The interview partners
Prof. Dr. Patrick Da-Cruz is Professor of Business Administration and Healthcare Management at the Faculty of Healthcare Management at Neu-Ulm University of Applied Sciences (HNU) and Academic Director of the MBA program Leadership and Management in Healthcare. Before joining the HNU, Mr. Da-Cruz worked for renowned strategy consultancies in the pharmaceutical/healthcare sector and in management positions in companies in the healthcare industry in Germany and abroad.

Andreas Probst is an expert in operational resilience with a focus on risk management and business continuity management - with more than 20 years of experience in the regulated financial and insurance industry as well as in the area of IT/cyber risks. He holds a degree in business administration from the HHL Leipzig Graduate School of Management and a Master of Commercial Law (LL.M.) from Saarland University. In addition, Andreas Probst is a certified Financial Risk Manager (GARP), Business Continuity Manager (BCM Academy Hamburg) and Cyber Security Practitioner (ISACA Germany Chapter).
Cyber attacks on hospitals have increased dramatically in recent years. The consequences can be considerable. In some cases, the work of clinics can be impaired for weeks or even months. Postponed operations and treatments have far-reaching consequences, and cyber attacks can result in immense costs for hospitals, e.g. for consulting services. Against this background, how relevant is the topic of cyber security in the healthcare sector today?
Andreas Probst: In the healthcare sector today, cyber security is an existential factor for patient safety, quality of care, data protection and, in the worst case, for the continued existence of an institution. The increasing digitalization of medical processes, for example through electronic patient records or networked medical devices, makes facilities vulnerable to targeted cyberattacks. At the same time, the healthcare sector is one of the critical infrastructures - the relevance of cyber security is therefore not only high in operational terms, but also in regulatory terms. This is also underpinned by the cybersecurity action plan for hospitals and healthcare providers announced by the EU Commission in January 2025.
What impact can cyberattacks have? How do they affect patient care and the operation of clinics or practices?
Andreas Probst: Cyber attacks can have a massive impact: They often lead to IT system failures, which paralyzes diagnostics, documentation and communication. This goes hand in hand with the loss of relevant medical data, or at the very least a loss of trust in the databases. Relevant medical treatment decisions, operations or therapies are then suspended or postponed, as the risk of treatment errors - without a valid data basis - increases dramatically. In most cases, this can only be compensated for by manual (paper) processes at an emergency operating level. The situation becomes even more critical when OT (operational technology) systems are affected - such as the control of medical devices, infusion pumps or laboratory automation. In such cases, not only are organizational processes disrupted, but the lives and health of patients are also potentially at immediate risk. Such attacks can also cause considerable economic damage - for example through ransom demands, reputational damage and recovery costs.
In clinics and medical practices, IT systems play an important role both in administration and in the areas of diagnostics and therapy, e.g. in medical technology. Which areas of the IT infrastructure of clinics and medical practices are particularly vulnerable to attacks?
Andreas Probst: Systems with external interfaces - such as to laboratories, pharmacies, billing centers or cloud services - are particularly at risk. Administrative IT systems with access to sensitive patient and billing data as well as technical systems (OT systems), such as medical devices or building control systems, are also increasingly under threat. Another risk area is IoT components - networked/internet-enabled devices that communicate with each other or with central systems, such as networked blood pressure monitors, infusion pumps, temperature sensors in medicine refrigerators or cameras. Many of these devices are constantly online, but are often inadequately secured or difficult to update. This makes them a potential gateway for attackers.
There is also the human factor: phishing emails, poorly chosen, shared passwords or careless behavior are still a common attack vector. It is therefore important to take a comprehensive approach to protection that includes all digital and networked systems - regardless of whether they are located in traditional IT or medical technology.
How can healthcare facilities strengthen their resilience to cyberattacks? What are the organizational consequences?
Andreas Probst: A holistic approach is crucial: technically through segmented networks, strong authentication such as multi-factor authentication, regular updates and an appropriate backup strategy in which backups are also kept physically separate from the network. Organizationally through clear role allocations, emergency plans and regular awareness training. In addition, continuous risk and vulnerability management is essential - as is the integration of cyber security into overarching resilience and business continuity management.
Developments in IT are extremely dynamic. What developments in cyber security in the healthcare sector do you expect in the next five to ten years? What role will AI play here, if any?
Andreas Probst: I expect greater regulatory penetration, as the action plan published by the EU Commission suggests - EU directives such as NIS2 and their national implementation will also establish minimum technical and organizational standards in regulatory terms. At the same time, we will see an increase in AI-supported security systems, both for threat detection and prevention. Zero-trust architectures and the protection of medical IoT devices (“Internet of Medical Things”) will also gain in importance. However, it will remain crucial that cyber security is not seen as a technical add-on, but as an integral part of good healthcare.
Thank you very much for the interview!
The content and statements presented in the interviews reflect the perspective of the interviewees and do not necessarily reflect the position of the editorial team.






