Epic’s security chief says ‘patch faster.’ Can health systems keep up?

Advertisement

When Epic’s top security executive said health systems need to “get ready to patch, patch, patch,” the leaders responsible for applying those fixes largely agreed. Their caveat: Moving faster depends on knowing sooner what needs fixing and which fixes can’t wait.

Epic Chief Security Officer Stirling Martin made the comments to The New York Times in a Sept. 30 story after the EHR vendor used Anthropic’s Claude Mythos AI model to find configuration flaws that could let someone view patient records without the access appearing in an audit trail.

“As soon as they think they are patching fast enough, they need to patch faster,” Mr. Martin told the Times.

For some health system technology and security leaders, it’s already the norm.

Luis Taveras, PhD, executive vice president and chief digital and information officer of Philadelphia-based Jefferson Health, said his organization now patches daily and, in some cases, multiple times a day, depending on the severity of a threat. He cited operational complexity, legacy systems, testing requirements and the need to keep clinical care running as the main obstacles, but said the risk of delaying critical security updates now often outweighs the disruption of making rapid changes.

“Traditional patching strategies that were developed decades ago are no longer sufficient in an era where AI is accelerating the discovery and exploitation of vulnerabilities,” Dr. Taveras told Becker’s.

Matt Morton, assistant vice president and chief information security officer at the University of Chicago, said his organization has moved toward a goal of remediating high-risk vulnerabilities within seven days, with critical vulnerabilities handled even faster when there is evidence of active exploitation. AI has shrunk the time between a vulnerability’s disclosure and its use in attacks from days or weeks to potentially hours in some cases, he said, making a monthly patching rhythm insufficient for many systems.

Others drew a firmer line around what faster patching can cost a hospital.

“I agree with the direction behind ‘patch faster,’ but speed alone is not the objective,” said Dennis Leber, PhD, senior director and chief information security officer of Chattanooga, Tenn.-based Erlanger Health. “In healthcare, the objective is to reduce the window of exposure without creating a new patient-safety or operational risk in the process.”

Dr. Leber said Erlanger has been shifting from traditional patch management toward vulnerability management that weighs exploitability, exposure, asset criticality and patient impact. An actively exploited or internet-facing vulnerability should move immediately, he said, while lower-risk issues can follow a disciplined cadence. When an immediate patch isn’t operationally safe, compensating controls and formal risk acceptance should bridge the gap.

“Patient safety is the boundary condition,” he said. “We cannot improve security by introducing an avoidable clinical outage.”

Jack Kufahl, chief information security officer at Ann Arbor-based Michigan Medicine, said the push to patch faster is “as real as it gets,” but that the downtime that comes with it will increasingly reflect what health systems have invested in resiliency. Testing patches before deploying them helps limit unexpected downtime, he said, and redundant systems let organizations stage patches.

“Highly redundant environments can help reduce downtime by staging patching, but often these are available on only the most precious of digital solutions,” Mr. Kufahl said.

Even organizations that can afford that redundancy often take on added complexity, which can cause problems of its own, he said.

The leaders’ most pointed comments were aimed back at Epic and other vendors: Tell health systems sooner, and tell them more.

“As soon as a credible threat or vulnerability is identified, healthcare organizations should be informed, even if a patch is not yet available,” Dr. Taveras said. “Early notification enables us to increase monitoring, implement compensating controls, and heighten vigilance across our environments.”

Mr. Kufahl said the alerts his team receives often don’t carry enough detail to tell which patches require immediate, disruptive action and which can wait for regular patch cycles.

“We often get a precursory and vague warning about critical system zero days but little contextual information,” he said. “We spend a lot of time determining, on partial information, which is which.”

He added that vendors have often been reluctant to let health systems penetration-test their own configurations, either offering no avenue for support or imposing contractual limits.

Dr. Leber’s wish list for vendors included clear exploitability information, precise guidance on affected versions, tested rollback procedures, low- or no-downtime deployment options and machine-readable advisories that feed into health systems’ vulnerability and change-management workflows. As AI speeds up the discovery of flaws, he said, defenders should use AI and automation to speed up their response as well.

Patching, he said, “can no longer be treated as a monthly maintenance exercise” and is becoming a continuous risk-management function.

“The organizations that succeed will not simply patch everything faster; they will get much faster at deciding what matters, acting safely, and verifying that the risk is actually gone,” Dr. Leber said.

Advertisement

Next Up in EHRs / Interoperability

Advertisement