Trump AI order could narrow rural hospital cybersecurity gap, CIOs say

Advertisement

President Trump’s June 2 executive order to expand AI-enabled cybersecurity tools to rural hospitals could help narrow a longstanding imbalance in healthcare cybersecurity, according to two health system CIOs who say smaller organizations face the same threats as larger systems with far fewer resources.

The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” directs the Homeland Security secretary to issue binding directives within 30 days expanding AI-powered cyber defenses across civilian federal systems and extending those tools to state and local governments, rural hospitals, community banks and other critical infrastructure operators.

A separate provision establishes a voluntary AI cybersecurity clearinghouse to coordinate vulnerability scanning and patch distribution across participating organizations.

The resource gap is well documented. As of 2025, 59% of small hospitals lacked 24/7 threat monitoring or a dedicated security operations center, relying instead on general IT staff, according to Black Book Research. The same research found 16% of small and rural hospitals were planning to postpone cybersecurity expenditures due to Medicaid funding cuts — this at a moment when healthcare had become the most-targeted critical infrastructure industry by hackers and when cyberattacks tend to be more disruptive for rural facilities than for larger systems.

Muhammad Siddiqui, CIO of Reid Health in Richmond, Ind., said the explicit inclusion of rural hospitals was not a small gesture.

“Small and regional health systems have the same threat exposure as large academic medical centers but a fraction of the security resources,” Mr. Siddiqui told Becker’s. “That gap has been visible for years.”

Rick Leesmann, CIO of Sky Lakes Medical Center in Klamath Falls, Ore., put it more directly.

“Rural health systems don’t get a different version of the threat landscape and we never have,” Mr. Leesmann told Becker’s. “We face the same adversaries, the same sophistication, the same stakes as any major healthcare organization, with fundamentally different resources.”

Both CIOs said the order’s significance lies less in what it creates than in what it acknowledges. For years, rural and regional health systems have operated in a threat environment built around the capabilities of large, well-resourced organizations.

Mr. Siddiqui said the provision he is watching most closely is the 30-day binding directive from CISA, which would direct agencies to establish or expand AI-enabled defensive tools and facilitate access for critical infrastructure operators.

“If that translates into real services we can actually use, it changes the economics of healthcare cybersecurity for systems like Reid,” he said. “If it produces another framework document, it does not.”

He said the voluntary clearinghouse for vulnerability scanning and patch coordination also addresses a tangible gap.

“Smaller health systems do not have the threat intelligence pipeline that large systems build through vendor contracts and dedicated SOC teams,” Mr. Siddiqui said. “A centralized clearinghouse, if it works as described, fills a real gap.”

The June 2 order builds on a June 2025 executive order that strengthened national cybersecurity defenses and expanded the use of AI to detect software vulnerabilities. It also follows the White House AI Action Plan released in July 2025, which called for the Department of Homeland Security to launch an AI Information Sharing and Analysis Center to help healthcare and other critical infrastructure sectors defend against AI-driven cyber threats.

Among the order’s other provisions, the Treasury secretary has 30 days to stand up the voluntary AI cybersecurity clearinghouse with the private sector; senior officials from Treasury, the NSA and CISA have 60 days to build a classified process for identifying the most advanced AI systems, which the order designates as “covered frontier models”; and the Office of Personnel Management has 60 days to expand cybersecurity hiring pathways through the U.S. Tech Force. The order also bars the government from using that framework to impose mandatory licensing or permitting requirements on AI developers.

Mr. Leesmann said Sky Lakes has been building its AI governance posture and cybersecurity infrastructure deliberately and that the order does not change the organization’s direction or roadmap. But he said the most important outcome it could drive is harder to measure than any single tool or program.

“It’s the conversation it forces about what it actually costs to defend a rural hospital in 2026,” Mr. Leesmann said. “Awareness drives investment. If this order moves that needle, equitable adoption opportunities stop being an aspiration.”

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Artificial Intelligence

Advertisement