We will be at HIMSS, Las VegasMar 14-17, 2026Meet us there
INSIGHTS

Securing Healthcare in the Cloud: Insights from AWS and Greenway Health

Paul Ford, Chief Information and Security Officer, Greenway Health 

Payoj Mistry, Senior Solutions Architect, Amazon Web Services 

Friday, October 24, 2025 @ 9:59 AM EDT

Cybersecurity in healthcare is no longer just a technical challenge: it’s a strategic imperative. As threat actors grow more sophisticated and the value of health data continues to rise, organizations must evolve their defenses. In this blog, experts from Amazon Web Services (AWS) and Greenway Health share their perspectives on the most pressing threats, emerging technologies, and the future of secure cloud-based healthcare systems. 

 

A glowing digital lock surrounded by streams of binary code and data points, symbolizing cybersecurity

The Threat Landscape: What’s Keeping CISOs Up at Night 

Healthcare organizations are prime targets for cyberattacks due to the high value of electronic health records and intellectual property. According to Greenway, the most critical threats include “data leakage, phishing, ransomware, nation-state actors, insider threats, DDoS attacks, and supply chain attacks.” 

Payoj Mistry, Senior Solutions Architect at AWS, echoes these concerns as common risks. To combat these, Mistry explains that AWS provides a robust infrastructure designed to protect identities, applications, and data. Their services help customers “automate manual security tasks, enforce fine-grained policies, and continuously monitor network activity.” 

Greenway has taken a layered approach to security, leveraging AWS technologies like Shield, GuardDuty, and Cognito to build Greenway Secure Cloud—a platform purpose-built for healthcare IT modernization. 

AI: A Double-Edged Sword in Cybersecurity 

The rise of artificial intelligence has brought both innovation and new vulnerabilities.  

Paul Ford, Chief Information and Security Officer at Greenway Health, notes, “Over the last year, there has been a significant increase in AI adoption, but it also introduces risk, especially with retail generative AI such as ChatGPT and Copilot. The risk of sensitive data leakage is becoming a true concern.” 

To mitigate these risks, Greenway implements advanced data loss protection tools, data discovery software, and strengthens its third-party risk management program to ensure appropriate safeguards are applied to AI platforms before integration. 

Beyond MFA: Evolving Authentication Strategies 

Multifactor authentication (MFA) remains a cornerstone of cybersecurity, but it’s no longer enough on its own. “Deploying MFA is no longer sufficient to safeguard sensitive information,” says Ford. “Threat actors have developed tactics to circumvent these controls.” 

Greenway has partnered with AWS to implement Adaptive Authentication (AA). This risk-based approach verifies user identity before granting access to internal networks and applications. Ford recommends organizations adopt phishing-resistant methods like biometrics and FIDO passkeys, and enforce AA across all access points. 

Shared Responsibility: A Model for Secure Collaboration 

Security in the cloud is a shared responsibility. Mistry emphasizes that “customers choose the AWS region(s) in which their content is stored, and AWS does not access or use customer content except as necessary to provide services or comply with legal obligations.” 

Greenway aligns its configurations and access controls with AWS’ infrastructure and compliance standards. This partnership ensures that both parties uphold their roles in protecting sensitive health data. 

Healthcare provider using Greenway Secure Cloud

HIPAA Compliance: Built-In and Inherited 

AWS has achieved HITRUST certification for 177 services as of August 2025. This allows healthcare organizations to inherit controls for their own HITRUST assessments. “Our certification is based on version 11.5.1 of the HITRUST CSF,” Mistry notes, “so customers inherit the latest controls and scoring.” 

Greenway ensures its systems are configured to meet HIPAA requirements, with continuous monitoring and alignment to evolving compliance frameworks. Greenway has also aligned its cybersecurity program to the HITRUST CSF to proactively mature the enterprise. 

Avoiding Compliance Pitfalls 

One of the biggest challenges in healthcare cybersecurity is keeping up with the pace of change. “Threat actors constantly evolve their tactics,” says Ford, “and compliance frameworks also evolve, requiring constant attention.” 

To stay ahead, Greenway recommends leveraging automated Governance, Risk, and Compliance (GRC) software to monitor security posture and adapt to new controls as they’re introduced. 

Looking Ahead: AI and the Future of Healthcare Cybersecurity 

Artificial intelligence is poised to reshape cybersecurity and healthcare IT. “AI is the new frontier,” says Ford. “Organizations need to mature their AI governance and risk posture to ensure ethical and secure adoption.” 

Standards-based frameworks from NIST, ISO, and HITRUST will play a key role in guiding responsible implementation. As threat actors adopt AI, defenders must also level up their capabilities. 

Over the next three to five years, AI will be essential to modernizing healthcare IT. “Cybersecurity teams must evolve alongside these technologies to bring secure value to customers,” Ford adds. 

Conclusion 

Cybersecurity in healthcare is a shared journey that demands collaboration, innovation, and constant vigilance. Whether through layered security, adaptive authentication, or AI governance, AWS and Greenway Health remain committed to helping healthcare organizations stay secure, compliant, and resilient.