I have spent more than two decades watching attackers go where the defenders aren't. In the military, at NSA, in financial services, and now for years inside one of the largest public health systems in the country, the pattern never changes. The adversary studies your blind spot before you do. They find the seam between two tools, the gap between two teams, and the log nobody is reading. Then they live there.
That seam has moved. It used to live in the data center. Today it lives in your cloud tenant, your SaaS estate, your identity provider, and increasingly inside the AI systems we are racing to adopt. And most healthcare security programs are still pointed at the old neighborhood, polishing endpoint and network controls, while the fight has relocated to a place where they have almost no visibility.
Politeness has not served our industry well, so I want to be provocative about this. Healthcare is being breached at a rate that should embarrass all of us, and the explanation that we are underfunded and overexposed is only half true. The other half is that we have not adapted our detection and response strategy to where care happens now. Patient data does not sit in a fortress anymore. It moves through Microsoft 365 and Google Workspace, through Epic integrations and Workday, through a sprawling mesh of cloud services and third-party SaaS that no single person in the organization can fully inventory. We modernized the business. We did not modernize the way we hunt for threats inside it.
Identity is the new front door, and we left it unlocked
Start with the linchpin of identity. In a cloud and SaaS world, identity is the perimeter. There is no firewall between an attacker with valid credentials and the systems those credentials unlock. They simply log in. They don’t need malware, exploits, or anything for an endpoint agent to catch. A phished MFA session or a stolen OAuth token, and the adversary is now indistinguishable from a clinician, a billing specialist, or an administrator — except in their intent.
We have seen how this plays out across industries. Attackers phish a user, ride single sign-on from email into a downstream SaaS application, and start operating with legitimate access. In healthcare, that downstream application might hold protected health information for millions of patients or control the financial plumbing that pays your workforce. The intrusion does not look like an intrusion. It looks like Tuesday.
Here’s the hard question every healthcare security leader needs to answer. If a valid account in your environment started behaving maliciously this morning, how long would it take you to know, and could you reconstruct everything it touched afterward? If the honest answer involves opening a ticket and waiting on a cloud provider, you do not have an identity security program. You have an identity hope.
SaaS and cloud broke our forensic model
The deeper problem is that the cloud and SaaS world broke the forensic model we all grew up on. In the on-premises era, when something went wrong, the evidence was sitting on a disk we owned. We could image it, analyze it, and tell the story of the attack at our own pace. That world is gone.
Cloud and SaaS logs are ephemeral, inconsistent, and scattered across dozens of platforms, each with its own retention window, export quirks, and definition of what counts as an event worth keeping. By the time a healthcare organization realizes it is under investigation, often weeks after the initial access, the evidence it needs to understand the breach may have already aged out. You cannot investigate what you did not retain. And you cannot retain what you were never collecting in the first place.
The majority of healthcare breaches that persist for months are not actually a failure to investigate the cloud, but rather an organization that was not prepared to investigate its own cloud. The detections were tuned for the network. The data was never centralized. The team had never practiced hunting across identity, SaaS, and cloud as one connected story. So, when the incident came, they were building the airplane in mid-flight.
This is the gap that a cloud-native detection, investigation, and response approach — the philosophy companies like Mitiga have built around — is meant to close. Not as a product you bolt on and forget, but as a discipline of constantly capturing the forensic data your SaaS and cloud platforms generate, correlating identity and application activity into one incident view, and hunting proactively instead of waiting for an alert that may never fire. I am less interested in any single vendor than I am in the principle. If your strategy assumes the evidence will be there when you need it, you have already lost. You have to capture it on purpose, ahead of time.
AI raised the stakes on both sides of the table
Now layer AI on top of all of this because that is where healthcare is sprinting next. We are deploying clinical AI, ambient documentation, AI-assisted diagnostics, and a growing roster of copilots wired directly into our most sensitive systems. Every one of those integrations is a new identity, a new set of permissions, a new data flow, and a new pathway an attacker can abuse. We are expanding the attack surface faster than we are expanding our ability to monitor it.
And the adversary has AI, too. The phishing is more convincing, and the reconnaissance is faster. The ability to operate inside a compromised cloud environment, blending into normal activity, is improving on their side as quickly as it is on ours. I am genuinely optimistic about what AI will do for defenders. I have built and deployed this technology, and used well, it can triage and correlate at a speed no human team can match. But AI is an accelerant, not a strategy. Pointed at a cloud environment you cannot see inside, it just helps you be confidently wrong, faster.
The healthcare organizations that will weather the next few years are the ones treating their AI adoption less as an IT initiative and more as a security event. That means inventorying every AI system's access the way you would a new employee. It means logging and monitoring what those systems do inside your SaaS and cloud estate. And it means building detections for the new failure modes AI introduces, not just the ones we already know how to find.
Earn your readiness before you need it
This isn’t an argument for fear, and it’s not an argument for slowing down. Healthcare has to go to the cloud. We have to adopt AI. The mission—patient safety, patient care, and patient trust—requires it. My argument is on the order of operations.
Build the visibility before you need it. Centralize and retain the cloud and SaaS evidence before the incident, not during it. Treat identity as the perimeter it has become and watch it like one. Hunt on a schedule instead of waiting to be told you have a problem. And practice your cloud incident response like clinicians practice a code, over and over, in a realistic way, until it becomes muscle memory.
The attackers have already moved into the cloud, the SaaS layer, and the identity fabric of your organization. The only real question is whether you will meet them there with eyes open or arrive weeks later trying to read evidence that has already disappeared. In healthcare, that lag is not only measured in dollars. It’s measured in patient trust we cannot afford to lose.
We earned our reputations defending the old perimeter. It is time to earn them again on the new one.
