Seeing More, Closing Less: The Healthcare Remediation Gap

By Russell Teague, Chief Security and Strategy Officer, Fortified Health Security
LinkedIn: Russell Teague
LinkedIn: Fortified Health Security
Column: Defense Desk

Why NIST CSF 2.0 should be the beginning of the work, not the end

Healthcare is getting better at seeing its risk. The hard part is now what we do after the finding.

During the first half of 2026, organizations have been identifying more risk than ever, but they are remediating less of it according to Fortified Health Security’s rolling risk assessment data. The average remediation rate has fallen to 6.4%, down from 23.3% over the same period last year, even as critical and high-risk findings rose 60%. Identified risk now sits open for an average of 345 days.

That gap is evidence of visibility outpacing capacity, shifting the healthcare cybersecurity bottleneck from detection to remediation. Breaking that bottleneck requires disciplined prioritization, clear accountability, and enough capacity to act.

Prioritizing through NIST CSF 2.0

As healthcare organizations adopt NIST CSF 2.0, the framework is exposing areas where cybersecurity maturity has not kept pace with operational dependency and emerging risk. Supply-chain risk findings are tracking toward a 6x increase this year, with 63% rated critical or high. Identity and access findings are tracking toward 4x, with 64% critical or high.

The increase does not necessarily mean these environments suddenly became six times more dangerous. It reflects, at least in part, deeper examination of risks that were previously underassessed or inconsistently measured.

The framework is also the right lens for the regulation on the horizon. While the final requirements and timing remain uncertain, the direction of travel is increasingly clear: healthcare organizations will be expected to demonstrate greater rigor, accountability, testing, and resilience.

I’d advise leading with NIST CSF 2.0 rather than waiting on the HIPAA modernization. Long term, aligning to NIST now insulates you from however the final changes land. In the short term that alignment demonstrates to OCR, state attorneys general, cyber-insurers, and other stakeholders that the organization is using a recognized, outcome-based framework to systematically identify, prioritize, and manage cybersecurity risk.

Still, a critical vulnerability remains a risk until someone evaluates it, makes a decision, and takes action. When remediation stalls, the exposure doesn’t sit quietly on a spreadsheet. It waits on the same network as the imaging system, the infusion pump, and the EHR.

Remediation Is a Program, Not a Metric

No framework alone fixes an execution problem. Organizations can prioritize accurately and still stall because of limited staffing, unclear ownership, legacy-system dependencies, constrained maintenance windows, competing capital priorities, or the clinical consequences of taking systems offline. That is why remediation has to be built as a program, not a project.

A sustainable remediation program requires more than a list of findings. It needs:

  • Accountable risk owners
  • Defined service-level expectations
  • Validation of closure
  • Exception and risk-acceptance processes
  • Dependency tracking
  • Regular escalation when critical risks remain unresolved

Without that operating structure, even accurate assessments eventually become aging inventories of known exposure.

It also can’t be tracked as a single number because not all risks are created equal. Overall remediation time remains useful, but it should never be viewed in isolation. Organizations should separately measure critical and high-risk findings, especially those that are internet-facing, actively exploited, or connected to essential clinical services. Leaders should also track the age of unresolved risk, adherence to remediation targets, accepted exceptions, and whether closure has been independently validated.

This additional layer of visibility will help your team prioritize effectively.

AI can help by correlating asset criticality, exploitability, threat intelligence, compensating controls, business ownership, and patient-care dependencies so analysts can evaluate findings faster. It should accelerate context gathering and recommended next actions, not independently accept risk or determine whether remediation is complete. Human judgment and patient-care impact stay with the analyst so that your team can move faster, but safely.

The Board Conversation

When it comes to evaluating under NIST rather than waiting for HIPAA modernization, the wrong frame for the board conversation is fear, uncertainty, and doubt. The right frame is opportunity. A compliance-first program asks, “when must I comply?” A security-first program asks, “what should I prioritize to protect patients and care delivery?” That reframing shifts the boardroom question from “what will this cost us?” to “what do we get for moving now?”

Once a material risk has been identified, an organization should be prepared to demonstrate how it evaluated the exposure, prioritized its response, documented its decision, and implemented reasonable corrective action. You should also make it clear to your board that none of this is ultimately about a remediation rate. It is about the patients who depend on these systems staying up, and the teams working under real constraints to keep them that way.

Detection Creates Awareness. Remediation Reduces Risk.

The organizations that pull ahead over the next twelve months will be the ones that treat visibility as the start of the work, not the end of it. That means converting findings into three things: clear prioritization, a strategic roadmap, and the resourcing to execute against it.

Stay safe, healthcare.