Hospital IT pros are understaffed and overwhelmed: report
Poll data suggests a quarter of healthcare IT pros are “at risk of burnout.”
• 4 min read
Jason Elrod, VP and CISO at MultiCare Health System, a healthcare network in the Pacific Northwest covering 13 hospitals, describes his more than 30-person team as a “lean, mean, fighting security machine.”
But even lean and mean comes with challenges, especially when the job involves keeping critical healthcare machines on and attackers away, all while ensuring the cybersecurity team doesn’t become too tired and perspired.
“In most industries, downtime is measured primarily in dollars,” Elrod, also executive advisor at cybersecurity company Elisity, told IT Brew. “In healthcare, eventually you’re measuring it in clinical consequences, and so that changes how you make technology decisions, and it’s rough for IT professionals.” To that end, IT teams at MultiCare have to measure both cyber risk as well as impact on patients. “If…the air conditioning goes out in the summer or the heater goes out in the winter at the healthcare system: huge impact on patient care,” Elrod said. “We shift to the things that are the most impactful to the delivery of the mission, which is safe patient care.”
Cybersecurity—STAT! A new report from networking-as-a-service company Nile of just over 300 global IT healthcare pros, including C-level leaders and networking and security practitioners, concluded that “cybersecurity is the dominant concern, disruption to clinical systems is common rather than rare, and the teams responsible are frequently stretched.” For example:
- About 6 in 10 of those surveyed (61%) are not confident or only slightly confident in their ability to contain a cyberattack.
- Approximately 1 in 5 (21%) admitted to being “critically understaffed and at risk of burnout.”
Driving factors for this cyber-stress, according to the report, include IT pros’ role in protecting and managing a healthcare environment’s high-value patient data, as well as “life-critical uptime that gives attackers leverage, and a large attack surface of connected and often unpatchable medical devices.”
According to a report from research site Comparitech, the healthcare sector faced over 2 cyberattacks per day, on average, in the first half of 2026—a nearly 14% increase from the second half of 2025. Median ransom demands on healthcare providers during H1 of 2026 reached $310,000.
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
We’re all tired, OK? Cybersecurity and IT burnout is a familiar story that hits all sectors. Nonprofit training organization ISC2, which conducted a cross-industry survey in 2025 of over 16,000 global cybersecurity professionals, found that almost half (48%) admitted to “feeling exhausted from trying to stay current on the latest cybersecurity threats and emerging technologies.” Meanwhile, 47% said they’re often overwhelmed by their workloads.
One way to prevent burnout, according to Elrod, is to eliminate not the hard tasks, but the pointless work. Elrod knows plenty of engineers who jump at a difficult problem. “If I’m asking that same engineer to manually compensate every week for a broken process that we’ve known about for three years, or God forbid, 15? That’s different,” he said.
No rest for the techie. Jim Francis, chief technology officer and vice president of IT shared services at Houston Methodist Health System, supports nine hospitals and close to 300 physician practices. Francis and his staff of about 250 employees have to deal with the familiar pressures of connected devices, 24/7 uptime, electronic patient records, high hardware costs, and tired team members.
To that long list, you can add one more challenge, Francis said: “I think the onslaught of AI has really risen the stakes for cyber.”
Francis added that he has seen a rise in cyberattacks—across all industries— in the past two years: “AI is going to be the way for [threat actors] to be able to continuously hit you over and over again and at different angles at the same time.”
Francis argues that easing burnout begins with treating IT as a mission-critical, not back-office operation. That includes giving teams clear priorities, he said, with visible executive backing, and enacting thoughtful incident-escalation procedures and support for those taking on after-hours workloads. Recommended security practices include a familiar combination of strong identity controls, strict patching and segmentation, and 24/7 monitoring to fight today’s increasingly tireless adversaries.
“Morale improves when people see that their contribution is valued, their workload is sustainable, and their work is connected to a larger mission,” he said.
About the author
Billy Hurley
Billy Hurley has been a reporter with IT Brew since 2022. He writes stories about cybersecurity threats, AI developments, and IT strategies.
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.