Ransomware remains one of the biggest cybersecurity threats facing healthcare, but the threat landscape is changing rapidly. Attackers are becoming more targeted, ransomware-as-a-service is making sophisticated tools more accessible, and artificial intelligence is giving cybercriminals new ways to identify vulnerabilities and craft convincing attacks.
In this episode of The Beat's Cybersecurity at ViVE series, Sandy Vance speaks with Dave Bailey, VP of Consulting Solutions & Strategy at Clearwater, about the evolving ransomware threat and what healthcare organizations can do to stay ahead of it. Dave explains why smaller healthcare organizations and specialty practices are increasingly attractive targets, how attackers are using AI to improve social engineering and phishing, and why traditional cybersecurity approaches may not be fast enough for the threats ahead.
The conversation also explores why healthcare organizations need to understand their AI risk, establish guardrails, inventory their AI use cases, and prepare defenses that can respond at machine speed. Dave shares practical advice for organizations beginning their AI journey, while emphasizing that cybersecurity can no longer be something organizations assess once a year. It has to become a continuously monitored, evolving process.
In this episode, they talk about:
Why healthcare continues to be one of the most attractive targets for ransomware
How ransomware attacks have shifted toward smaller healthcare organizations and specialty practices
Why dental practices and specialty providers can be particularly appealing targets
How ransomware-as-a-service has created a more scalable business model for cybercriminals
Why cybercriminals increasingly operate like businesses
How attackers decide which healthcare organizations to target
Why post-COVID healthcare's rapid shift to telehealth changed the threat landscape
How AI is making phishing and social engineering attacks more sophisticated
Why AI creates new governance and risk-management challenges for healthcare organizations
Why healthcare organizations need defenses that can operate at machine speed
How frontier AI models could help attackers discover previously unknown software vulnerabilities
Why patching needs to become faster as AI-powered attacks evolve
Why healthcare organizations need to challenge vendors about their cybersecurity roadmaps
How organizations can begin building an AI governance strategy
Why organizations should inventory their AI use cases before trying to govern them
How healthcare organizations can use a tiered approach to AI risk
Why workforce training and communication are essential to responsible AI adoption
Why cybersecurity risk assessment can no longer be a once-a-year exercise
Why scalability and continuous monitoring will become increasingly important
A Little About Dave:
Dave Bailey is Vice President of Consulting Solutions & Strategy at Clearwater, where he leads the development and delivery of enterprise-level cybersecurity and risk management services for healthcare organizations nationwide. With more than 24 years of cybersecurity experience, including 14 years focused on healthcare, Dave is a trusted advisor to executive teams navigating complex regulatory, operational, and cyber risk challenges.
A recognized authority in cyber risk management and NIST Cybersecurity Framework assessment and implementation, Dave brings a strategic, business-aligned approach to security transformation. He previously served 13 years as a Communications and Information Officer in the United States Air Force, with leadership assignments spanning the Pentagon, domestic bases, and overseas operations.
Dave holds an Executive MBA from Quantic School of Business and Technology and is a CISSP, blending executive perspective with deep technical expertise.