The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Healthcare Strategies
Healthcare Strategies artwork

Exploring rural healthcare cybersecurity resource constraints

Healthcare Strategies · 2025-06-23 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

41 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality8 / 20
Guest Caliber11 / 20
Specificity & Evidence7 / 20
Conversational Craft7 / 20

Rural healthcare providers face a fundamentally different cybersecurity landscape than their larger counterparts, constrained by limited IT staff, outdated technology, and competing budget priorities. Jim Rotor, VP of IT at Lakewood Health System in Minnesota and co-lead of the HSCC's resource constrained provider cybersecurity task group, explains how smaller facilities and critical access hospitals often have one person managing multiple IT roles that would be distributed across dedicated specialists (CIOs, CSOs, network admins) at larger systems. The interviews revealed common themes: workforce shortages, outdated systems as the only affordable option, and funding constraints affecting both operating capital and reimbursement strategies. Key challenges include attracting and retaining cybersecurity talent in rural areas with lower salaries and limited career growth, managing third-party vendor risk without dedicated oversight resources, and balancing security investments against competing clinical priorities like MRI systems. The episode explores practical solutions including automation frameworks, outsourced managed services, incentive-based reimbursement models rather than penalties, and leveraging free resources from CISA and the HSCC. Rotor emphasizes relating cybersecurity investments to patient safety and risk tolerance to secure board buy-in.

Key takeaways

  • →Rural healthcare facilities typically lack the dedicated IT staff (CIOs, CSOs, system admins) that larger systems have, forcing single staff members to wear three or four different roles with only partial time allocated to cybersecurity.
  • →Shared vendor responsibility models are emerging but not yet standard - advocating vendors take 50/50 risk responsibility and ensure proper configurations (not leaving default admin credentials) would significantly improve security posture.
  • →Free resources from CISA, the Health Sector Coordinating Council, and collaboration with peer systems can help under-resourced providers prioritize and implement cybersecurity improvements without major capital expenditure.
  • →Rural staff attraction and retention could be improved through government-backed loan forgiveness programs (similar to the RA program for providers) targeted at cybersecurity roles in critical access hospitals and rural emergency systems.
  • →Patient safety messaging is the most effective strategy for securing board approval of cybersecurity funding when competing against clinical capital priorities like imaging equipment.

Guests

Jim Rotor

Topics in this episode

NIST frameworkCISA (Cybersecurity and Infrastructure Security Agency)Managed Service Providers (MSPs)Critical access hospitalsLakewood Health SystemHealth Sector Coordinating Council (HSCC)Phishing trainingThird-party vendor risk assessmentDisaster recovery and business continuityDetection and response technology

Questions this episode answers

What are the main cybersecurity challenges unique to rural healthcare providers compared to larger systems?

Rural healthcare facilities lack dedicated IT staff (forcing one person to perform multiple roles), have outdated technology due to budget constraints, lack advanced security tools, and struggle with workforce shortages and limited reimbursement - making them more vulnerable to cyber threats and less able to secure patient data and enable remote care.

How can rural healthcare IT leaders fund cybersecurity improvements when competing with clinical priorities?

Frame cybersecurity as patient safety, quantify the risk the organization is willing to accept if not implementing a security measure, and propose incentive-based reimbursement models (bonuses for implementing detection and response technology) rather than penalty-based approaches that further squeeze budgets.

What free resources are available to help under-resourced healthcare providers improve cybersecurity?

CISA offers free external testing of IPs to identify vulnerabilities, the Health Sector Coordinating Council publishes reports and training videos, and collaboration with peer local health systems can help smaller providers share resources and learn what others are doing.

How should smaller healthcare providers manage third-party vendor risk with limited resources?

Conduct risk assessments with vendors using either homegrown spreadsheets or dedicated software, and advocate for shared responsibility models where vendors take 50% of the risk by ensuring proper configurations and updates rather than leaving default credentials and settings.

What incentives could help attract cybersecurity talent to rural healthcare organizations?

Government-backed student loan forgiveness programs targeted at cybersecurity professionals working in critical access hospitals or rural emergency systems, remote work opportunities, and on-the-job training programs could help overcome the challenge of lower rural salaries and limited career growth opportunities.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode surfaces a few practitioner-level observations - remote work as a double-edged sword, log monitoring getting only a fraction of staff time - but much of the runtime is consumed by well-known problems (rural pay gaps, outdated systems) without unpacking mechanisms or solutions at any depth.

sometimes they only have half a day or eight hours of their 40 hour work week that gets dedicated to that
someone living in this area now could work for a big urban company and get the urban salaries

Originality

8 / 20

The idea of shifting vendor liability to a 50/50 model and proposing rural cybersecurity loan forgiveness analogous to provider incentive programs are genuinely non-generic framings, but they're briefly mentioned and not developed; the rest of the conversation recycles well-worn healthcare IT discourse.

a lot of the facilities said they want to see a shift where today typically the vendor doesn't have to take on any of the risk. If we can get to even 50 50, there'd be a lot of leaps and bounds
can there be some sort of rural loan forgiveness for their student loans If they go into cybersecurity and they work in a critical access, a rural emergency system

Guest Caliber

11 / 20

Jim Rotor is a genuine practitioner - sitting VP of IT at a rural health system and co-lead of a 42-executive HSCC research effort whose findings reached HHS, the White House, and Congress - giving him real operational and policy credibility, though his organization is small-scale.

this task group interviewed 42 executives across 31 states from entities such as rural and critical access hospitals, small fit physician practices, and federally qualified health centers
HSDC deliver these results to HHS, the White House and the House and Senate Rural Health caucuses in May, 2025

Specificity & Evidence

7 / 20

The 42-executive, 31-state sample is the strongest concrete data point; otherwise the episode relies on anecdote and approximation ('probably 15 years ago,' '3, 6, 9 months,' 'a hundred thousand dollars on this software or whatever value') and never names a specific incident, breach cost, vendor, or quantified outcome from the HSCC research.

this task group interviewed 42 executives across 31 states
I look at my system admin started here probably 15 years ago and probably will work here another 10 15

Conversational Craft

7 / 20

The host asks coherent, logically sequenced questions but they are uniformly open-ended and invitational; there is no pushback, no probing on the HSCC findings, and affirmations like 'That's great advice' and restating the guest's answer replace genuine follow-up.

what are some of those unique challenges that smaller rural healthcare providers face compared to their larger counterparts?
That's great advice.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cybersecurity18rural17healthcare14help14smaller12sure12risk12health9organizations9system8challenges8ones8resources8funding7cyber7different7

Episode notes

Rural and small healthcare entities face the same cyber threats as the nation's largest health systems, but often lack the tools to combat them in the same way. From funding scarcity to workforce shortages, rural healthcare organizations must balance the need for an effective cybersecurity program with ongoing operational constraints. How can rural healthcare providers manage risk while understaffed and underfunded? Featuring: Jim Roeder, vice president of IT at Lakewood Health System In this episode, we'll cover The unique cybersecurity challenges that small and rural healthcare providers face compared to their larger counterparts How the cybersecurity workforce shortage has impacted rural entities' ability to attract and retain cyber talent What types of government and community support would help rural healthcare organizations improve their cybersecurity programs and more! References Understaffed, underfunded: Health IT security for small, rural providers Rural healthcare cybersecurity aid grows, but challenges persist To learn more about healthcare cybersecurity,

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

I think one of the refreshing things was I quickly realized I'm not alone in what I face. Being a smaller rural facility, the workforce shortages, running some outdated systems just because I have to. That's the only option you have and the funding constraints. Hello and welcome to Healthcare Strategies.

I'm Jill McKean, associate editor of Health Tech Security. Today we're joined by Jim Rotor, vice president of IT at Lakewood Health System, a nonprofit rural healthcare system in Staples, Minnesota. Welcome, Jim. Thanks for having me.

So today we're talking about cybersecurity challenges that come along with being a rural healthcare organization. For some context, our guest, Jim, recently served as a co-lead on the health sector coordinating council's resource constrained provider cybersecurity task group. So this task group interviewed 42 executives across 31 states from entities such as rural and critical access hospitals, small fit physician practices, and federally qualified health centers. They conducted these interviews to learn how resource constrained entities approach cybersecurity and what kind of government and community support would really help them bolster their cybersecurity programs.

HSDC deliver these results to HHS, the White House and the House and Senate Rural Health caucuses in May, 2025. So we'll be discussing the results of that report as well as the challenges that rural and under-resourced healthcare entities face on a daily basis. So to begin, Jim, as VP of IT at Rural Healthcare System, what are some of those unique challenges that smaller rural healthcare providers face compared to their larger counterparts? Yeah, I think the main thing that the smaller ones kind of face that we heard in the interviews and speaking from our own lens is we lack some of the dedicated IT staff that they typically have.

They have a lot of your CIOs, CSOs, network admins, system admins. When you start looking at these smaller facilities, they either have a person doing three or four of those roles or they have a lot of your virtual services or an MSP helping them out. The other thing too is they typically lack the financial resources that the larger ones have, and so then that comes out to play. The smaller ones are usually working with outdated technologies.

They're not able to upgrade to the newer things or have some of the higher end tools that the larger ones have. And so they're typically a little more vulnerable to cyber threats because of that. And then just it's hard for them to make sure they're securing everything the way they should, which that can come in. The patient data's more apt to be hacked or even their clinicians have a harder time having remote access and doing even remote care.

And so I think that's where you see the smaller facilities at the disadvantage compared to the larger ones. Not to say we're all facing the same realities of the threats that come with it, but it's just in my mind, the rural and smaller facilities are probably a little more susceptible to. For sure. And like you said, these entities are all facing lots of cyber threats on a daily basis, but the smaller ones might have more funding and workforce challenges to really combat those threats effectively.

So we previously mentioned the HSCC task group that you were part of, and you interviewed 42 executives from various resource constrained healthcare organizations. Were there any really surprising commonalities or differences in the challenges reported across this diverse set of organizations? Yeah, I think one of the refreshing things in doing it was I quickly realized I'm not alone. What I face being a smaller rural facility, a lot of them had the same themes that the workforce shortages that we face running some outdated systems just because have to, that's the only option you have.

And the funding constraints, whether it's your operating capital budgets or the reimbursement strategies that are available to you, those are similar to all of them that we talked to. Some of the differences that jumped out on me was that what we prioritize as the number one things we have to do was maybe three or four on the list out of another one where they're looking more at making sure that they're ready for disaster recovery or business continuity, and maybe we're focusing more on the risk and compliance side of things.

The prioritization of things was a little different for everybody we talked to, but it was probably on their list just not as high or as low as other ones. Yeah, it's interesting to see in that research how different organizations approach prioritizing certain cybersecurity and compliance activities given their limited resources. So I'd like to dive into that more. Talking about the cybersecurity workforce shortage, which I know has impacted organizations not just in healthcare and not even just in rural areas.

It's a widespread issue. I'm curious from your perspective, what are some challenges that come with attracting and retaining cyber talent in a rural area or at an under-resourced healthcare entity? And also what incentives might help attract cyber talent in the future? Yeah, I think some of the challenges are around, typically your rural areas are going to have lower salaries and it takes, the person wants to live in kind of that geographic location while you're comfortable being 30 minutes away from restaurants to go eat at or activities to do with a family.

And then two, one we run into a lot is I look at my system admin started here probably 15 years ago and probably will work here another 10 15 and someone that wants to move into that role or have some career growth. It's just it's not there because there's limited job roles and limited opportunities in the rural area. The things we've tossed around to try to help attract talent to come in, can there be some sort of rural loan forgiveness for their student loans If they go into cybersecurity and they work in a critical access, a rural emergency system, can that be forgiven somehow through the government?

Much there is programs for providers if they go into that, the RA program for instance, and you look at remote work opportunities, sometimes that's a blessing and a curse for us because yes, we can offer that to work remotely, but also at the same time, someone living in this area now could work for a big urban company and get the urban salaries. And so it goes both ways on something like that. But those are what we look at for ways to try and help out. So there's a barrier to entry for some of these prospective employees may be a barrier to growth in those roles.

And then there's also the competition for other higher paying jobs in different regions. Yeah, exactly. It's definitely a complex issue for sure. So I think it's fair to say that amid these workforce challenges, a lot of healthcare IT and cybersecurity teams probably don't have the ideal amount of resources across the board.

So that might mean that one person's doing the job of three people or however it might work out. So how does the reality of staff wearing multiple hats in a smaller healthcare organization impact your approach to security planning? Yeah, like I mentioned before, we have to wear sometimes three or four different hats and do different job roles. I think the problems we're aware of with that or that we got to be cognizant of is we're not able to dedicate that time to cybersecurity all the time.

Or it'd be lovely to have someone that's reviewing our logs and check in on things and any alerts every day in their role. But the truth of the matter is sometimes they only have half a day or eight hours of their 40 hour work week that gets dedicated to that. And so sometimes you get those gaps in oversight. And so anytime you can have some sort of automation or framework to follow that, some guidance like that goes a long ways.

And you have to sometimes start weighing that, okay, what would it cost for me to outsource this? Can I find a company to do these two or three things for X amount of dollars that's cheaper than hiring someone and I'm able to not have to worry about whatever those gaps are and can sleep better at night because I know it's being managed and looked at. Yeah, I can see how being able to outsource some of these functions would be really helpful in just reducing that burden across your small team.

And I know that we've already discussed this a bit, but funding for cybersecurity really remains a bottleneck for a lot of these resource constrained entities. I'm curious, what strategies have proven most effective when trying to advocate for cybersecurity funding to leadership and board members when there are competing priorities? I think the biggest thing I always try to do is try to relate it to patient safety when trying to make sure we're taking care of our patients, securing their data, and then just if we don't implement said product or said strategy, what's the risk we're willing to take on or that we're going to have to be comfortable with?

And just trying to show that to them so they can have an understanding of, yes, okay, we're not comfortable spending what a hundred thousand dollars on this software or whatever value by doing so and saying, so this is the risk we're going to take on and be aware of. And when there is that risk taken on coming back to it even in 3, 6, 9 months and saying, are we still comfortable with this? If not, here's the opportunity we have or what we can invest in or implement to take that risk and get rid of it.

But at the end of the day, the biggest thing I always try to do is relate it back to our patients and their care. For sure. And that's a big theme in this sector I think, is that cybersecurity is a big aspect of patient safety. So being able to communicate that to the board.

And I often hear the predicament of a hospital choosing between an MRI system or a cybersecurity software, things like that. So it's certainly a tricky situation for these entities. I'd also love to talk about the role of vendors. I know that they're such a critical part of any healthcare organization's ecosystem and their valued partners, but they can also expose these organizations to some third party risk.

So given the resource constraints that we've discussed, what are some of those approaches for managing third party risk as a smaller provider that might not have the resources to oversee however many vendors they're dealing with? Yeah, I think that's a big challenge for the smaller facilities. It's hard to do that continuous monitoring of your third parties always knowing what's going on, asking them, have they done their due diligence, can they provide reports? I think anytime you bring on a third party, it's vital that you do some sort of risk assessment with them, whether that's a homegrown spreadsheet that you use within your facility or it is a software that can help manage that.

I think that's important that you go through that and make sure that's in place. One of the things that came out too when we did the interviews with the health sector coordinating council was a lot of the facilities said they want to see a shift where today typically the vendor doesn't have to take on any of the risk. If we can get to even 50 50, there'd be a lot of leaps and bounds that we could gain and help implement more cybersecurity and have them take on that risk, make sure things are getting updated, that things are set up the way they should be, hear about it all the time that things are implemented in the default admin user and password are just left.

Just little things like that where they can help go through and okay, this is what it is, but make sure you change this before we go to production. Things like that would help. For sure. Making it a shared responsibility between the vendors and system owners, things like that would go a long way.

Would you say that's not the norm at the moment for that to be a shared responsibility? Yeah, we're not there yet. I will say if I look back three, five years ago, the shift has already started happening, which is great to see. Great.

Yeah. And I know this was mentioned a lot in the HSCC report, just the role that different industry associations, vendors, government agencies, can play in supporting cybersecurity at under-resourced healthcare providers. So I'm curious your thoughts on the role that these organizations can play and how subsidies and reimbursement incentives could also help fill the gap for these organizations? I think if somehow they could come together and whether it's, obviously funding always helps.

I don't think any small rural facility would turn a town, but even something as simple as training, helping end users understand the risks of clicking on things in emails, things like that. We all typically do phishing tests now and then even training your IT staff I think would be great. A lot of times you recruit talent and they have to take on all those roles. They're learning on the job learning as they figure it out.

So any training that could help or even help us, okay, here's the NIST framework, here's how you can relate it and implement things within your facility, helping us understand that and get those things into place. And then if there's any reimbursement or subsidy, any type of incentive that could help offset security upgrades. So you have that framework, okay, we got to implement some sort of detection and response technology. Okay, if you do that, we'll give you some sort of extra reimbursement or bonus payment instead of you got to have this or you take, there's a haircut off your reimbursement.

Try and get more to the bonus side of things for implementing the right things. For sure. And I could see how incentives would go a long way when you're making that choice between priorities. If you're able to get some funding back for good cybersecurity, that would positively incentivize people to take those actions.

And it's interesting you also mentioned the cybersecurity workforce training across the organization. Another instance of shared responsibility for cybersecurity because we know that it only takes one employee to click a bad link to start a cyber attack. So that's a really critical piece of the puzzle there. I'm curious also what practical advice you'd offer to IT leaders at similar organizations to yours who are trying to balance security needs against operational constraints?

Yeah, that's a good question. Something I always try to make my peers aware of and as I talked to with, even though the ones in the interviews we did, was there's a lot of free resources out there now, and there's more and more that become available, like the Health Sector Coordinating Council, we publish different reports to try to help 'em, training videos that they can leverage and give to their employees. CS a does a lot of stuff depending on what vertical you're in, for example, like the healthcare vertical.

They'll do external testing of your ips to make sure you know what vulnerabilities are out there, things like that. If you're not taking advantage of 'em, try to do that. Collaboration's a big one. We've touched on that.

Local health systems or things like that. Find out what they're doing. Can you do that or can you share some resources? Prioritizing what you want to work on, trying to focus on what's the biggest risk we have here that for an cyber attack and how can we address that?

And then probably like that mantra, we talked about it, cyber safety is patient safety. We talk about that a lot on the health sector coordinating council, and that's the slogan we utilize on a lot of things, but that's really what it comes down to. Definitely. That's great advice.

So we know that resources are really minimal, but there are resources at a low cost or no cost that can help these organizations improve their security posture and smartly prioritize risk management tasks. So really appreciate you joining us today. It was a pleasure. Yes, thanks for having me.

And thank you listener for tuning in. If you liked what you heard, head over to Spotify or Apple and drop us a review. We'll be choosing some of our reviews to be read on the show in appreciation. So keep listening through to the end because you might get name dropped.

See you next time. Music by Kyle Murphy and production by me, Kelsey Waddill. This is an Informa Tech target production.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Fortune 500s Use Procurement to Manage Vendor AI Training Data RightsEnterprise Tech with Fexingo · on NIST framework90 / 100
  • Why Medicare’s Hospital Wage Index Exceptions Jumped 60%A Health Podyssey · on Critical access hospitals85 / 100
  • How Smaller Businesses Beat Bigger Competitors with Gareth LockwoodSpotlight on B2B Marketing · on Managed Service Providers (MSPs)84 / 100
  • Ben's Den LIVE! at Fuse 2026 | AI in Healthcare: Beneath the Frothy SurfaceBen's Den · on Critical access hospitals82 / 100
  • From Uber to Exaba: AJ Tills takes on Big Tech storageThe Business of Tech · on Managed Service Providers (MSPs)75 / 100
  • Transforming Healthcare Through Shared Medical Appointments: A Conversation with Dr. Kathleen FindlayThe Reverse Mullet Healthcare Podcast · on Critical access hospitals72 / 100

More from Healthcare Strategies

All episodes →
  • Pursuing strategic partnerships to tackle Cobalt Strike abuse85 / 100
  • Reshaping healthcare revenue cycle management with AI
  • Balancing technology and touch with virtual nursing programs
  • FDA ends GLP-1 compounding for semaglutide, tirzepatide
  • Peer navigators: the soul of community-based street medicine
Explore the best B2B Ops podcasts →
All Healthcare Strategies episodes →