Can small hospitals realistically meet strong cybersecurity standards?
I've been reading about ransomware attacks on hospitals, and the damage goes far beyond the ransom itself—patient records get locked, surgeries get postponed, and sometimes lives are at stake. My cousin works at a small clinic that got hit last year, and they were down for three days even after paying. Is it realistic to expect every healthcare provider, especially smaller ones, to build a serious cybersecurity defense, or are we setting an impossible standard that ignores their limited budgets and expertise?