Healthcare Security at Machine Speed: $17M Ransomware & AI Adversaries

Date:
Tuesday, November 10
Time:
3pm ET / 8pm BST
Bishop Fox virtual session on securing healthcare at machine speed and $17M ransoms, AI adversaries.

AI is changing how healthcare operates and how adversaries attack it. With average healthcare ransomware demands approaching $17 million, can healthcare security teams detect and respond to attacks as quickly as AI-enabled adversaries can carry them out?

Join us for a virtual session on how AI is changing healthcare security and what it takes to protect patient care and operations, featuring:

  • Farzan Karimi, Deputy CISO, Executive Director at Moderna, who leads security at a global pharmaceutical and biotech organization
  • Matthew B. Welling, Partner at Holland & Knight, who operates the nation's largest healthcare law practice
  • Zach Moreno, AVP Consulting at Bishop Fox, who has spent years testing healthcare defenses firsthand

Attendees will leave with perspectives on:

  • Preparing for AI on both sides of an attack. AI healthcare applications introduce new access paths and dependencies across care environments. Adversaries use the same technology to accelerate reconnaissance, social engineering, and exploitation. Where do existing defenses hold up, and which assumptions need testing?
  • Planning for disruption before it happens. Healthcare ransomware can combine data theft with interrupted services, putting containment decisions and recovery plans under immediate pressure. Readiness depends on how well security teams and clinical leaders coordinate when their decisions affect patient care.
  • Protecting connected care environments. Medical device cybersecurity extends beyond patching, especially when legacy systems support essential care and cannot easily be taken offline. Access restrictions and containment measures must account for device availability, with biomedical engineering and clinical stakeholders involved in planning.
  • Setting investment priorities as AI adoption expands. AI healthcare deployments raise questions about who approves new uses, evaluates security implications, and manages access to sensitive information. Clear accountability helps leaders direct healthcare security investment toward the exposures that carry the greatest operational consequences.

These priorities converge in the workflows that health systems depend on every day. As AI healthcare adoption grows, leaders need evidence that their controls protect sensitive information and limit what a compromised account or connected application can reach. That evidence also helps determine where to strengthen existing strategies and where a different approach is needed.

Healthcare ransomware readiness requires response plans that account for compromised identities and data exfiltration, alongside disruption across interconnected services. Medical device cybersecurity belongs in those plans, with escalation paths that reflect the clinical consequences of isolating a device or interrupting a workflow.

This session connects healthcare security strategy to these operational decisions: how to evaluate response assumptions, assign ownership across departments, and prioritize investments that support continuity of care.


    Farzan Karimi Moderna

    About the speaker, Farzan Karimi

    Deputy CISO, Executive Director, Moderna

    Farzan Karimi is the Deputy CISO, Executive Director at Moderna, where he leads incident response, security engineering, and offensive security. Over 20 years in offensive security, he has built and led offensive security programs at Google, Microsoft, Electronic Arts, and Moderna.


    Bfx25 welling matt web

    About the speaker, Matthew B. Welling

    Partner at Holland & Knight

    Matthew B. Welling is an attorney at Holland & Knight and member of the Data Strategy, Security & Privacy Team and Energy Team. Matthew has a deep technical background that he leverages to represent clients in a wide range of counseling and regulatory matters.

    Matthew has advised numerous clients on appliance energy conservation standards before the U.S. Department of Energy (DOE), including multiple appeals to the Federal Energy Regulatory Commission (FERC) under the Energy Policy and Conservation Act (EPCA) and before the California Energy Commission (CEC).


    Zach moreno

    About the speaker, Zach Moreno

    AVP Consulting

    Zach Moreno is AVP Consulting at Bishop Fox and focuses on application penetration testing (static and dynamic), vulnerability risk management, network penetration testing (external and internal), and dynamic application security testing. He has advised Fortune 500 brands and startups in industries such as healthcare, financial services, education, and technology.

    Ready to get started? We can help.

    Contact Us