Skip to content
Greenway Health ENGAGE 2026Nov. 17-19, 2026Learn More
INSIGHTS

Securing Healthcare in the Cloud: Insights from AWS and Greenway Health

photo of a man in a blue jacket looking at the camera and smiling

Paul Ford

Chief Information Security Officer

Friday, October 24, 2025

Co-Author: Payoj Mistry, Senior Solutions Architect, Amazon Web Services

Cybersecurity in healthcare is no longer just a technical challenge: it’s a strategic imperative. As threat actors grow more sophisticated and the value of health data continues to rise, organizations must evolve their defenses. In this blog, experts from Amazon Web Services (AWS) and Greenway Health share their perspectives on the most pressing threats, emerging technologies, and the future of secure cloud-based healthcare systems.

 

A glowing digital lock surrounded by streams of binary code and data points, symbolizing cybersecurity

The Threat Landscape: What’s Keeping CISOs Up at Night

Healthcare organizations are prime targets for cyberattacks due to the high value of electronic health records and intellectual property. According to Greenway, the most critical threats include “data leakage, phishing, ransomware, nation-state actors, insider threats, DDoS attacks, and supply chain attacks.”

Payoj Mistry, Senior Solutions Architect at AWS, echoes these concerns as common risks. To combat these, Mistry explains that AWS provides a robust infrastructure designed to protect identities, applications, and data. Their services help customers “automate manual security tasks, enforce fine-grained policies, and continuously monitor network activity.”

Greenway has taken a layered approach to security, leveraging AWS technologies like Shield, GuardDuty, and Cognito to build Greenway Secure Cloud—a platform purpose-built for healthcare IT modernization.

AI: A Double-Edged Sword in Cybersecurity

The rise of artificial intelligence has brought both innovation and new vulnerabilities.

Paul Ford, Chief Information and Security Officer at Greenway Health, notes, “Over the last year, there has been a significant increase in AI adoption, but it also introduces risk, especially with retail generative AI such as ChatGPT and Copilot. The risk of sensitive data leakage is becoming a true concern.”

To mitigate these risks, Greenway implements advanced data loss protection tools, data discovery software, and strengthens its third-party risk management program to ensure appropriate safeguards are applied to AI platforms before integration.

Beyond MFA: Evolving Authentication Strategies

Multifactor authentication (MFA) remains a cornerstone of cybersecurity, but it’s no longer enough on its own. “Deploying MFA is no longer sufficient to safeguard sensitive information,” says Ford. “Threat actors have developed tactics to circumvent these controls.”

Greenway has partnered with AWS to implement Adaptive Authentication (AA). This risk-based approach verifies user identity before granting access to internal networks and applications. Ford recommends organizations adopt phishing-resistant methods like biometrics and FIDO passkeys, and enforce AA across all access points.

Shared Responsibility: A Model for Secure Collaboration

Security in the cloud is a shared responsibility. Mistry emphasizes that “customers choose the AWS region(s) in which their content is stored, and AWS does not access or use customer content except as necessary to provide services or comply with legal obligations.”

Greenway aligns its configurations and access controls with AWS’ infrastructure and compliance standards. This partnership ensures that both parties uphold their roles in protecting sensitive health data.

Healthcare provider using Greenway Secure Cloud

HIPAA Compliance: Built-In and Inherited

AWS has achieved HITRUST certification for 177 services as of August 2025. This allows healthcare organizations to inherit controls for their own HITRUST assessments. “Our certification is based on version 11.5.1 of the HITRUST CSF,” Mistry notes, “so customers inherit the latest controls and scoring.”

Greenway ensures its systems are configured to meet HIPAA requirements, with continuous monitoring and alignment to evolving compliance frameworks. Greenway has also aligned its cybersecurity program to the HITRUST CSF to proactively mature the enterprise.

Avoiding Compliance Pitfalls

One of the biggest challenges in healthcare cybersecurity is keeping up with the pace of change. “Threat actors constantly evolve their tactics,” says Ford, “and compliance frameworks also evolve, requiring constant attention.”

To stay ahead, Greenway recommends leveraging automated Governance, Risk, and Compliance (GRC) software to monitor security posture and adapt to new controls as they’re introduced.

Looking Ahead: AI and the Future of Healthcare Cybersecurity

Artificial intelligence is poised to reshape cybersecurity and healthcare IT. “AI is the new frontier,” says Ford. “Organizations need to mature their AI governance and risk posture to ensure ethical and secure adoption.”

Standards-based frameworks from NIST, ISO, and HITRUST will play a key role in guiding responsible implementation. As threat actors adopt AI, defenders must also level up their capabilities.

Over the next three to five years, AI will be essential to modernizing healthcare IT. “Cybersecurity teams must evolve alongside these technologies to bring secure value to customers,” Ford adds.

Conclusion

Cybersecurity in healthcare is a shared journey that demands collaboration, innovation, and constant vigilance. Whether through layered security, adaptive authentication, or AI governance, AWS and Greenway Health remain committed to helping healthcare organizations stay secure, compliant, and resilient.

About the author

photo of a man in a blue jacket looking at the camera and smiling
Paul Ford

Chief Information Security Officer

As Chief Information Security Officer of Greenway Health, Paul leads the Cyber Security Department, overseeing the management, monitoring and execution of programs and initiatives to safeguard its data and systems. Paul has aligned the company’s security posture with the HITRUST framework to maintain HIPAA compliance and…

More by Paul Ford