When Patient Data Crosses A Dozen Systems, Trust Is The Top Asset Hospitals Must Defend
Muralidharan Ramachandran, Founder of MR Advisory, on why a provider is only as secure as the weakest vendor holding patient data.

Make The Intelligence Record one of your go-to sources on Google
It's not that the healthcare ecosystem doesn't know what privacy is, but things have become more complex today because everything is interconnected.
A patient will forgive a long wait or a billing error. What they won't forgive is learning that their medical history, diagnoses, and insurance records were exposed or that an attack disrupted their care. In a healthcare system where a single patient's data can pass through a hospital, a diagnostic lab, a third-party administrator, an insurer, a cloud platform, and a technology vendor before a diagnosis is even finalized, the surface area for that kind of failure has expanded faster than most boards have adjusted. The organization the patient trusts is the provider, but the risk now lives everywhere the data travels, and a breach three vendors removed still lands as the hospital's broken promise.
That gap between where risk originates and where accountability settles is the latest focus for Muralidharan Ramachandran. He's the Founder of MR Advisory, a firm he built to give boards and founders independent guidance on technology, cybersecurity, and governance. Over more than three decades he's held the CEO, CIO, CTO, and CISO seats across global and regulated industries, and now sits on corporate boards across India. In Ramachandran's view, what has changed the stakes is how many hands a patient's data now passes through before anyone can protect it.
"Even if digitization is still new, medicine has been here for centuries. It's not that the healthcare ecosystem doesn't know what privacy is, but things have become more complex today because everything is interconnected," he says.
Trust is quietly becoming a digital property
Ramachandran's starting point is that the trust patients place in a provider has always existed, but the terms have shifted underneath it. The confidentiality a doctor once protected inside a physical file now depends on every system that touches the record after it leaves the room. He traces the ordinary path a patient once took from doctor to lab to hospital to insurer, where each report moved by hand. "Earlier, it used to be all manual. You take a file, you go over there, you put it in another file, so it was not on a digital system," he explains. "Now everything is on digital platforms, and everything is connected." Digital trust, in his framing, is no longer a subset of clinical trust. It's becoming a peer, and it's earned or lost in infrastructure the patient never sees.
That reframing raises a risk that boards rarely treat as their own. When care depends on systems that span organizations, the provider is vouching not only for its own security, but for the reliability of every partner in the chain.
You're only as secure as the weakest link
The interconnection that makes modern care possible is also its central vulnerability. "Your cybersecurity or digital risk is only as good as the weakest link in the chain," Ramachandran points out. A hospital can run strong internal controls and still be exposed through a lab, a claims administrator, or a device vendor with weaker defenses. From a technical standpoint, the failure occurred at the vendor. From the patient's standpoint, the provider held the data and thus, is answerable for it.
That logic moves third-party risk out of procurement and into the domain of trust. The question leaders need to ask, in his view, is not whether a vendor is compliant on paper, but whether it can protect patients and keep operating when it comes under attack. Compliance describes a moment, but resilience describes what happens during the incident that compliance didn't prevent.
People and process decide more than the tool
Ramachandran is emphatic that the hardest part of this is not the technology, and he says so as a self-described hardcore technologist who came up through the ranks. His organizing idea is a framework he's used for years: people, process, and technology, in that order of importance, with governance sitting over all three.
Technology decisions, he believes, are the easy ones. "What differentiates company X from company Y is not the choice of technology, because the same technology is available to everybody," he notes. Two hospitals can deploy the same information system. What separates them is how they use it over the asset's life.
He's watched organizations spend millions on enterprise platforms and then bend the software back to old habits. "They make SAP work like a glorified Excel." In his view, that's a process failure rather than a technological one, and process itself is downstream of people, their skills and the culture in which they operate.
Ramachandran backs the point with a pattern that has held for decades. Analysts today report that a large majority of AI pilots never reach production, which mirrors reports on IT investments from forty years ago. "Even in those days, Gartner and Forester would say that 65 to 70% of IT implementations didn't meet the ROI requirements. So that hasn't changed, and all of this is not because of technology. It's because of people."
Governance keeps the standard from slipping
The layer sitting above the other three, governance, is what keeps the security standard from slipping over time. Ramachandran illustrates the danger with an example from schooling in India. "Let's say you take an exam, and 50% is the passing score. Somebody gets a 49. The examiner says, 'Oh, it's just one mark away. Let me just give a grace mark and pass that.'" Over a period of time, 49 becomes the baseline and not 50. "Then when you get a 48, they'll say, 'Oh, he's just one mark away. Slowly, one day we'll say zero is passing." Security postures decay the same way, one accepted exception at a time, unless someone is accountable for holding deviations inside a defined tolerance he calls accepted risk.
That accountability, he insists, can't sit with the CIO, CTO, or CISO alone. It has to come from the top as leadership accountability, because the threat landscape is now moving too fast for anything less. AI is reshaping the risks in real time, quantum computing is coming behind it, and a framework that's not being updated constantly falls behind on its own.
A live deadline makes the abstract concrete
Ramachandran's connected-hospital insights are framed with a global audience in mind, but pointed first at an Indian reader facing a hard date. Under the country's Digital Personal Data Protection Act, rules finalized in late 2025 give enterprises 18 months to comply, and that window closes in May 2027. For healthcare organizations holding some of the most sensitive data any sector handles, that deadline turns Ramachandran's argument from principle into schedule.
His counsel resists a single template. "It's never one-size-fits-all. Every organization is unique," he says, noting that the same controls can't be dropped uniformly across an ecosystem where not everyone operates at the same level. "Some of the principles you follow will be consistent, but you need to really look at it organization to organization." The implementation must be built for the specific chain of hands a patient's data actually passes through, which is the only chain that patient will hold the provider accountable for protecting.




