions that empower hospitals and healthcare systems to provide better
patient care. He manages CloudWave’s security and platform operations in
addition to advisory, technical, and consulting services, ensuring that customers’
technology environments are reliable and efficient and fortified against
emerging threats.






