# Healthcare Industry

Published articles for Healthcare Industry.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Healthcare AI's real bottleneck isn't intelligence -- it's integration

DevFeed: [Healthcare AI's real bottleneck isn't intelligence -- it's integration](<https://devfeed.tech/articles/healthcare-ai-s-real-bottleneck-isn-t-intelligence-it-s-integration-50550.md>)

Original publisher: [Read original article](<https://www.cio.com/article/4223369/healthcare-ais-real-bottleneck-isnt-intelligence-its-integration.html>)

Author: Par Chadha

Published: 2026-09-18T09:00:00Z

Content type: opinion

Language: en

Sources: [CIO](<https://devfeed.tech/sources/cio.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [API](<https://devfeed.tech/topics/api.md>), [ibm](<https://devfeed.tech/topics/ibm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [artificial-intelligence-enterprise-architecture-healthcare-industry-ibm-industry-it-leadership](<https://devfeed.tech/tags/artificial-intelligence-enterprise-architecture-healthcare-industry-ibm-industry-it-leadership.md>), [contributor](<https://devfeed.tech/tags/contributor.md>), [enterprise-architecture](<https://devfeed.tech/tags/enterprise-architecture.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [healthcare-industry](<https://devfeed.tech/tags/healthcare-industry.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [industry](<https://devfeed.tech/tags/industry.md>), [integration](<https://devfeed.tech/tags/integration.md>), [it-leadership](<https://devfeed.tech/tags/it-leadership.md>), [markets](<https://devfeed.tech/tags/markets.md>), [vendors-and-providers](<https://devfeed.tech/tags/vendors-and-providers.md>)

### AI overview

The article argues that healthcare AI's operating value depends less on isolated intelligence than on integration across clinical information, coverage rules, providers, payers, care teams, and operating systems. Using IBM Watson's MD Anderson experience and prior authorization as examples, it highlights architecture, business context, interoperability, and workflow handoffs as central challenges, including upcoming CMS FHIR API requirements.

### Source excerpt

In 2012, MD Anderson Cancer Center began working with IBM on one of the most ambitious experiments in healthcare AI. The premise was compelling: combine the knowledge of a leading cancer center with Watson's computing power and help physicians make better treatment decisions. Five years and roughly $62 million later, MD Anderson allowed the contract to expire before Watson had been used to treat an actual patient. A university audit documented procurement problems, cost overruns and delays. The Journal of the National Cancer Institute also described the challenge of assimilating Watson into a hospital environment where important information lived in physician notes, medical shorthand and electronic records that the system could struggle to interpret. I take a broader lesson from that history. Intelligence can be impressive in isolation and still create little operating value when it cannot understand the information around a process, participate in the work and hand the next action to the right system or person. The same operating challenge has returned with agentic AI. Healthcare processes can cross clinical information, coverage rules, providers, payers, care teams and multiple operating systems. As CIO has recently noted in its coverage of enterprise architecture for agentic AI, traditional interfaces can move data between systems without supplying all the business context an agent may need to operate across them. In my experience, that is where the architecture problem begins. The problem between the systems Prior authorization is a useful example because it appears simple from the outside. A request is submitted and a decision comes back. Inside the enterprise, the process may depend on eligibility, clinical documentation, coverage requirements, information from a provider and a review that may require professional judgment. Each component can function well, and the overall process can remain slow because the difficult work often sits between systems. Beginning

## State of Pentesting in the Healthcare Industry

DevFeed: [State of Pentesting in the Healthcare Industry](<https://devfeed.tech/articles/state-of-pentesting-in-the-healthcare-industry-54164.md>)

Original publisher: [Read original article](<https://www.cobalt.io/blog/state-of-pentesting-in-healthcare-industry>)

Author: Cobalt

Published: 2026-08-18T15:25:32Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog-4.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [healthcare-industry](<https://devfeed.tech/tags/healthcare-industry.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [security](<https://devfeed.tech/tags/security.md>), [state-of-pentesting](<https://devfeed.tech/tags/state-of-pentesting.md>)

### AI overview

This overview examines penetration testing in healthcare using five years of Cobalt findings and a 2026 survey of security leaders and practitioners. Healthcare organizations remediate some high-risk findings quickly but conduct less proactive, programmatic testing than other sectors, leaving a longer backlog of unresolved findings.

### Source excerpt

The healthcare industry closes high-risk findings faster than almost any sector, by one measure, but security teams in the industry are also more anxious about threats than other industries, and the industry has a lower rate of programmatic testing than any other sector. This overview of the state of pentesting in healthcare pairs five years of Cobalt pentest findings with our 2026 survey of security leaders and practitioners to profile how the sector finds, fixes, and thinks about security risk.. The healthcare industry runs less proactive penetration testing than most sectors, leaning on compliance-driven rather than continuous programs. However, there is a contradiction in the findings: the healthcare industry posts one of the fastest mean remediation times of any sector, but by a more rigorous measure (half-life, the time to clear half of all high-risk findings including those still open), it sits mid-pack. It's fast on what it fixes; slower to work through the whole backlog. Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) - 2026 survey of 455 security leaders and practitioners (Emerald Research). The high-risk remediation funnel Every high-risk pentest finding runs this gauntlet, from discovery to closure. The industry moves quickly on what it fixes, but the half-life shows a longer tail of findings still open. 9% of findings are high-risk -> 86% of those get resolved -> 37d mean time to remediate -> 55d high-risk half-life 39 % run a programmatic pentesting cadence (lowest of the major sectors) 81 % say AI needs a strategic pause to recalibrate (highest of any sector) 56 % are compliance-driven rather than programmatic (highest of any sector) Where the healthcare industry stands: remediation half-life by sector Chart: the time to remediate half of all high-risk findings. Lower is better. The healthcare industry sits mid-pack on half-life (55 days), tied with the finance industry and well behind the leaders. That is worth pausing on,