Skip to content

Healthcare

Protect patient data without taking clinical systems down.

You cannot patch a clinical device during a procedure, and you cannot block a clinician mid-shift. Security has to work around uptime that genuinely matters.

The pressure

Pressures specific to this sector

Every sector has pressures. These are the ones that change what a security programme is allowed to do here.

  1. Clinical systems that cannot be patched inside a normal maintenance window.

    A severity ranking that ignores when you are allowed to act produces a queue nobody can work.

  2. Patient data spread across systems with very different controls.

    The boundary drawn on the architecture diagram is not where the data actually is.

  3. Staff using whatever tool is fastest, including AI tools nobody approved.

    The fastest tool during a shift is rarely the one that went through review.

  4. Breach notification timelines that leave no room for slow scoping.

    The clock starts before you know the blast radius, not after.

The constraint

The constraint

You cannot patch a clinical device during a procedure, and the procedure does not move.

Frameworks

What you are measured against, and what we actually do about it.

Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.

  • HIPAA

    Evidenced

    No agent assesses it. What the platform gives a notification timeline is scoping speed and a complete record of who accessed and who was told.

  • NIST CSF 2.0

    Scored

    All 106 controls across six functions, with identity, logging and asset-inventory controls answered from connected tools rather than a questionnaire.

  • CIS Controls v8

    Scored

    153 safeguards across 18 controls, scoped to the implementation group you are actually held to before anything is scored.

  • ISO/IEC 42001

    Scored

    Coverage computed from what AI Guardian actually detects in usage telemetry, not from an answered questionnaire. It attests only what telemetry can satisfy.

Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.

The answer

How the platform works around it.

Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.

  1. See

    Where the data actually is

    Sensitive data detected in content rather than assumed from a system boundary, including what staff paste into external models at the egress boundary.

  2. Decide

    Risk weighed against uptime

    Reachability and asset criticality weighted so a fix is scheduled against a change window rather than forced through one, with freeze windows honoured rather than overridden.

  3. Act

    Contained, then scoped fast

    Containment on approval, with the blast radius established quickly enough for a notification timeline and reversibly enough to undo if the verdict was wrong.

Questions

The things this sector asks first.

  • Will it try to patch something mid-procedure?

    No. Change-freeze windows are merged from ServiceNow and your own calendars, and work that hits a freeze is held rather than forced. Autonomy is set per environment and severity, so a clinical environment can sit at manual while a corporate one does not.

  • How fast can we actually scope a breach?

    For an email incident, Microsoft Graph enumerates every mailbox that received the message directly rather than inferring spread, and Advanced Hunting correlates who clicked. For AI usage, raw payloads archive within five minutes and are retained, so a prompt sent last quarter is still scopeable.

  • Does it find patient data, or just assume where it is?

    It detects sensitive data in content. Prompt inspection runs Presidio and GLiNER at the egress boundary and highlights the detected entities, redacted by default. That is the opposite of assuming data is wherever a system boundary says it should be.

  • Can we block AI tools without blocking clinicians?

    Policy is set per tool, per group and per data class, not as a blanket domain block, and a rule can allow, warn, quarantine or block. Discovery comes first: the inventory catalogues what is in use before anything is enforced.