Healthcare organizations are increasingly preparing for the inevitability of cyberattacks, but many still fall short in foundational areas such as asset and third-party risk management, according to an April 11 report from KLAS Research.
The Healthcare Cybersecurity Benchmarking Study 2025, a joint effort by KLAS, Censinet and the American Hospital Association, surveyed 69 healthcare and payer organizations. While many of these organizations demonstrate strong incident response capabilities, gaps remain in identifying and managing risks—especially those related to vendors and connected devices.
Here are four key findings from the report:
- Supply chain risk and asset management still lag. For the third consecutive year, these areas reported the lowest coverage—just 53% and 52%, respectively—under the NIST Cybersecurity Framework 2.0 (CSF 2.0), despite being critical in preventing third-party breaches.
- Proactive vs. reactive postures. Functions like “Respond” and “Recover” scored highest, reflecting strong preparedness for breaches. However, the “Govern” and “Identify” categories—core to proactive risk management—saw the weakest implementation.
- NIST CSF 2.0 adoption pays off. Organizations using NIST CSF 2.0 as their primary framework experienced significantly lower increases in cybersecurity insurance premiums—3% on average—compared to 11% for those that did not.
- AI risk management is nascent. Only 13 organizations reported using the NIST AI Risk Management Framework. While AI adoption is increasing, governance and cross-functional accountability remain in their early stages.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.