Editorials

Cybersecurity in healthcare as a clinical competency: a conceptual proposal informed by recent evidence

Publisher's note
All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.
Received: 1 September 2026
Published: 2 September 2026
86
Views
27
Downloads

Authors

The progressive digitalization of healthcare delivery and the widespread adoption of telemedicine have significantly expanded the attack surface of clinical infrastructures.

Recent evidence shows that cybersecurity incidents do not result solely in informational or reputational harm, but are associated with measurable adverse clinical outcomes, including excess in-hospital mortality during ransomware attacks.

In this editorial, we argue that healthcare cybersecurity should be recognized, at both the operational and governance levels, as a clinical competency, on par with hand hygiene, radiation protection, and antimicrobial stewardship. We discuss the implications for healthcare workforce training, managerial accountability under the NIS2 Directive, and the regulation of telemedicine platforms.

Downloads

1. Verizon Communications Inc. 2025 Data Breach Investigations Report. Verizon Communications Inc.; Basking Ridge, USA; 2025.

2. IBM Corp. Security. Cost of a Data Breach Report 2025. IBM Corp.; Armonk, USA; 2025.

3. Agenzia Italiana per la Cybersicurezza Nazionale (ACN). La minaccia cibernetica al settore sanitario. Analisi e raccomandazioni. Edizione aggiornata, periodo gennaio 2023 - settembre 2025. ACN; Rome, Italy; 2025.

4. Neprash HT, McGlave CC, Nikpay SS. Hacked to pieces? The effects of ransomware attacks on hospitals and patients. Am Econ J Econ Policy 2026;18:256-81.

5. Neprash HT, McGlave CC, Cross DA, et al. Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum 2022;3:e224873.

6. Ponemon Institute, Proofpoint. Cyber insecurity in healthcare: the cost and impact on patient safety and care 2025. Proofpoint; Sunnyvale, USA; 2025.

7. Decreto Legislativo 4 settembre 2024, n. 138. Attuazione della direttiva (UE) 2022/2555 relativa a misure per un livello comune elevato di cybersicurezza nell’Unione (NIS2). Gazzetta Ufficiale della Repubblica Italiana n. 230, 1º ottobre 2024.

8. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices. Official Journal of the European Union, L 117, 5 May 2017.

9. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). Official Journal of the European Union, L, 20 November 2024.

10. European Commission. Proposal for a revision of Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR). COM(2025) 1023 final. Strasbourg: European Commission; 16 December 2025.

How to Cite



Sossai, P., & Fabbri, N. (2026). Cybersecurity in healthcare as a clinical competency: a conceptual proposal informed by recent evidence. TeleMedicine International, 2(1). https://doi.org/10.4081/tmi.2026.799