​​Combatting AI Threats with AI, People, and Practices: Three Lessons from Occupational Health​

Become an Insider.

Get Government Technology Insider news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

​When schools are overcrowded and under-resourced, cybersecurity may not top the list of priorities for administrators. But ransomware attacks alone jumped 23 percent year over year in the first half of 2025, making education the fourth most targeted sector this year. The personal and health information, such as social security numbers, held by educational institutions make them attractive targets for financially motivated threat actors. And as attacks grow more sophisticated, the technology and tactics that fended off more obvious threats are no longer sufficient to protect students and their data. 

In this article, originally published on Future Healthcare Today, we share best practices from occupational health for securing data with limited resources. 

​Healthcare data is more valuable than ever, and cyber criminals have taken notice. The recently released Verizon 2025 Data Breach Investigative Report (DBIR) made it clear: “Healthcare continues to be a favorite target for this kind of attacker, and the urgent need for access to data in emergency situations only adds to the pressure healthcare organizations feel when their systems are all unavailable and they must resort to more old-school processes.” Occupational healthcare clinics are particularly vulnerable. They sit at the nexus of patient health and enterprise productivity, holding sensitive data that’s tightly regulated and operationally essential. A single breach here can ripple far beyond compliance fines or lost records, disrupting businesses and, in the worst cases, putting lives at risk. 

Why Cybercriminals are Targeting Occupational Healthcare 

Healthcare information has eclipsed financial information as the most valuable target,” said Michael Krouse, Chief Information Security Officer at Enterprise Health. “It’s not just Social Security numbers or birth dates. From addresses and phone numbers to insurance details, 

medical records can include up to 18 different data points under HIPAA. That’s a gold mine for identity theft, fraud, and even extortion.” 

​The threat goes deeper than stolen identities. Cybercriminals can also manipulate records. “Imagine if I changed your chart to say you had high blood pressure and multiple surgeries that never happened. That could directly impact your care going forward. Cybercriminals can jeopardize your health, not just your finances,” Krouse explained. Like Sutton’s Law, the motive is simple: criminals target healthcare “because that’s where the money is.” 

At the Crossroads of Healthcare and Enterprise

​Occupational health sits at the intersection of two security landscapes. Clinics face the same cyber risks as hospitals and health systems—phishing, insider threats, third-party vulnerabilities—while also managing enterprise-level concerns like budget constraints, vendor oversight, and workforce impact. “Threat actors are using the same vectors across industries,” Krouse explained. “But occupational health programs often have limited budgets, making it harder to stay current with training and devices needed for a robust defense. Compliance is the floor. Security means going above and beyond.” 

The dual role of safeguarding Protected Health Information (PHI) while supporting enterprise productivity compounds the challenge. Secure interoperability across supply chains, rigorous vendor vetting, and global compliance requirements only add to the burden.  

​People as a Strong Link  

​Cybersecurity has long leaned on the cliché that “people are the weakest link.” Krouse rejects that framing. “People don’t have to be the weak link. They can be the strongest link, if they’re trained and engaged,” he said. This can be done in a myriad of ways from new hire orientations that include security training and annual reviews of policies, to monthly phishing simulations and constant reinforcement that

vigilance doesn’t end at the office door.

​“It’s important to stress during cybersecurity training that this isn’t just for work,” noted Krouse. “Cyber awareness protects your home, your family, your community. If we’re all more secure, it makes the world better.”  

​His advice is straightforward: “If you see something, say something. If you get an email, use it as information, not as a transaction. Go to the source directly. That one habit alone can block countless attacks.” 

Getting the Basics Right 

 Occupational health organizations don’t need exotic defenses to reduce their risk. They do, however, need discipline. Krouse highlighted several priorities: 

  • Annual security risk assessments to identify vulnerabilities and track mitigations. 
  • Encryption of data in transit and at rest. 
  • Regularly tested backups to ensure data can be restored after an attack. 
  • Endpoint protection and firewalls to block suspicious traffic. 
  • Timely patching of servers and devices to close known vulnerabilities. 
  • ​Physical safeguards like printer hygiene, locked-down fax machines, and access controls that prevent unauthorized personnel from entering the building without an employee escort, which is often referred to as tailgating.  

​Technology choices amplify risk. Electronic health records (EHRs) widen the attack surface, making vendor due diligence essential. Independent audits like SOC 2 Type 2 and HITRUST R2 provide assurance by thoroughly assessing and validating hundreds of controls against 60+ standards, from HIPAA to NIST and ISO 27001. 

​AI: Risk and Defense 

Artificial intelligence is adding a new layer of complexity. “AI will both increase and decrease cybersecurity risk,” Krouse noted. Attackers are already using it to craft more convincing phishing campaigns and probe for vulnerabilities. But defenders can also harness AI for anomaly detection, automated response, and 24/7 monitoring. 

​Such tools as AI-driven monitoring platforms can flag unusual patterns in communication or behavior, like atypical phrasing, timing, or access requests, that may indicate phishing attempts, insider threats, or system compromises. “The question isn’t whether AI is good or bad for cybersecurity—it’s how you apply it,” Krouse said. 

Mission-Critical Vigilance 

In the world of occupational health, where a breach can affect regulatory standing, workforce productivity, employee trust, and even patient safety, cybersecurity is paramount. By investing in fundamentals, treating people as empowered defenders, holding vendors accountable, and approaching AI with both caution and creativity, organizations can strengthen resilience. In today’s landscape where healthcare data is under constant attack, vigilance becomes the foundation of both workforce safety and organizational resilience.  

​Learn more about transforming occupational healthcare here. 

​