The Cyber Attack No One Can Survive Alone | Executive Interview with Josh Howell

This Week Health
This Week HealthMay 6, 2026

Why It Matters

Healthcare organizations that adopt Rubric’s secure‑by‑design, automated recovery model can cut ransomware downtime from weeks to days, protecting patient care and avoiding costly operational disruptions.

Key Takeaways

  • AHA partners with Rubric after rigorous vendor vetting process.
  • Effective ransomware recovery requires coordinated legal, PR, clinical, and IT teams.
  • Automation of identity and application restoration shortens attack recovery from weeks.
  • Zero‑trust, secure‑by‑design architecture prevents attackers from weaponizing admin rights.
  • Start with backup survivability, then iteratively build incident response capabilities.

Summary

The interview spotlights Rubric’s partnership with the American Hospital Association (AHA), earned after an unusually stringent vetting that involved legal negotiations, reference checks, and a review of Rubric’s data‑protection portfolio. The discussion frames cyber‑resilience as a multi‑disciplinary challenge, emphasizing that ransomware recovery hinges on legal, public‑relations, clinical, and IT teams working in lockstep, rather than merely restoring data. Key insights include a predictable 30‑35‑day ransomware timeline versus traditional IT outages of a few days, the critical role of automation in restoring identity controls and core applications, and the necessity of a zero‑trust, secure‑by‑design architecture that isolates recovery tools from compromised admin privileges. The speakers cite John Regi’s alarming board presentation that spurred AHA’s involvement, the industry’s largest IT outage, and a 24‑month, $18 million IR build‑out as concrete examples. Notable quotes underscore the shift from “what do we restore?” to “did the backup survive?” and illustrate how attackers who seize the identity control plane can weaponize an organization’s own tools. The Mandant report’s graphic scenarios of domain‑admin takeover reinforce the argument for multi‑admin authorization and immutable, clean‑room recovery environments. The takeaway for healthcare leaders is clear: begin by verifying backup survivability, then incrementally construct an incident‑response framework using affordable, automated components. This iterative, practice‑driven approach delivers measurable risk reduction now while scaling toward a fully zero‑trust, resilient infrastructure.

Original Description

What happens when attackers don't just break into your systems, they become you? Josh Howell, Healthcare CTO at Rubrik, joins Drex DeFord to unpack Rubrik's newly announced partnership with the American Hospital Association, a rigorous vetting process that signals a new standard in cyber risk validation. Josh draws on hundreds of ransomware recovery experiences to challenge how health systems think about resilience, recovery sequencing, and the identity control plane. Learn why the worst-case scenario in the 2026 Google Mandiant M-Trends report should keep every CISO up at night.
Key Points:
00:35 AHA Partnership Overview
04:19 Turning Tools Into Outcomes
10:50 Worst Case Scenario
13:47 Secure by Design Zero Trust
Keep up to date on the latest in health IT:
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454

Comments

Want to join the conversation?

Loading comments...