Healthcare’s 30-day patch policy may already be obsolete

By Errol Weiss, Chief Security Officer, Health-ISAC
Five days: That was the median time in 2025 between the publication of a high- or critical-severity vulnerability and its addition to CISA’s Known Exploited Vulnerabilities (KEV) Catalog of flaws known to be exploited in the wild, according to Rapid7’s 2026 Global Threat Landscape Report.
Now put that beside your own remediation policy, which most likely sets a timeline of 30 days.
AI is adding speed and scale to hackers’ already effective tactics, and it’s helping blow those numbers apart. Frontier models can help discover vulnerabilities, develop exploits, and carry out complex, multi-step operations that once demanded specialized skills. And those capabilities are also beginning to appear in cheaper, open-weight models.
What’s worse, attackers might not even need a person directing the AI: In a first-of-its-kind event, OpenAI’s latest models went rogue during internal testing and hacked Hugging Face to find ways to abuse a benchmark.
According to Health-ISAC’s latest Frontier AI in the Health Sector report, the takeaway for security leaders is blunt: the deadline for fixing vulnerabilities has shrunk from weeks to days and hours.
Read the article in Cybersecurity Insiders. Read More
Topics covered include:
- The window from disclosure to exploit is closing
- There’s no more Patch Tuesday. It’s Patch Now
- The contract is now a security control
- Redefine what’s reasonable
- Related Resources & News
- Threat Actor Playbook: Conversational Social Engineering in Care Settings
- The Human Risk Layer of AI
- Cybersecurity in the Lab
- Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience
- What’s in America’s Code?
- Introducing AI Agents to Your Identity Fabric
- Cyberattacks on Healthcare Sector Jumped 14% in First Half of 2026
- What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
- Continuous attack surface monitoring and sophisticated social engineering assessment
- Hospital Networks are Becoming Targets in Cyberwarfare, and They’re Unequipped to Deal With It