Primary care practices depend on more connected devices than ever, including EHRs and diagnostic equipment. A Medical Economics commentary outlines how cyber incidents can disrupt care and offers four practical steps to reduce risk without a complete network overhaul.
Primary care practices now depend on more than clinical skill and staffing. They also rely on a growing mix of connected technologies, from electronic health records to diagnostic equipment and devices that capture and transmit patient data in real time. These tools have helped improve efficiency and broaden what primary care can deliver. They have also created a cybersecurity challenge that many practices may not be fully prepared to manage.
Connected medical devices are increasingly being targeted in cyberattacks. When these systems are disrupted, the consequences can extend well beyond information technology and affect patient care directly. A cyber incident that reaches the devices and systems used in daily operations can interrupt access to records, slow the flow of information and make routine work harder to complete.
In a busy primary care setting, technology is part of nearly every step of care delivery. Schedules are tight, communication moves quickly and staff depend on systems working as expected. Even a brief outage can create problems that spread through the day. Practices may lose access to patient records, wait longer for laboratory results or diagnostic data, or run into communication breakdowns with pharmacies or specialists. When that happens, staff may have to fall back on manual processes, which can slow patient flow and affect quality of care.
Recent health care cyber incidents have shown how quickly a disruption can spread and how difficult recovery can be. What starts as a technical problem can turn into delays in care, missed information and reduced capacity to see and treat patients. The impact can be even greater for smaller practices, which often have fewer IT resources and tighter staffing models.
One overlooked problem is that many of the devices used every day are now connected to the same network as other systems. That includes electrocardiogram machines, ultrasound systems and patient monitors. Most practices focus cybersecurity efforts on laptops, servers and email systems, but connected devices may carry risks of their own. Their connectivity helps speed data sharing and supports more informed clinical decisions, yet it also opens new paths for vulnerabilities.
Many medical devices run on older or unsupported software. Some require coordination across multiple vendors, and some sit outside traditional IT visibility. On top of that, many were not originally designed with strong cybersecurity protections. Without a clear, up-to-date and real-time inventory of connected devices, it becomes difficult to identify where vulnerabilities may exist. That lack of visibility is described as one of the most common gaps in health care cybersecurity today.
The issue is becoming more important as health care grows more digital at every level, including primary care. Telehealth, remote patient monitoring and digital diagnostics are expanding access to care and helping practices manage rising patient demand. At the same time, cyber threats are becoming more frequent and more disruptive. Health care data remain highly valuable, and systems that support clinical workflows are attractive targets because of the urgency involved in restoring operations.
When systems go down, the pressure to resume care is immediate. That urgency can make health care organizations more vulnerable to ransomware and other attacks. The result is a higher-risk environment in which even smaller practices are part of a broader, interconnected system that can be affected by cyber incidents.
The concern for many physicians is that extra security controls may slow care delivery. The commentary argues that effective cybersecurity should do the opposite. It should work in the background to protect systems without creating friction for clinicians or staff. That means moving away from reactive approaches and toward more integrated, proactive strategies.
In the context of medical devices, that includes identifying and tracking connected devices across the network, monitoring for unusual activity that could signal a threat, and prioritizing vulnerabilities based on their potential impact to patient care. It also includes ensuring systems can recover quickly if an incident occurs. Security measures are most effective when they match the way care is actually delivered. When designed thoughtfully, they can strengthen resilience without adding complexity to daily operations.
The article offers practical steps that do not require a complete overhaul of existing systems. Instead, it recommends focused attention and clear priorities. The first step is to start with visibility. Practices should develop a basic inventory of connected devices, including where the devices are used and how they connect to the network.
The second step is to focus on clinical impact. Practices should prioritize devices that are essential to patient care or that integrate directly with the electronic health record. Not every device carries the same level of risk, so attention should be directed first to the systems most closely tied to daily patient care.
The third step is to engage vendors. Practices should work with device manufacturers and IT providers to understand available security updates, support options and best practices. Because many devices depend on outside support or coordination among multiple vendors, those relationships matter when it comes to patching, maintenance and response planning.
The fourth step is to prepare for disruptions. Practices should have a plan for maintaining operations during a system outage, even if it is temporary. That planning helps staff keep care moving when connected systems are unavailable and reduces the chance that a disruption becomes a larger operational problem.
Taken together, these four steps can help practices build a stronger foundation without overburdening staff or disrupting workflows. The message is not that every connected device must be replaced or that security requires a major network rebuild. It is that the current environment calls for more deliberate attention to how medical devices are connected, monitored and supported.
Primary care is built on consistency and trust. Patients expect their care to be available, their information to be secure and their experience to be uninterrupted. As more parts of care move online and become interconnected, maintaining that trust increasingly depends on the reliability and security of the systems behind the scenes.
Medical device security is part of that equation. It helps make sure that the tools clinicians rely on remain available when they are needed most. The move to connected health care has created opportunities for better care, but it has also introduced new challenges. Addressing those challenges means treating cybersecurity as an essential part of safe and effective care, not as a separate function.
The commentary closes on a simple point: when systems are secure and reliable, care can continue without interruption, and that remains the primary goal in any practice. Cesar Villalta, the author of the commentary, is a managing director at Accenture and leads security for the firm’s U.S. health business. His work focuses on helping payers, hospitals and health systems defend the technology their patient care depends on, including ransomware, major breaches, connected medical devices and the risks that artificial intelligence brings to both sides of the fight. He says that in health care, cybersecurity is patient safety.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.