The security stack for healthcare
In healthcare, a security failure is not only a data problem, it is a care problem. When a clinic's systems go down to ransomware, appointments stop and records become unreachable, so the stakes sit closer to patient safety than to an IT inconvenience. On top of that, the data a provider holds is the most sensitive and most heavily regulated kind there is, and it is carried on an IT setup that is usually thinner than the risk deserves, with rotating clinical staff, shared devices, and rarely a dedicated security person.
That shapes the stack in a particular way. The general field guide maps the whole board for any company. Here it is reordered for a clinic, a hospital, or a health-tech company, with the parts that matter most spelled out underneath.
- In healthcare a security failure is a care problem: when systems go down to ransomware, appointments stop and records become unreachable, so the stakes sit close to patient safety.
- The highest-value moves are getting MFA onto accounts that reach patient data, replacing shared logins with individual ones, and making offboarding actually remove access for rotating clinical staff.
- In a recent access audit of a mid-sized healthcare client, the environment held 31 accounts with MFA on only 4 of them, under 13 percent; a shared reception account that several people used was a full Global Administrator with no MFA, and a leftover service account also carried Global Administrator rights.
- Patient data is special-category data under the GDPR, which means stricter handling and steeper consequences when it leaks; a tested, isolated backup is what stands between a ransomware attack and a genuine care crisis.
- Health is an essential sector under NIS2, so many providers inherit obligations around access control, MFA, incident handling, and management accountability, most of which the access and resilience work already covers.
- Clinicians have started using AI scribes and assistants that take patient information, so knowing what AI is in use and what patient data it touches is becoming a real part of the healthcare stack.
the priority order for a care setting
Access to clinical systems is critical: MFA on accounts that reach patient data, shared logins replaced, rotating staff offboarded fast. Patient data protection is critical: know where it lives and flows, encrypt it, and hold tested backups. Resilience and recovery are high: tested, isolated backups and a rehearsed incident plan, because ransomware is the sector's top threat. NIS2 obligations are high: access control, MFA, incident handling, management accountability. Email and people are high, because phishing is how most healthcare ransomware starts. AI in care is high and newly arrived, because AI scribes and assistants now handle patient data. Endpoints and medical devices, including shared, legacy and connected equipment, are the baseline.
the access problem, in real numbers
The pattern that shows up again and again in clinics is worth making concrete, because it is so common and so fixable. In a recent access audit of a mid-sized healthcare client, the environment held 31 accounts with multi-factor authentication on only 4 of them, under 13 percent. A shared reception account that several people used was also a full Global Administrator, with no MFA on it. A leftover service account also carried Global Administrator rights. None of this came from carelessness. It came from a busy clinical setting where access got added to keep things moving and nobody ever went back to clean it up.
That is the real shape of healthcare risk: not exotic, just ordinary access nobody closed, sitting on systems that happen to hold patient records. Clinical work means many people reaching the same systems, doctors, nurses, locums, reception, on shared devices and sometimes shared logins, with high turnover, which is exactly the recipe for access that sprawls and offboarding that slips. Getting MFA onto the accounts that reach patient data, replacing shared logins with individual ones where you can, and making offboarding actually remove access are the highest-value moves available.
protecting the data, and being able to restore it
The patient data itself is the crown jewel. It is special-category data under the GDPR, which means stricter handling and steeper consequences when it leaks, so knowing where it lives and flows, keeping it encrypted, and controlling how it is shared all matter. But the part to take most seriously is backup. A tested, isolated backup is what stands between a ransomware attack and a genuine care crisis, and healthcare is targeted heavily precisely because that disruption is so costly. A backup that has never been restored in a drill should be assumed not to work when it is needed, because that is the most common and most painful discovery during a real incident.
nis2 sits on top of the work you are already doing
Health is an essential sector under NIS2, so many providers fall in scope and inherit obligations around access control, multi-factor authentication, incident handling, and management accountability. The reassuring part is that the access and resilience work above is most of what NIS2 asks for on the technical side, so doing it well is also most of the compliance. As with any of these regimes, the harder half is usually making controls visible and evidenced rather than only present.
the phishing door, and the AI nobody mentioned
Most healthcare ransomware starts with a phishing email a stretched staff member clicks on a busy day, so email filtering and a light, practical awareness effort that fits clinical reality are worth the small effort, because they sit at the start of the chain that leads to the disruption providers most fear.
And there is a newer territory creeping in quietly. Clinicians have started using AI scribes and assistants that take patient information, and AI is moving into diagnostics and triage, which means special-category health data can flow into tools nobody approved. Knowing what AI is in use and what patient data it touches is becoming a real part of the healthcare stack rather than a future concern.
the devices, and the rest of the floor
Shared clinical devices, legacy systems that cannot be patched, and connected medical equipment are their own challenge and want someone who understands the clinical environment. Solid endpoint protection across devices is still the baseline, alongside the email and backup work above. These sit a little below the access and data layers because in a care setting the most common and most damaging exposure is in who can reach patient systems and whether the provider can keep running, though they still matter.
provider or health-tech
The order above fits a care provider directly. A company that builds software for the sector shifts toward the software company stack: its code and its customers' patient data are the crown jewels, and the providers it sells to will review it hard precisely because of the data involved. Either way, access to systems holding health data is the center of gravity.
where to start
Start by seeing who can reach the systems that hold patient data, because that is where the most common healthcare exposure lives and it stays invisible until someone maps it. The shared accounts, the missing MFA, the staff who left and kept access are all sitting there, fixable, once they can be seen.
let's start with a conversation
Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.
Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.
We'll take it from there

+48 783 762 997
julian@unshadowit.com

