Webinar

Healthcare IT Risk Management

Balancing Security Without Disrupting Care

Join the conversation to explore strategies and tools for managing the often competing needs of security, compliance, and operational excellence in healthcare IT environments.

Practical Lessons From One of the Country's Leading Academic Medical Centers

Healthcare IT teams rarely struggle because they don't understand cyber risk. They struggle because every security decision competes with clinical operations.

In this 45-minute webinar, we sit down with Michael Meis, Associate CISO of the University of Kansas Health System, to discuss how healthcare organizations define acceptable risk, manage technical debt, and strengthen cybersecurity without introducing operational disruption.

Brought to you by:

The CISO's Approach to Acceptable Risk:

Join the conversation to learn how to:

  • Define acceptable cyber risk without lowering your standards
  • Prevent technical debt from becoming a security problem
  • Aggressively pursue hardening projects without risking operational disruption
  • Build a scalable approach to risk minimization that evolves with and supports the organization's needs
Speakers:
Michael Meis
Michael Meis
Associate CISO  | University of Kansas Health System
David Rummage
David Rummage
Strategic Accounts  | Remedio

What is healthcare IT risk management?

Healthcare IT risk management is the practice of identifying, prioritizing, and reducing cyber risks while ensuring clinical systems remain available, reliable, and compliant.

Why is balancing security and clinical operations so difficult?

Healthcare environments depend on thousands of interconnected systems supporting patient care. Security improvements that introduce downtime or operational disruption can directly affect clinical workflows.

What is acceptable cyber risk?

Acceptable risk is the level of cyber exposure an organization consciously chooses to tolerate after weighing operational requirements, patient safety, regulatory obligations, and available mitigation options.

Why does technical debt increase cyber risk?

Legacy systems, inherited infrastructure, and deferred upgrades create security gaps that accumulate over time, increasing operational complexity and making remediation more difficult.

How can healthcare organizations improve cybersecurity without disrupting operations?

Successful organizations continuously prioritize risk, validate remediation before deployment, and introduce security improvements in ways that minimize operational impact.

Why is accountability important for healthcare cybersecurity?

Clear ownership ensures identified risks are evaluated, prioritized, and remediated instead of remaining unresolved across multiple teams.