
Chatbots, IT Outages, Devices Top 2026 Health Tech Hazards
About this episode
Get every episode summarized
Each time Banking Information Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
271 searchable segments. Every word is indexed and playable.
Full transcript
Banking Information Security Podcast — Chatbots, IT Outages, Devices Top 2026 Health Tech Hazards. Machine-transcribed; use the interactive transcript above to jump the player to any line.
I'm Mary Ann Kolbisak-Miggy, Executive Editor at Information Security Media Group. ECRE Institute, a Patient Safety Research Organization, recently issued its annual Top Health Technology Hazards Report. Among the top 10 hazards that ECRE named for 2026 are AI chat bots, IT outages, or so-called digital darkness, and legacy medical device cybersecurity issues. Today I'm speaking with Scott Looney, who is ECRE's cybersecurity consultant lead, and Rob Schluth, who is Project Leader for ECRE's Device Safety Group. Scott and Rob will be discussing how these technology issues rose to the top of hazards in healthcare. So just for starters, briefly explain to our listeners how ECRE identifies what's included in the Top Health Tech Hazards list, and how those hazards get ranked. Rob?
Yeah, sure, Mary Ann, thanks. Okay, so every year we produce this report, this is our 19th edition that just came out in 2026. The purpose of this report is to highlight potential sources of danger involving the use of medical devices and systems, and then to evaluate contributing factors and then provide recommendations to reduce the incidence of preventable harm. So throughout the year, we select ideas for topic nominations. So our staff are involved in all areas of healthcare and technology management. They suggest topics, things that they see, talking with hospitals, talking with manufacturers, we do testing in our lab, so sometimes those evaluation processes reveal problems. We also have like a problem reporting network. So people report problems to us, we have a patient safety organization, they receive reports. So from all those channels, we get topic ideas to think about. Usually we end up in like the 70 to 100 different topics to consider, and then it's just kind of an iterative process of committee review looking at what's
suggested and narrowing it down, review and voting until we get to the final 10 topics that we think weren't the most attention for the coming year. And that's how we kind of end up with the report that we issued here. So with that said, Ekri's report this year named chatbots as the top healthcare tech hazard, why being that you had so many different things to choose from, and how was it chosen and decided that this was the top risk or hazard? And was chatbots on the list in previous years, or is this the first time? This is the first time with this specific focus related to chatbots. We've covered AI topics probably four or five times over the recent years. Obviously AI is becoming such a big issue in all of our lives. And this year was really interesting figuring out we knew we needed to talk about AI, but like what angle makes sense? What haven't we covered before? Last year we focused on AI-enabled health technologies. So technology is specifically
intended for healthcare applications. This year we took a different tech. So we're talking specifically about the large language models. So things like chatbots, Gemini, Grock, Copilot, things that any of us can use. We have one of our phones. We have one of our laptops. They're not intended for healthcare applications. They're not medical devices. They're not regulated that way. But do these are things that we're finding out people are using for healthcare-related applications. So it could be a patient, you know, any one of us looking up information about health condition. It could be a clinical practitioner, maybe looking up some treatment options for a patient they have, or just anyone in healthcare answering questions for their job, writing a report, searching for products, troubleshooting a problem. We may turn to one of these tools to try to get information to help us help the patient or do the job that we have to do. So we thought that was an interesting angle and we delved into the risks that are associated with that. So as a follow-up
to that rub, there are some AI type of companies, you know, chat GPT. They know what their health version of this, their chatbot. There's a number of other companies doing similar things. So when it comes to those more specialized chatbot sorts of tools, when it comes to those tools being used by patients, but then also perhaps by healthcare professionals, what are the top worries and concerns, even if these products are supposedly, you know, tailored for the health community? There are a lot of issues. So the large language models, LLMs, on which they're based, have some fundamental limitations that I think are even going to show up in some of these healthcare-specific tools. It was very interesting to us when chat GPT Health, and I think Clawed has a project they're working on. It kind of reinforced what we talk about in our report. Healthcare is a different animal when it comes to using these tools. There are privacy considerations, so you have patients uploading their files. Once you do that, if it's a general purpose LLM,
now your private information is out there for these tools to train on and use, and a lot of cases like I personally wouldn't be comfortable with that, wouldn't recommend that. So some of these chat GPT Health, I think are looking at ways to maybe secure that better, so that's good. They're addressing some of the issues that are out there. But it's still early days in terms of these things, but I have seen some indications that they still produce some questionable results sometime. I don't want to give the impression that these tools are bad. They're actually really useful, and it can be very impressive, and what they do. But they just aren't always accurate, and we get into some of the details there, and that's something that people who use the tools just need to be aware of. So when it comes to digital darkness, IT outages cause by cyber attacks, vendor incidents, and similar events, that was also on the list. What can health care entities do to better prepare for these kinds of situations? And what sorts of digital darkness events are the most difficult to prepare for, and potentially the most dangerous?
Scott? Yeah, digital darkness events and compass really a broad catalogue of incidents and events that can happen at any time. For healthcare organizations specifically, having a proactive disaster-ready approach to any outage event is essential. You know, it'd be proactive. An organization should build a disaster recovery and contingency plan, incorporating the most comprehensive procedures and tools that can assist in the resiliency and minimize downtime, thus ultimately minimizing the risk of harm to patients and the organization itself. Akri even had a client. We have a program that we do, and we kind of highlight some of our clients for different things. And we actually had a client that was on the East Coast, and they had really good proactive disaster recovery plans to pace. And they got hit with the hurricane. And so they had a natural disaster. You know, that's one of the biggest things that we can see here in terms of like, you know, a digital darkness event. So they were able to spin up, you know, some alternate communication tools, so cell phones, plan lines, things like that were
down. So they had to refer back to satellite phones, things like that to be able to continue to communicate. And so they really, really followed that. And we were able to highlight, you know, what they were doing. And they kind of just did the best practices on what we could do. And so I'll touch on a couple of things that they did. One of the things that a healthcare institution and really any business that's global or just in the States or at all, especially with cloud sources and things like that, your biggest thing that you can do, especially in a healthcare market is, you know, strong backups. Implementing the 321 backup rule, you know, that's maintaining the three copies of data on two different media types. One copy stored entirely offline, and geographically, you know, distant prevent ransomware, you know, different natural disaster situations that could actually happen in the geographic region and actually get all your copies of data backups. So you want to minimize that. Additionally, you know, conducting registration and integrity drills on the data backups. Absolutely. Let's you know that if you had an incident where you had to use those backups, they're going to work and you're going to be able
to get back online. You know, in the case of like communication, like I said, you know, having a failover system such as satellite phones, alternate Wi-Fi, you know, a lot of satellites will give you the Wi-Fi. Well, cellular services possibly, but a lot of times in certain events, those services will be completely unreliable. So, you know, just keeping in mind, you know, depending on the type of scenario you're in, if it was a localized ransomware attack, obviously your communication is still going to be there. If it's a natural disaster, you may be looking at a completely different scenario. So really trying to assess what scenarios you may face versus, you know, what you're not, you know, being where I'm at, I'm in the middle of the United States. So I'm not necessarily going to be prepping for a hurricane, but I prep for tornadoes. So very similar situation. For healthcare entities, thinking about if you did have a scenario where your facility was down, digital darkness in terms of the actual building, making what's called like a minimum viable hospital, setting up a protocol that identifies required life safety and a clinical application that you could spin up if you could
have connection to your EMR, you know, systems that are doing medication administration, fusion pumps, things like that. Trying to keep those life safe systems on or bringing them back up, you know, having an alternate facility is definitely going to be great. You know, even doing some things as easy as like making a clinical go bag, you know, with paper charts, instructions for manual workflows of certain things, just keeping the ability, you know, to work technology free in a situation. So really that's the best way you can do it. And then honestly, you know, the best proactive thing you can do is once you have your plans in place, always test them when you can, you know, a lot of this entities will do cyber security tabletop exercises. And this kind of falls into that bucket, you know, when you look at a Nautilus disaster or you look at a cyber security attack, you know, you kind of treat them similarly, depending on the situation. But you always are going to spin up your plans, you're going to bring on the, you know, your different teams that are going to assist in getting things going and managing that setup while you're in a reduced
capacity. And then actually, you know, when you talk, you had asked, to which event, you know, which is the hardest to prepare for, I would honestly say I think the events that would be the hardest in my mind would probably natural disasters. For example, like an earthquake, you know, those are something that just even with today's technology, we can't really predict when once going to hit. We can have a, you know, an idea, but we don't know. So, you know, a giant earthquake, hitting a large metropolitan area, could definitely see a surge of capacity needs, you know, meaning you're going to end up with staff shortages, infrastructure failures, you know, communication failures, power, et cetera. So I really do look at, you know, natural causes as being one of the hardest to prepare for. We can prepare for ransomware and cyber attacks, you know, we have tools in place that are monitoring, you know, you'll start seeing little blips on our, on our alerts, you know, that we might have somebody coming in or, you know, things like that, or you have publications out there that are finding vulnerabilities. So really, that's the biggest thing to me, I think, is just the natural causes.
So Scott, with all that said, we also often see major vendors, you know, to the healthcare sector, having cyber incidents where, you know, they wind up, you know, taking their systems down, or perhaps supply chain sorts of companies that are very critical to the healthcare sector. Are there any top lessons that you see emerging from some of these high profile outages involving cyber and vendors, such as the change healthcare ransomware attack in 2024 that led to various outages for different kinds of processes that thousands of healthcare practices in hospitals depended on, you know, with change, and then all of a sudden those systems were down. And any lessons there? Absolutely, yeah, that change healthcare attack. I would say there are lots of lessons for global organizations, you know, they, everybody learned something from that event. I was actually working in a cyber security engineering role at the time. And so, you know, our revelation with our organization is that we
really did have a lot of things correct compared to change healthcare, but it also definitely helped us reveal, you know, some of the vulnerabilities and you brought up the perfect example of third-party vendors. Everybody's depending on a third-party vendor these days. So it's like, you know, we have our cyber security infrastructure, so we know what we're putting into place. But some of the lessons that I saw come out of the ordeal was really realizing that a lot of people aren't necessarily implementing strong MFA or multi-factor authentication. You know, the change particular attack, you know, it started with a social engineering attack where the bad actor gained credentials through pretending to be their IT guy. I'm giving bad actor access and to changes systems, you know, they didn't have a secondary validation of MFA, so then all of a sudden, you know, they got right in. Then on top of that, we learned, you know, that a lot of their critical networks were not necessarily properly segmented. So the bad actor once he was able to get in, he was able to propagate through the network and kind of traverse the ecosystem and find other places and start getting into the more
basically taking them down at that point. And that was just really, yeah, we just really learned just to lack business continuity planning was another one disaster recovery. They took them a long time. I can't even remember how long it took, but it was, you know, that third-party vendor failure, you know, as you said, it touched basically almost everyone in the United States that has ever had healthcare or has a prescription, you know, things like that. I mean, it was it was rough. And I really led to that lengthy recovery process and it kind of, you know, in our our circumstance at the time, it actually had our organization. We ended up not redoing, but really we've re-reviewed all of our business plans and really made sure that we didn't have any of these open gaps that changed it so that, you know, we weren't part of that problem. So now also on that list, as I mentioned up front, is legacy medical devices and the cyber risk involved in those when these products are no longer supported by their vendors, but they're still in use for patient care. In those circumstances, what are the top patient safety and data security concerns? And what kinds of legacy medical devices
are of highest concern and why? The term legacy legacy devices, you know, when we think of it, the word legacy, we always think, you know, systems that are old, aging, you know, things like that. And that definitely encompasses that. But, you know, according to this, a legacy device is any system or technology that cannot be reasonably protected against cyber security threats. So obviously, that includes the older aging systems without data operating systems and proper security protocols, things like that. And even newer systems that are not necessarily able to patch it, brand new systems are coming out and they automatically could fall into the legacy category. And we look at it from the lens that we have legacy devices and they're in use all over the world. And really, we have to protect them. And to me, you know, what we see from all of our different partners and vendors that we work with, you know, some of the top risks that we see are the unpatchable vulnerabilities, you know, those are just leaving devices open to attack. And obviously, when I'm talking to devices that are open to attack, these are going to be the IOT, the IOMT medical thing devices,
you know, anything that's connected to the network. So, you know, those systems are going to be containing patient data. They're going to be on the network. They're, you know, it's just one of those things where that really becomes that big thing. So, you know, your data breaches a PHI exposure really ramps up. Let's take an EKG, for example, you know, it's got, you know, the patient's birthday, maybe their name, things like that. The system, let's say it doesn't have the ability to be encrypted. So it's actually transmitting data over the network, you know, in plain text. So problem, you got a guy sitting out in the lobby with a sniffer and he can see some of that traffic. So, obviously, that's going to be a problem. Now, the thing we see with, you know, legacy devices, if it were to be compromised, you know, that ends up affecting patient safety. Should a compromised device, you know, be altered and then malfunction or be remotely shut off or some other scenario, you know, that could have catastrophic impacts to that patient and that patient safety. Another big risk that we see is the modern technology compatibility, you know, this kind of relates to more
of the older devices. Most of the new devices can, you know, work with the protocols out there, you know, TLS, you know, things like that. But, you know, we see a lot, you know, there's situations where you may have like a fleet of infusion pumps that are on the network. Your network guy made a change. We went from TLS 1.1 to 1.2 to 1.3, but our infusion pump suites that we have, they can only support 1.1. And when we change that network protocol, also these infusion pumps quit working, you know, that's a really bad example of a scenario that we actually saw happen. And so that, that is a problem because then you also knew you had a resulting risk of patient safety and failures to medication delivery. And then when it comes to, you know, with these risks that we have, you know, you need to, we need to mitigate them as possible, you know, as much as possible. So when it comes to mitigating, you know, legacy systems, several factors kind of come into play. Obviously, you know, financial factors are in play, you know, replacing an entire fleet of outdated patient monitors is quite costly. And so, you know, implementing predictive replacement play in this key,
you know, getting that ahead of the game. And we have an, you know, echo here, we have it, we have a group that actually works with some of our partners, you know, kind of making those predictive replacement plans so that when they get into a scenario, you know, they have or a situation, they have some predictability in terms of costs moving forward. And in talking about replacements, some devices, you know, may not be a one-to-one direct replacement. So if you have a device performing a very specific function, and then any newer devices that are coming out don't necessarily provide that same exact function, you know, that device itself may need to stay in service. So, you know, in a scenario like that for a connected device that's at risk of being vulnerable, you know, you got to really apply some definitely other security controls in place. So like, you know, network segmentation, isolating it on the network, you know, physical protection of the device, you know, and storing it when not in use, migrating sensitive data off of the devices as they're being stored, et cetera. So really, physical security comes into play there along with, you know, the transmitted data security. So encryption is always, you know,
employee, things like that, you know, all sorts of mitigating devices for legacy systems. But to me, it's every day it's something new. So it's like, it's an ever-evolving situation. So we're just always trying to come up with new mitigation strategies and making sure that we can keep those systems patched and or protected if they're unpatchable. Finally, looking ahead into the rest of 2026, or maybe even into next year, any predictions or suggestions that, you know, both of you have about other top health tech hazards, even, perhaps things that we didn't go into that have some kind of cyber element. But might have been things that you were considering to put on, you know, the top 10 list this year didn't make it, but it's still something to be thinking about. And that healthcare entities need to consider when dealing with their risk and threat landscapes. Rob, do you want to start and then Scott, you can weigh in? Sure. Sure, Mary. Great. Thanks. I have, I guess, maybe two general
overarching fact thoughts to kind of address that question. So the first is, I think, organizations need to assess their incident reporting mechanisms. One of the issues we see with AI, it's so new, organizations aren't sure how to capture problems that are occurring. And if you don't know that a problem exists, you can't fix it. So incident reporting is very important. All organizations, regardless, you know, whether it's cybersecurity AI or just basic supplies and medical devices, you need a way to know if problems are occurring and to learn from those incidents. So a lot of times that's a matter of organizational culture. If you have a punitive culture, you're not going to learn about problems. You need a culture where staff are empowered to speak up when there's an incident. And that way you can learn from those incidents rather than having them be obstacles that lead to future incidents. One of the topics we covered in our report this year relates to poor quality products, a lot of them medical device supplies, some of them counterfeit products. We've been seeing kind of an uptick in that in the reports
that are submitted to ECRI. And if organizations don't learn that they have problems with these products, they may get used in more and more patients. You don't fight out about them, pull them from your inventory and solve the problem. And then you can end up causing harm from that way. The other kind of overarching thought would be to keep systems thinking in mind when you're assessing technology safety. So a lot of these failures, they don't occur in isolation and a lot of stuff Scott talked about is a good example of that. There are all kinds of contributing factors, people, processes, the environment, connected and supporting technologies. So you want to look at hazards through that lens of the total system rather than in isolation as a way to identify what can be going on and also to come up with solutions that were truly deal with that problem. One of the topics and other one we talked about this in this year's report relates to the way technologies might be designed or configured or implemented and how that might not align with how they're actually
used in practice in the clinical workflow. And then when that happens, when those configuring systems aren't fully aware of the environment of use, you could get the end users implementing workarounds and that can just leave to problems that put patients and even staff in danger. And Scott, anything you'd like to add to that? You know, I was just thinking more like, you know, in 2026 as everything is cloud and becoming more out there, all of our devices are connected, everything is connected. Really third party vendor security is a big, you know, that's a big layering gap that a lot of places see. There's some new cybersecurity technology that's out in the markets that's kind of being out there to kind of help close that gap. So one of the big things in my mind and, you know, we're talking about, you know, internally here as well with like RCCO, but you know, things like, you know, SaaS security posture management, watching, implementing a tool that actually helps you monitor your third party. We can't look at everything that they do, but a lot of these tools kind of give you ability to secure your third
party connections from your side and actually have reports and ideas of what is missing in terms of the security on the third party. So to me, you know, having that ability to really rain in and protect your data across all the different platforms, that's my big look at for 2026 is kind of that, whether it's on a medical device that's the software's medical device, an actual physical medical device, you know, all of our EMRs, all of our, you know, identity stuff, everything that's out there that's cloud based, you know, we've got our AWS is our Microsoft's, our Google's, you know, everything like that. You know, if I can visualize and see that security and what's missing, and I can actually go in there and lock that down, I think that's a really thing to me is as kind of, you know, Rob says, like, you know, configurations, you know, making sure all of our configurations are correct, I think is really really at the heart of a lot of problems. We come across things when just things, you know, a lot of breaches happen, a lot of vulnerabilities are exposed by misconfigurations.
So being able to catch those early and fix them is really in my mind, one of the biggest things that we can do. Well, thank you so much, Rob and Scott. I've been speaking to Rob Schlooth and Scott Looney of the Acre Institute. I'm Mary Ann Kolbasek McGee of Information Security Media Group. Thanks for joining us.
More episodes
More from Banking Information Security Podcast

How Agentic AI Is Reshaping the Modern SOC
Banking Information Security Podcast

How Renown Health Is Reshaping Its Digital ID Strategy
Banking Information Security Podcast

How Cloud Security Risks Grow With Home-Based Care
Banking Information Security Podcast

Addressing Quantum Readiness in Healthcare Security
Banking Information Security Podcast