I use cyber maturity scores as a planning tool - not proof that patient care is safer. Start with one critical service, such as medication administration, and check its exposure, tested controls, repair times, and recovery results.
The stakes go beyond your own systems. In a March 2024 American Hospital Association survey of nearly 1,000 hospitals, 74% reported direct patient-care impact from the Change Healthcare cyberattack.
Here’s what I would measure instead of relying on a score:
- Exposure: Which critical systems have high-risk weaknesses, and which haven’t been checked?
- Control performance: Can tested safeguards detect and stop attacks without disrupting care?
- Remediation: How long do high-risk findings stay open before fixes are verified?
- Recovery: Can systems and clinical workflows return safely within approved downtime and data-loss limits?
An approved policy is not a passed test. I would track these results by clinical service, give each gap an owner and deadline, and fund the fixes that protect care first.
The goal is <u>less risk and safer recovery</u> - not just a higher rating.
Healthcare Cyber Risk: What to Measure Beyond Maturity Scores
Why Maturity Scores Do Not Prove Lower Risk
Documented Processes Do Not Prove Controls Work
Policies and training show intent. Testing shows whether controls work. Healthcare framework guidance separates policy from implementation and testing.[8]
For access reviews, require reviewers to identify privileged accounts, tie each account to a current workforce or vendor role, verify business need, and confirm removal of unnecessary access. A signed review is not proof of revoked access.
Report unresolved exceptions and how long access removal takes. Then retest to confirm closure. This distinction matters most when enterprise reporting hides exposure in clinical systems.
Average Scores Can Hide Clinical System Weaknesses
Enterprise averages can hide weaknesses in EHRs, imaging, medical devices, identity systems, or vendor links. Use a separate critical-systems view to keep emergency-care exposure visible rather than burying it in an enterprise average.
Show which weaknesses could expose PHI, disrupt medication delivery, or delay diagnosis. Assign each finding an owner. HHS’s Healthcare and Public Health Cybersecurity Performance Goals emphasize high-impact practices - not equal effort across every activity.[4][7]
The consequences extend beyond a hospital’s own systems. In March 2024, an American Hospital Association survey of nearly 1,000 hospitals found that 74% reported direct patient-care impact from the Change Healthcare cyberattack, including delays in authorizations for medically necessary care.[9]
Visibility alone isn’t enough. The score also needs verified evidence.
Self-Assessments Can Miss Changing Threats
Self-assessments fall short when ratings depend on subjective judgments or outdated evidence. A score can look precise even when unverified answers don’t support it.[5] One reviewer may count an approved procedure as implemented; another may count it as merely documented.
Define the evidence required for each rating. Judge control presence and control effectiveness separately, and disclose the scope, validation date, and unresolved exceptions.
Periodic reviews also lose value when credentials are compromised, new vulnerabilities emerge, or vendor integrations and clinical technology change. Review again after these events rather than waiting for the next assessment cycle.
Unsupported medical devices and emergency-access needs call for tested safeguards. Don’t assume standard controls fit every system. HHS guidance calls for rapid action on prioritized findings from penetration testing and attack simulations.[4]
sbb-itb-535baee
Measure Exposure, Control Performance, and Remediation
Track Exposure Across Critical Clinical Systems
Track the share of critical clinical systems with at least one high-risk exposure: exploitable vulnerabilities, internet exposure, unsupported software, weak privileged access, unknown assets, or risky vendor connections. Report both the affected count and the total number of critical systems.
Check findings against asset inventories, vulnerability data, network records, and clinical dependency maps. Disclose which systems have unknown exposure. These measures show where maturity scores may hide clinical risk. Prioritize by the care affected - not vulnerability count alone. Use the findings to support replacing unsupported systems, restricting vendor access, or funding segmentation.[4][6] Then use exposure metrics to guide control testing.
Test Controls Against Realistic Attack Paths
Track control coverage separately from tested performance. Configuration records show what’s deployed; test records and security tickets show how well it works.
Measure phishing-resistant MFA coverage and telemetry coverage across critical systems. Then run authorized simulations and penetration tests to assess detection, containment time, and verified fixes. Define detection based on the attack behaviors tested. Measure containment from a validated alert to isolation or access revocation.[10][11][12]
Coordinate testing with clinical teams so it doesn’t disrupt care.
Test whether compromised vendor credentials can reach clinical applications or whether ransomware can cross into imaging infrastructure.
Record blocked paths, missed alerts, and failed containment. Identify which failures could disrupt care, then connect each gap to the work needed: missing telemetry supports monitoring investment, reachable clinical systems support segmentation, and slow containment supports staffing or response automation.
Results show tested performance, not breach probability.[6][7][14] Use failed tests to set remediation priorities.
Track Remediation Time by Risk Level
Start the remediation clock when a finding is validated. Stop it only after independent verification confirms the fix.
Report median and longest remediation time, the age of the oldest open critical finding, missed targets, and recurring vulnerabilities. Group results by exploitability, internet exposure, clinical criticality, and patient-care impact. Keep unresolved findings in the report until their closure has been independently verified.
Slow closure means risk remains active. It can point to a need for more patching capacity, faster clinical change approval, or vendor escalation.[4][6][10]
When patching could interrupt treatment, require tested compensating controls and an approved exception - not an open-ended delay. Record the system, vulnerability, clinical risk, owner, approver, target date, expiration date, verification method, and failure response.
Restricted access, segmentation, or removal of internet exposure may reduce immediate exposure while teams arrange a safe maintenance window.
Label these findings temporarily mitigated, not remediated.[11][13][14] Temporary fixes reduce exposure but don’t prove resilience. Use risks that remain open after mitigation to guide recovery testing.
Nexus Podcast: Healthcare Cybersecurity & Third-Party Risk with Greg Garcia on the SMART Toolkit
Test Recovery and Use Results to Guide Decisions
After remediation, check whether care can resume safely when systems fail.
Test Recovery Against Clinical Downtime Limits
Have clinical leaders set recovery time objectives (RTOs) and recovery point objectives (RPOs) for each critical service. Base these targets on safe downtime limits, with input from clinical, privacy, and IT teams.
Test backup restores, then compare actual recovery time and data loss with those targets. Include clinical workflows and third-party vendor dependencies in the tests.
A successful restore does not mean care can safely resume. Verify that restored systems support safe patient care. Test downtime procedures and the steps for returning to normal workflows. Require clinical sign-off before declaring recovery complete.
Set Action Thresholds, Owners, and Deadlines
Before setting escalation triggers, map each critical service to the applications, devices, vendors, and data it relies on.
Define triggers for failed restores and missed RTO/RPO targets. For each trigger, specify a named owner, a mitigation decision, a deadline, and who receives the escalation if that deadline is missed.
Report Risk Trends With Supporting Evidence
Build the risk report around test results. Report trends for each critical service instead of combining them into a single enterprise score. Show exposure, control-test results, remediation age, and recovery results together.
Attach dated evidence and disclose dependencies that have not been tested. Assessment closure is not proof of resilience. Use service-level trends and missed RTO/RPO targets to direct spending toward the specific constraints.
Conclusion: Use Maturity Models as Maps, Not Proof
After measuring exposure, control performance, remediation, and recovery, use maturity models as planning tools - not proof of lower clinical risk. They organize capabilities and show gaps. NIST’s Current and Target Profiles help leaders compare where they are with where they want to be and prioritize work. Evidence from day-to-day operations shows whether those changes reduce risk.[15][16]
Start with one critical clinical service.
For example, medication administration.
Establish a baseline for its exposed assets, control-test results, high-risk remediation times, and recovery performance. Use those measurements to distinguish activity from actual risk reduction.
Fund the weaknesses with the greatest impact first. For each proposed fix, state the expected risk reduction and the evidence needed to verify it. A higher score shows process progress only - unless exposure, control effectiveness, remediation, and recovery improve.
FAQs
How do we set realistic cyber risk targets?
Go beyond static compliance checklists. Set outcome-based goals tied to patient safety and your ability to keep services running during disruptions. Map framework requirements to attack paths your organization could face and the systems clinical care depends on. Then set measurable targets that match your organization’s risk appetite.
Track key risk indicators: MFA coverage, detection and reporting time, time to fix critical findings, and verified remediation plans for high-risk vendors. Assign an owner to each indicator, document its data sources, and review performance quarterly.
How can we test controls without disrupting care?
Go beyond paperwork and periodic audits. Test controls and verify them continuously. Use passive monitoring and simulated attacks to check that multi-factor authentication and logging work as intended.
For legacy medical devices that can’t be safely patched, focus on network segmentation and passive monitoring. Run tabletop exercises with IT and clinical staff to practice recovery and spot bottlenecks without affecting live systems.
How do we verify a vendor’s recovery readiness?
Go beyond signed agreements and paper records [1]. Require vendors to share their recovery expectations and dependencies on sub-tier partners [2]. Review their documented recovery procedures and recovery time targets for critical systems [1]. Also assess how they cooperate during incident reviews and the results of their breach response drills [2][3].
Track the percentage of high-risk vendors with verified remediation plans as a key measure of third-party resilience [1].