​​Combatting AI Threats with AI, People, and Practices: Three Lessons from Occupational Health​

Become an Insider.

Get Financial Technology Today news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

AI-powered attacks are driving profound changes in cybersecurity, shaping both common attack methods and the best forms of defense. With the vast majority of threat actors being motivated by financial gain, financial services institutions (FSI) remain an attractive target for these advancing tactics. But amid AI threats like deepfakes, phishing, and malicious code, AI also plays an important role in FSI security strategies. 

​In this article, originally published on Future Healthcare Today, we share best practices from occupational health for using AI in tandem with people and practices to secure data and systems against increasingly complex threats.

​Healthcare data is more valuable than ever, and cyber criminals have taken notice. The recently released Verizon 2025 Data Breach Investigative Report (DBIR) made it clear: “Healthcare continues to be a favorite target for this kind of attacker, and the urgent need for access to data in emergency situations only adds to the pressure healthcare organizations feel when their systems are all unavailable and they must resort to more old-school processes.” Occupational healthcare clinics are particularly vulnerable. They sit at the nexus of patient health and enterprise productivity, holding sensitive data that’s tightly regulated and operationally essential. A single breach here can ripple far beyond compliance fines or lost records, disrupting businesses and, in the worst cases, putting lives at risk. 

​Why Cybercriminals are Targeting Occupational Healthcare

​“Healthcare information has eclipsed financial information as the most valuable target,” said Michael Krouse, Chief Information Security Officer at Enterprise Health. “It’s not just Social Security numbers or birth dates. From addresses and phone numbers to insurance details, 

medical records can include up to 18 different data points under HIPAA. That’s a gold mine for identity theft, fraud, and even extortion.” 

​The threat goes deeper than stolen identities. Cybercriminals can also manipulate records. “Imagine if I changed your chart to say you had high blood pressure and multiple surgeries that never happened. That could directly impact your care going forward. Cybercriminals can jeopardize your health, not just your finances,” Krouse explained. Like Sutton’s Law, the motive is simple: criminals target healthcare “because that’s where the money is.” 

​At the Crossroads of Healthcare and Enterprise 

​Occupational health sits at the intersection of two security landscapes. Clinics face the same cyber risks as hospitals and health systems—phishing, insider threats, third-party vulnerabilities—while also managing enterprise-level concerns like budget constraints, vendor oversight, and workforce impact. “Threat actors are using the same vectors across industries,” Krouse explained. “But occupational health programs often have limited budgets, making it harder to stay current with training and devices needed for a robust defense. Compliance is the floor. Security means going above and beyond.” 

​The dual role of safeguarding Protected Health Information (PHI) while supporting enterprise productivity compounds the challenge. Secure interoperability across supply chains, rigorous vendor vetting, and global compliance requirements only add to the burden. 

​People as a Strong Link 

​Cybersecurity has long leaned on the cliché that “people are the weakest link.” Krouse rejects that framing. “People don’t have to be the weak link. They can be the strongest link, if they’re trained and engaged,” he said. This can be done in a myriad of ways from new hire orientations that include security training and annual reviews of policies, to monthly phishing simulations and constant reinforcement that

vigilance doesn’t end at the office door. 

​“It’s important to stress during cybersecurity training that this isn’t just for work,” noted Krouse. “Cyber awareness protects your home, your family, your community. If we’re all more secure, it makes the world better.”  

​His advice is straightforward: “If you see something, say something. If you get an email, use it as information, not as a transaction. Go to the source directly. That one habit alone can block countless attacks.” 

​Getting the Basics Right 

​Occupational health organizations don’t need exotic defenses to reduce their risk. They do, however, need discipline. Krouse highlighted several priorities: 

  • Annual security risk assessments to identify vulnerabilities and track mitigations. 
  • Encryption of data in transit and at rest. 
  • Regularly tested backups to ensure data can be restored after an attack. 
  • Endpoint protection and firewalls to block suspicious traffic. 
  • Timely patching of servers and devices to close known vulnerabilities. 
  • ​Physical safeguards like printer hygiene, locked-down fax machines, and access controls that prevent unauthorized personnel from entering the building without an employee escort, which is often referred to as tailgating.  

​Technology choices amplify risk. Electronic health records (EHRs) widen the attack surface, making vendor due diligence essential. Independent audits like SOC 2 Type 2 and HITRUST R2 provide assurance by thoroughly assessing and validating hundreds of controls against 60+ standards, from HIPAA to NIST and ISO 27001. 

​AI: Risk and Defense 

​Artificial intelligence is adding a new layer of complexity. “AI will both increase and decrease cybersecurity risk,” Krouse noted. Attackers are already using it to craft more convincing phishing campaigns and probe for vulnerabilities. But defenders can also harness AI for anomaly detection, automated response, and 24/7 monitoring. 

​Such tools as AI-driven monitoring platforms can flag unusual patterns in communication or behavior, like atypical phrasing, timing, or access requests, that may indicate phishing attempts, insider threats, or system compromises. “The question isn’t whether AI is good or bad for cybersecurity—it’s how you apply it,” Krouse said. 

​Mission-Critical Vigilance 

​In the world of occupational health, where a breach can affect regulatory standing, workforce productivity, employee trust, and even patient safety, cybersecurity is paramount. By investing in fundamentals, treating people as empowered defenders, holding vendors accountable, and approaching AI with both caution and creativity, organizations can strengthen resilience. In today’s landscape where healthcare data is under constant attack, vigilance becomes the foundation of both workforce safety and organizational resilience. 

​Learn more about transforming occupational healthcare here.