Hospitals have trouble disconnecting from breached IT vendors and AI platforms, compromising their cybersecurity, Black Book Market Research found.
Here are seven things to know from the Nov. 24 report that surveyed 250 hospital and health system executives and 109 chief information security officers and other senior cybersecurity leaders:
1. Only 11% of hospitals have a tested vendor kill switch.
2. 63% of CISOs say they lack a tabletop-tested runbook for isolating a compromised supplier.
3. Median time to fully cut off a compromised vendor is 12 hours.
4. Only 27% can revoke all third-party identities/tokens within 60 minutes; 24% take more than 8 hours.
5. 68% have not assessed the cyber readiness of their top 10 vendors in the past year.
6. 61% lack enforceable service level agreements for rapid third-party notification and response.
7. 58% of CISOs expect vendor-originated incidents to increase in 2026.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.