If I had to boil this quarter down to one point, it’s this: peer health systems are getting better results when they assign one clear owner, review proof on a set schedule, and act on gaps fast. One stat says it well: when the CISO’s office owns medical device security risks, HICP coverage moves from 45% to 63%.

Here’s the short version for me:

  • Governance: peers are tightening accountability and using routine proof instead of ad hoc updates.
  • Vendor risk: teams are asking vendors for proof of response and recovery, not just security claims.
  • Incident readiness: ransomware and downtime playbooks are being updated based on drills and actual gaps.
  • AI risk: ownership is being split by risk type across security, clinical, legal, privacy, and procurement.
  • Supply chain: medical devices, service providers, and single points of failure are getting more attention.

This is not about adding more tools. It’s about showing who owns what, what proof exists, how often it gets reviewed, and what gets fixed next.

Quick comparison

Area What peers are doing now Main gap
Governance Clearer accountability and set review cadence Weak enterprise inventory in many systems
Vendor risk Tighter access reviews and shorter fix deadlines Limited visibility into AI inside vendor software
Incident readiness Playbooks updated from exercises and recovery checks Many programs still lean too much on response after the fact
AI risk Risk review split by domain before deployment Fragmented ownership and weak escalation in some programs
Supply chain More CISO oversight for devices and dependencies Lowest maturity area across NIST CSF categories

If I were using this benchmark, I’d focus first on the places where ownership is still blurry. That’s where work tends to stall.

Healthcare CISO Benchmark: Peer Program Gaps vs. Best Practices by Domain

Healthcare CISO Benchmark: Peer Program Gaps vs. Best Practices by Domain

Customer Conversations: The Healthcare Cybersecurity Benchmarking Study

1. Governance

Governance is the first place stronger programs are tightening up. Why? Because ownership decides whether the rest of the controls hold up or fall apart.

This quarter, the biggest gap is ownership. Peer health systems are moving away from informal handoffs and toward clear accountability across the CISO's office, clinical operations, legal, compliance, and business leadership.

Ownership

Medical device security is the clearest example. Health systems where the CISO's office is responsible for medical device security are seeing higher HICP coverage. When the CISO's office owns medical device security, HICP coverage rises from 45% to 63% [1].

That’s a big shift. It shows that when one group clearly owns the work, progress is less likely to stall in the handoff between teams.

Evidence

Stronger programs are also bringing better proof into governance reviews. That includes dashboards, control attestations, exception logs, and asset and identity risk data.

Instead of pulling this information together only when someone asks for it, teams are now reviewing it on a regular schedule. In plain terms, governance is becoming more about routine proof and less about ad hoc reporting.

Cadence and Action

AI governance needs shared ownership across clinical, legal, compliance, privacy, and business leaders. That makes sense. AI touches patient care, policy, data use, and business risk all at once.

At the same time, cybersecurity programs still perform better when the CISO owns the risk end to end [2]. Shared input matters, but clear final ownership still does the heavy lifting.

2. Third-Party and Vendor Risk

Third-party risk is still a weak point in healthcare. In fact, supply chain risk management ranks last across all 23 NIST CSF categories in healthcare [1]. That leaves a gap, and peers are moving on it this quarter with tighter vendor access reviews, stricter proof requirements, and shorter deadlines to fix issues.

Ownership

That same ownership pattern now shows up in vendor risk. When the CISO has clear accountability, vendor-risk decisions tend to move faster. Procurement, legal, and privacy still have their part to play, but someone needs to steer.

Evidence

Peers now want proof that vendors can respond and recover, not just promises about stopping breaches. That usually means asking for:

  • Incident reporting commitments
  • Ransomware response documentation
  • Subcontractor disclosures

Response and recovery are the strongest maturity areas across health systems [2].

Cadence and Action

More mature third-party risk programs are tied to lower annual cyber insurance premium increases [1]. That's a board-level case for putting money and attention into supply chain cybersecurity risk management discipline now, not later.

"The healthcare industry currently is better positioned to respond to security incidents versus identifying (and mitigating) cyber threats before they become incidents." - Ed Gaudet, CEO and Founder, Censinet [1]

Peers are also closing that gap with tighter vendor access reviews and shorter remediation deadlines for high-risk vendors.

3. Incident Readiness

Peer health systems now treat breach response and recovery as a normal part of operations, especially when third parties are in the mix.

Ownership

Peers are putting incident readiness under the CISO, especially for medical devices [1]. That setup helps teams move faster during a crisis. It’s not just about who has the title. It’s about who owns the call when time is tight and decisions can’t wait.

Evidence and Action

Stronger programs do more than run tabletop exercises and file the notes away. They use what they learn to revise ransomware playbooks, update escalation paths, and check whether backup recovery timelines hold up in practice. Asset management is still a stubborn gap [2].

Peers making progress here treat asset and identity visibility as readiness data, not just a list of what they own.

That same mindset is now showing up in AI governance, where peers are putting guardrails in place before adoption moves ahead of control.

4. AI Risk

The push for tighter guardrails has now reached AI too. But there’s a key difference: ownership doesn’t sit with one team. This quarter, peer health systems are splitting AI oversight by risk domain instead of handing it all to a single office.

Ownership

The big shift this quarter is simple: ownership now follows the type of risk. There isn’t one AI gatekeeper. And that makes sense. AI risk doesn’t stop at security. It also touches patient safety, bias, transparency, and consent. So now clinical, legal, privacy, and procurement leaders are all part of the job.

Those risks are now divided across these functions:

Accountability Area Primary Owner(s) Key Focus This Quarter
Clinical Risk Clinical Leadership / CMO Patient safety, clinical workflow, and diagnostic bias
Security Risk CISO / IT Security AI system security, model integrity, and data protection
Legal & Ethics Legal / Compliance Transparency, algorithmic bias, and regulatory alignment
Privacy Risk Privacy Officer Data de-identification and patient consent for model training
Vendor/Supply Chain Procurement / CISO Detecting third-party AI risk in vendor software and unsanctioned AI use

Action

Peer programs are now splitting AI review by risk area and adding AI checks to intake and procurement workflows before deployment. They’re also bringing clinical stakeholders into AI review before deployment, not after.

That same level of scrutiny now applies to vendor tools too. AI can show up embedded in software before anyone has formally approved it. And that matters, because supplier software is now a common path for embedded AI.

5. Supply Chain Controls

Supply chain risk still sits at the bottom across healthcare’s 23 NIST CSF 2.0 categories, and CSF 2.0 now puts it under Govern. That shift is changing how peer health systems handle it. They’re treating device, supplier, and service dependency mapping as a supply-chain control, not just something procurement handles.

Ownership

This quarter, accountability is moving into the CISO’s office.

"When the CISO's office owned responsibility for medical device security, HICP coverage increased from 45% with no ownership to 63% with complete ownership." - Ed Gaudet, CEO and Founder, Censinet [1]

That’s an 18-percentage-point jump in HICP coverage.

Cadence and Action

Peer programs are taking the same review process used for vendors and AI and applying it to connected devices and critical service providers too. In plain terms, they’re doing a few things:

Why does that matter? Because concentration risk now hits recovery planning, not just contract review. The 2024 Change Healthcare breach showed how fast third- and fourth-party concentration can ripple through operations [2].

What Stronger Programs Have in Common

Across the five areas above, the same pattern keeps showing up. Stronger programs assign clear owners, review work on a set cadence, and connect evidence to action. None of that is new. The gap is that stronger teams have made it part of everyday work, not something they scramble to do after a problem hits.

They’re also pushing ownership upstream, before an incident forces the issue.

Staffing gaps, split clinical-IT setups, and too many competing demands still slow teams down. Some health systems deal with that by handing off routine tasks to managed services while keeping risk calls in-house.

That’s the key difference. It’s not just what control is in place. It’s how often that control is owned, checked, and acted on. Side by side, the pattern is hard to miss:

Domain Near-Term Benchmark Main Barriers
Governance Centralized accountability; 70% have formal committees [1] Only 30% have enterprise-wide inventory [1]
Vendor Risk Mature third-party programs linked to lower annual cyber insurance premium increases [1] Many still cannot detect embedded AI in vendor software [2]
Incident Readiness Best-tested area, but still mostly reactive [2] Does not stop the initial breach [1]
AI Risk In-house teams show stronger risk mapping and measurement [2] 38% have fragmented ownership or no clear escalation paths [1]
Supply Chain Identified as a top priority for board-level reporting [2] Lowest maturity area across all 23 NIST CSF categories [1][2]

Use this as the final benchmark: when ownership is clear and evidence shows up as part of routine work, controls move faster. That sets up the next question: which controls are already up and running, and which ones still rely on manual effort?

Conclusion

The gap this quarter comes down to ownership, cadence, and proof that work is happening - not how many tools you have.

One number is worth keeping front and center: when the CISO's office owns medical device security, HICP coverage rises from 45% to 63% [1].

Use the worksheet below as a fast self-check. Compare your program with peer practice and set priorities for next quarter. For now, record the current state only.

Domain Current State Peer Move Evidence Required Owner Next Step
Governance Formal committee and cadence Centralizing accountability under CISO with documented decision cadence Documented accountability and decision cadence CISO / Risk Committee Chair Confirm accountability and decision cadence
Vendor Risk Scheduled third-party reviews Set review cadence and close remediation items Vendor assessment completion rate and remediation log Third-Party Risk Lead Close open remediation items
Incident Readiness Balance response with Govern and Identify Shifting focus to NIST CSF 2.0 "Govern" function [2] Tabletop exercise results for AI-specific outages Incident Response Lead Conduct AI-specific incident readiness drill
AI Risk Formal AI governance policy Splitting AI review by risk area and adding AI checks to intake and procurement workflows AI inventory and escalation path documentation CISO / AI Risk Owner Assign a named owner for AI risk decisions
Supply Chain Supply chain maturity and remediation follow-through Consolidating medical device security under CISO ownership [1] Supply Chain Risk Management (SCRM) policy Supply Chain / CISO Integrate security evidence into procurement decision cycles

FAQs

How do we decide who should own each risk area?

Ownership should match the type of risk.

For more familiar cybersecurity work, like medical device security, the CISO office is often the right owner. AI risk is different. It usually works better with cross-functional ownership because it cuts across data bias, clinical workflows, and ethics.

No matter who owns it, accountability needs to be spelled out. That means clear escalation paths and cross-functional governance committees.

What proof should we review every quarter?

Review findings from incident response drills, along with checks on third-party vendor risks, high-risk device exposure, and remediation status.

These quarterly reviews help spot immediate gaps and keep cybersecurity and AI governance in step with shifting threats and peer benchmarks.

Where should we start if ownership is still unclear?

Start by putting responsibility in the CISO’s office. Research ties full CISO program ownership to stronger cybersecurity maturity, including higher use of Health Industry Cybersecurity Practices for medical device security.

If roles are split or unclear, set clear escalation paths and formalize governance. Peer benchmarking can help you spot gaps and back this shift with leadership.

Related Blog Posts