Listen to this episode

From Ransomware to Recovery: How One Rural Hospital Transformed Its Cybersecurity

0:0057:51

Recorded June 2025. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Blake Rea talks with Scott, chief information officer at Southern Coos Hospital and Health Center, a 25-bed critical access hospital on the southern Oregon coast. Scott traces his path from fundraising and marketing into healthcare IT and describes how the community-owned hospital uses health assessments to plan service lines such as dermatology, general surgery, and orthopedics.

He explains rural funding realities, the elected board's scrutiny of major projects, and the two-year rollout of Epic Community Connect hosted by Providence Health Systems. Scott recalls a ransomware attack just before COVID-19 that drove cybersecurity spending from about 2 percent to over 12 percent of the IS budget, prompting an outsourced MDR provider, a zero trust platform now provided by Cloudflare, security awareness training, and revamped asset management. He argues HIPAA is not updated for the current threat environment, and Blake notes that, at the time of recording, proposed HIPAA updates would address encryption and MFA. Scott also shares his success metrics, wishes for a single regulatory source of truth, and describes an AI governance toolkit for rural hospitals.

Worth remembering

Key takeaways

  1. Scott says his hospital treats cybersecurity as a must-have project and a conscious investment rather than a nice-to-have.
    “a lot of people have kind of an antiquated notion about cybersecurity as being sort of like a nice-to-have and not a must-have”
  2. Scott says a ransomware attack just before COVID pushed the hospital to raise cyber spending from about 2 percent to over 12 percent of its IS budget.
    “we've increased our cyber spend from about 2% of our IS budget to just over 12% over the last well, over the last four years.”
  3. Scott explains that Southern Coos subscribes to an MDR vendor for security operations because it could not build a SOC on site given rural resource constraints.
    “there really wasn't any way for us to build a SOC here on site, due to our resource constraints, certainly.”
  4. Scott argues HIPAA is a nice entry point to compliance but is not updated for the current threat environment, so his hospital does more than required.
    “HIPAA it's a very nice entry point to compliance but in no way is updated for the current threat environment.”
  5. Scott says the hospital runs a robust security awareness program with social engineering tests because end users are often the weakest link in the chain.
    “end users are often the kind of the weakest link in the chain, and so we do a lot of education throughout the year”
  6. Scott says his team patches high-criticality vulnerabilities immediately and treats patch counts and phishing click rates as success metrics.
    “those high criticality vulnerabilities we do scan and we do patch immediately.”
  7. Scott says he is developing an AI governance toolkit for rural health that any rural hospital will be able to use.
    “We're going to make that toolkit available to, you know, any rural hospital that wants to utilize it.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Nestled along the scenic Southern Oregon coast, Southern Coos Hospital faces a unique set of challenges that many healthcare organizations never encounter. With just 25 beds serving a rural population of about 15,000, this critical access hospital demonstrates remarkable innovation in stretching limited resources while maintaining robust cybersecurity practices.

Scott, the hospital's CIO who transitioned from fundraising and marketing into healthcare IT, shares the compelling story of how a ransomware attack just before COVID-19 transformed their approach to cybersecurity. This pivotal moment prompted Southern Coos to increase their cybersecurity budget from a mere 2% to over 12% of their IT spending - a decision that positioned them ahead of many similar-sized facilities in protecting patient data.

The conversation delves into practical strategies that resource-constrained healthcare organizations can implement immediately: outsourcing Security Operations Center functions to specialized vendors, prioritizing security awareness training for staff, and making strategic investments in asset management tools. Scott's candid assessment of HIPAA's limitations ("a nice entry point to compliance but in no way updated for the current threat environment") demonstrates the gap between regulatory requirements and actual security needs that healthcare organizations must bridge themselves.

Perhaps most transformative for this rural hospital was implementing Epic's electronic health record system, which revolutionized how they transfer patient records during emergencies. What once took 30+ minutes now happens "with the click of a button" - a game-changer for a facility that frequently needs to transfer patients to higher levels of care. This technology leap showcases how even small hospitals can leverage enterprise-grade solutions to dramatically improve patient care.

Looking toward the future, Scott is developing an AI governance toolkit specifically designed for rural healthcare settings - a resource he plans to share freely with similar facilities nationwide. His vision for a centralized communication platform where hospitals could share cybersecurity incidents and mitigation strategies points toward a collaborative approach that could benefit the entire healthcare ecosystem.

Whether you're managing IT in a resource-constrained healthcare environment, developing regulatory frameworks, or simply interested in how rural communities are innovating to protect sensitive data, this episode offers valuable insights into balancing security requirements with practical realities. Subscribe now and join the conversation about building more resilient healthcare systems everywhere.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.