From EHRs to AI: How interconnected healthcare systems are changing technology risks

Healthcare technology risk has changed in a fundamental way over the past decade: it has moved from securing individual systems to managing entire digital ecosystems. A decade ago, the priority was straightforward: secure the Electronic Health Record, control who could access it, encrypt what sat inside it. Today, that same EHR is one node in a much larger network of connected applications, devices, and services, and protecting it in isolation no longer protects the patient. The question has shifted from "is this system secure?" to "can this entire ecosystem be trusted to deliver safe, uninterrupted care?"
That shift matters because the stakes have changed too. A technology failure in this environment is rarely just an IT event; it can directly touch clinical continuity and patient safety. A delayed lab result, a monitoring alert that doesn't reach the right clinician, an AI-based decision support tool working off outdated data: each of these has less to do with data breaches and more to do with whether care teams can rely on their systems at the moment it matters most.
From isolated systems to a connected care environment

A typical hospital today runs on a chain of connected components. The Hospital Information System (HIS) and EHR sit at the centre, but they now exchange data continuously with laboratory and radiology systems, pharmacy platforms, billing systems, and increasingly, AI-based clinical decision support. Interoperability standards let a patient's record move between a primary care system and a specialist's platform, or between a hospital and an insurer, often in real time. Connected medical devices, infusion pumps, patient monitors, and wearables feed data directly into these systems, and cloud infrastructure now hosts much of this exchange.
Each connection adds real clinical value: faster diagnosis, fewer manual handoffs, better-informed decisions at the bedside. But each also means a problem in one part of the environment can be felt somewhere else. If an interoperability interface between the HIS and a lab system fails silently, a clinician may make a decision on results that never actually arrived. If a connected infusion pump loses its link to the monitoring platform, an alert that should have reached a nurse may simply not fire. These are the kind of everyday operational risks that come with running a connected care environment, and they sit much closer to patient safety than to a conventional IT outage.
Why data protection alone no longer covers the risk

Protecting data will always matter, but it addresses only one part of a larger picture. The more relevant question today is whether every system and decision layer involved in a patient's care can be relied upon, not just whether the data behind it is encrypted. That requires visibility into how information flows between HIS, lab, pharmacy, imaging, and monitoring systems, clarity on which clinical decisions are being influenced by AI tools, and confidence that a vendor integration, a device manufacturer, a cloud provider, or a billing platform will not become the reason a clinician loses access to critical information at the wrong moment. Technology risk in healthcare is best measured by its potential impact on care delivery, not only by its exposure of data.
Building responsible AI into clinical workflows
AI is now present at multiple points in the care journey, supporting diagnosis, flagging deteriorating patients, prioritising triage, and assisting clinical documentation. This brings real benefits, but it also introduces a different kind of risk. A conventional system tends to fail visibly: it goes down, or it throws an error someone notices. An AI model can be wrong while continuing to function normally, and an incorrect recommendation can move through a clinical workflow with far less warning than an outage would give.

This is why AI governance has to be treated as a clinical safety issue, not just a technology one. It means validating AI tools against real clinical outcomes before they are relied upon at the bedside, keeping a clinician firmly in the loop on any AI-assisted decision so the model supports judgement rather than replacing it, and understanding what data a model was trained on, how its recommendations are monitored, and what happens when its performance drifts. Responsible adoption of AI in healthcare depends less on the sophistication of the model and more on the discipline of the oversight built around it.
Moving from reactive cybersecurity to resilience-by-design
Many healthcare technology risk programmes have historically been reactive: identify a threat, respond to it, move to the next one. That worked reasonably well when systems were self-contained, and failure modes were easier to predict. It holds up less well in a connected care environment, where tracing an issue back through HIS, lab, cloud and device layers can take time, time during which the impact may already have reached a patient.

Resilience-by-design starts from a different assumption: that some part of the environment will fail, and the priority is ensuring care is not disrupted when it does. Healthcare organisations managing this well share a few habits. They maintain a clear map of how data moves between HIS, EHR, lab, and connected devices, so that when an interface breaks, they know within minutes what else is affected. They set governance for third-party and AI integrations before those tools go live, not after an incident forces the issue. They build redundancy into critical workflows, a backup path for a monitoring alert, a manual fallback for a lab interface, so a single failed connection does not become a gap in patient care. And they review business continuity planning regularly as new systems are added, rather than treating it as a document written once. None of this is about slowing innovation down; it is about designing innovation so it continues to protect patients even when a part of the system does not go as planned.
Balancing clinical speed with security
There is a genuine tension for technology leaders to manage here. Clinicians need systems that keep pace with patient care, AI tools need to be adopted for their benefits to be realised, and patients are better served when useful new capabilities reach care teams without unnecessary delay. A risk management approach that defaults to blocking every new integration risks becoming an obstacle in itself; clinical teams will find workarounds, sometimes less safe ones, if the approved path is too slow.

A more workable approach brings trust and safety considerations into how new systems are evaluated from the outset, alongside clinical validation rather than after it, and gives clinical teams a straightforward way to flag when a connected system is not behaving as expected, so issues surface early. Resilience, in this sense, is an ongoing discipline that evolves at the same pace as the systems and AI tools being added to patient care.
For healthtech leaders, the takeaway is direct: technology resilience and patient safety are no longer separate conversations; they are the same conversation, viewed from different desks. The organisations that manage this transition well will not necessarily be those with the most controls in place, but those that treat every new system, device or AI tool as something to be trusted with a patient's care before it is trusted with anything else. That is what earns lasting confidence from clinicians, from patients, and from the wider healthcare system.
Surjeet Thakur
Surjeet Thakur is the Chief Information Officer at Kochi-based Rajagiri Hospital
