Ayush Jain, CEO & Founder, Mindbowser Inc.

getty
Most EHR modernization conversations begin with innovation: better interoperability, less clinician burnout, faster documentation, smarter decision support. Security is usually somewhere further down the list, treated as a compliance step rather than a design principle. That ordering is backward, and it is an expensive habit for the industry to keep.
The pattern is familiar to anyone who has sat through an EHR selection process. A health system picks a new platform based on how clinicians feel about the interface. Security shows up as a line item on a procurement checklist, somewhere below "user satisfaction" and above "implementation timeline." Months later, the same organization is explaining to regulators why a billing vendor's compromised credentials gave an attacker a direct path into patient records.
That sequence (features first, security retrofitted) describes most healthcare breaches happening right now, not the exception.
The numbers make the case on their own. Healthcare has been the most expensive industry for data breaches for 14 straight years, with the average incident now running $7.42 million and taking about 279 days to identify and contain, according to IBM's 2025 Cost of a Data Breach Report. That is nearly five weeks slower than the average across every other industry.
2024 was the worst year ever recorded for the sector: 725 large breaches reported to HHS, touching close to 289 million people, with the ransomware attack on Change Healthcare accounting for roughly 192.7 million of those records. This is not lost laptops or misfiled paperwork anymore. Hacking and network intrusions now make up more than 80% of large healthcare breaches, up from about half in 2019.
Every one of those figures runs through the EHR. It is the system that touches billing, imaging, connected devices, patient portals and a growing list of third-party vendors. Modernizing it for interoperability without rethinking how it is secured does not just add convenience. It widens the blast radius.
The Mistake Hiding In Plain Sight
Most legacy EHR environments were built for a different era: on premises, walled off, a small number of trusted users logging in from inside the building. Modernization asks those same foundations to support cloud hosting, API connections, remote care and dozens of external vendors, often without anyone going back to rebuild the parts that were never designed to carry that load.
Three things tend to go wrong. Access permissions get carried over from the old system instead of redesigned, so gaps in who can see what follow the organization into its new platform. Vendor connections multiply faster than anyone's ability to track them, which is how a compromised billing or scheduling partner becomes a hospital's problem. And audit logging gets treated as a compliance requirement to satisfy rather than the thing that determines whether an intrusion is caught in hours or in months.
That last point matters more than it gets credit for. The gap between a well-instrumented system and a poorly instrumented one is not measured in dollars first. It is measured in time, and time is what turns a contained incident into a headline.
What Security-First Actually Looks Like
None of this requires reinventing healthcare IT. It requires sequencing the decisions differently.
Access design should come before interface design: least privilege by default, not permissions inherited from the system being replaced. Vendor exposure should be mapped before any contract is signed, with a clear plan for monitoring those connections after go live, not just during onboarding.
Detection needs to be a stated design requirement, with a target for how quickly an intrusion would be spotted, rather than something measured for the first time after an incident occurs. Encryption and data segmentation should be defaults, not settings enabled later once someone gets around to it. And security leadership should be involved in vendor selection, alongside IT and clinical teams, so tradeoffs between a smoother interface and a wider attack surface get weighed openly instead of discovered afterward.
Why The Order Matters
The instinct to lead with features is understandable. Clinicians are stretched thin, patients expect better digital experiences and a modern interface is an easy thing to justify internally. But healthcare data does not behave like other data. It is effectively permanent. A diagnosis history cannot be reissued, which is exactly why it is so valuable to attackers.
Security built in from the start becomes a foundation the rest of the system can rely on. Security added afterward becomes a cost the organization keeps paying, on every feature that comes next.
Before the next EHR conversation turns to dashboards and clinical workflows, it is worth asking a more basic question: If someone tried to break into this system, would anyone know? Get that answer right, and the rest of modernization gets easier to build on top of. Get it wrong, and no interface redesign will offset the cost of the breach notification that follows.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?