Three Hundred Security Sessions Later, I Clicked the Link

The third edition of The HealthIMPACT Brief, a new editorial series amplifying the conversations happening on the stages and in the hallways of healthcare’s best events.

An action plan from HPN West Coast 2026


I clicked a phishing link on Tuesday morning.

The training did not stop it, and the evidence says it was never going to. An eight-month randomized controlled trial across ten phishing campaigns at UC San Diego Health, published at the 2025 IEEE Symposium on Security and Privacy, found that users who had completed embedded anti-phishing training failed at a rate only 1.7 percent lower than the untrained control group. Annual awareness training showed no significant relationship to failure at all. What the training changed was what I did in the ten seconds after the click, and that is the only part worth measuring.

The email came from a colleague I have known for years, forwarding an RFP. The sender address checked out. No typos, no fake logo, nothing off about the tone. It looked like an ordinary Tuesday, so I clicked, and then the link did not go where it said it was going, and my phone got hot in my hand. I stopped. I never entered a password or downloaded anything, but I shut the phone down and reset it. I have sat through more security sessions than I can count, most of them in rooms I booked myself, which is either the punchline or the point.

The most recent a panel titled, Making cybersecurity and governance work in the real world at HPN West Coast 2026, a three-day event produced by Partnership Network Events at the Omni La Costa in San Diego, July 8 to 10. Mike Mosquito, Head of Enterprise Automation, Fox Rehabilitation, moderating. Chase Franzen, Vice President of IT Risk Management and Chief Information Security Officer, Sharp HealthCare. Rachael Hill, Chief Nursing Information Officer and Director of Clinical Systems, North Mississippi Health Services. Anthony Locascio, Chief Technology Officer, Philips.

I expected the ransomware conversation. What I got instead was a governance gap we are barely talking about.

Everyone Is Governing AI Outputs; Nobody Is Governing AI Identities

We have spent two years building committees to evaluate whether an AI tool is accurate, safe, biased or clinically appropriate. All of that is necessary, and all of it is about what the model says.

Panel at HPN West July 2026

Chase asked a different question. "How do you govern, and how do you really even inventory the agents in your environment?" An agent is not just a model producing output. It is an account. It authenticates, it holds permissions, and it reaches into systems at three in the morning under credentials somebody provisioned in a hurry.

"Healthcare is not the best at identity and access management," he said. "We have long struggled with service accounts, and now agentic work is sprawling faster than any of those things."

The sector-wide numbers back him up. The Cloud Security Alliance's May 2026 whitepaper, The Non-Human Identity Governance Vacuum, puts non-human identities at roughly 45 for every human user in the average enterprise and as high as 144 to 1 in cloud-native environments. CSA's companion survey, The State of Non-Human Identity and AI Security, reports that most organizations are still managing AI identities with legacy IAM tooling and manual processes that were never designed for systems that provision themselves.

We never solved service accounts in the first place. Now we are deploying software that introduces more non-human identities, faster, often at the request of anyone with a good idea.

Mike had already heard the workaround, from a New York health system whose plan for governing agents was to deploy an agent to supervise the other agents. He is an engineer and you could see it pain him. "The watcher's going to watch the watcher watching you," he said. "Where's the human in the loop?"

What this means if you are the CISO or the CIO: the inventory is the control. Everything downstream, least privilege, rotation, offboarding, incident scoping, depends on a list that most health systems cannot produce. Can you name every non-human identity operating in your environment and what each one is permitted to touch? Most organizations cannot answer that for their service accounts, let alone their agents. It is also why identity governance keeps appearing in HealthIMPACT programming, and the issue is much bigger than any one vendor.

Your Downtime Plan Is Undocumented And It Lives In Somebody's Memory

Rachael talked about what happens when the system goes dark. "Our nurses don't know how to do that anymore," she said. "They're not learning that in nursing school."

Panel at HPN West July 2026

The panel described running a lights-out drill with a room full of clinicians, walking them through the simulation and asking what they would do next. The younger nurses said they would go and find the older nurses.

Everybody laughed for about a second and a half, because that is the plan. It is nowhere in a binder. It runs on the clinicians who trained before the EHR and still carry those workflows in their heads, and every year there are fewer of them on the schedule. Nursing schools have no reason to teach it and health systems have no line item for it.

The consequence is measurable and it does not stay inside your walls. Dameff and colleagues in JAMA Network Open studied two San Diego emergency departments adjacent to a health system under a month-long ransomware attack. Across 19,857 ED visits, the unaffected hospitals saw significant increases in census, ambulance arrivals, waiting room times, patients who left without being seen, and length of stay. Stroke code activations went from 59 in the four weeks before the attack to 102 during it. Confirmed strokes went from 22 to 47. The authors' conclusion is the one to bring to your board: a hospital cyberattack should be treated as a regional disaster.

What this means if you are the CNIO or the COO: downtime competency is a workforce program, not an IT document. The HSCC Operational Continuity-Cyber Incident checklist and the ASPR TRACIE cybersecurity collection give you the structure. Neither one teaches a 2019 nursing graduate how to run a paper med pass. That part is yours, and it belongs in orientation and annual competencies alongside fire and code blue.

Not Table-Topped. Tested.

When Mike closed by asking whether they would pay a ransom, Rachael answered first and she answered best. "Our goal is to prepare and have a strategy where we don't have to pay that ransom," she said, and she named the isolated recovery environment that makes that possible. Then she got to the actual question. "Do you pay or don't you pay. How dead are we?"

Chase, the CISO on the panel, responded. "It's funny you're not the CISO, because that is a perfect response." Then he added the line I would take to your board. "Not table-topped, but tested. Have you actually done a restoration from your immutable, air-gapped network?"

That distinction is federal baseline, not a preference. CISA's #StopRansomware Guide sets maintaining offline, encrypted backups and regularly testing their availability and integrity as Cross-Sector Cybersecurity Performance Goal 2.R. A tabletop confirms people know their roles. A restoration confirms the data comes back, on hardware you still own, inside a recovery time your clinical operations can survive. Only one of those is a control.

And About That Link I Clicked

Chase's team stopped writing their own fake phishing emails, because "the bad actors write way better emails than I can write now, because they're all using LLMs." They pull real attacks out of their email defense platform and run those as the training campaign instead. Rachael's program has no punitive reporting at all, just a risk officer who sits down and has a conversation with anyone who clicks.

Mike asked the room to raise a hand if they had ever clicked one. Hands went up slowly and then in larger numbers.

"There's no shame in clicking the link, you just gotta learn from it."

The UCSD researchers landed in the same place from the data side. In their study, more than half of employees clicked at least one simulated phishing link across ten campaigns, and over half of those who reached the embedded training page abandoned it within ten seconds. The click rate is not a measure of your program. It is a measure of how good the lure was.

I did not raise my hand in July. I would have to raise it today. That is less satisfying than saying I never got fooled, but it is probably the only story most of us are going to get. Worth remembering the next time someone proposes measuring a security program by its click rate.

What to do Monday

Three moves, ranked. If you only fund one, fund the first.

1. Inventory the non-human identities. Owner: CISO, with the CIO on the hook for the agent list. Filter: every account that authenticates without a person attached, including service accounts, API keys, integration credentials and every agent your AI governance committee approved. The tradeoff is that this is unglamorous work with no demo at the end, and I would fund it first anyway, because every other control on this list assumes the list exists. Give it a date and a named owner, not a workstream.

2. Run one restoration, not one tabletop. Owner: CISO and the CIO's infrastructure lead, with a clinical operations observer in the room. Filter: did the data come back, on what hardware, in how many hours, and did a clinician confirm it was usable. Table-topping is cheaper and it tells you almost nothing about recovery time. Do the restoration.

3. Put downtime competency in nursing orientation. Owner: CNIO with the CNO. Filter: can a nurse hired in the last five years run a paper workflow without finding a nurse hired twenty years ago. This is the cheapest of the three and the slowest to pay off, which is exactly why it never gets scheduled.

Notice what is not on the list. Raising your phishing click-rate target. The click rate measures the attacker's copywriting, and as of this year the attackers have better copywriters than any of us.

Where This Conversation Continues

The HealthIMPACT Fall Forum is October 6 and 7 at Microsoft Times Square in New York, focused this fall on care moving outside the hospital walls faster than the workforce can adapt. Different topic, same underlying problem: technology is moving faster than the operating models, workforce and governance around it. I have one ask. Before October 6, try to produce the list of every non-human identity in your environment and what each one can reach. Then bring me the number, or bring me the reason you could not get one.

HPN East Coast runs September 30 to October 2 at the InterContinental Buckhead in Atlanta, in the same format that produced this panel.

HealthIMPACT Briefs are insights from healthcare conferences, our own and others, written for the C-suite leaders who could not be in the room. HealthIMPACT Live convenes the rooms where health system technology and clinical leaders work through this together: the Operators Table dinner series, the HealthIMPACT Fall Forum, and the Digital Health Talks podcast.

Related listening: Female Founders Series: When the EHR Goes Down, with Chao Cheng-Shorland of ShelterZoom on continuity during failure rather than disaster recovery after it. [EPISODE URL NEEDED]


HealthIMPACT Briefs are insights from healthcare conferences, our own and others, written for the C-suite leaders who could not be in the room.

HealthIMPACT Live convenes the rooms where health system C-suite technology leaders solve this work together. The Operators Table dinner series, the HealthIMPACT Fall Forum, and the Digital Health Talks Podcast. Subscribe to the newsletter at healthimpactlive.com.

Next
Next

Longevity Just Quietly Exited the Wellness Aisle