Q&A with Marcus Flack, CTO at CenTrak

What are the most significant cybersecurity threats currently facing healthcare organizations, and how are health IT teams prioritizing risk mitigation?
Healthcare organizations continue to face a combination of ransomware attacks, third-party supply chain vulnerabilities, identity-based attacks, and the growing complexity of securing connected devices and systems. As hospitals expand their digital ecosystems to include cloud applications, medical devices, IoT technologies, and interoperable platforms, the attack surface grows significantly. Recent industry trends show that healthcare leaders are increasingly prioritizing identity security, network segmentation, continuous monitoring, incident response preparedness, and zero-trust frameworks to reduce risk while maintaining clinical operations.
From an RTLS perspective, connected technologies such as location platforms, staff safety solutions, environmental monitoring, and workflow automation are becoming part of a broader healthcare IoT ecosystem. The priority is no longer simply securing individual applications, but ensuring every connected system meets enterprise security standards and integrates responsibly into the hospital's technology architecture.
How do organizations balance the need for data accessibility and interoperability with stringent privacy and security requirements?
The key is establishing governance frameworks that allow the right information to reach the right people at the right time while enforcing strong controls around authentication, authorization, and auditing.
Modern integration approaches leverage standards such as FHIR, HL7, APIs, and middleware platforms to support interoperability while maintaining appropriate safeguards. CenTrak's own integration ecosystem reflects this reality, connecting RTLS data with EHRs, nurse call systems, asset management platforms, identity systems, and analytics applications through standards-based approaches.
For technologies like RTLS, interoperability creates the greatest value when real-time location and workflow data can securely flow into the systems clinicians and operational teams already use rather than requiring separate workflows or applications.
What role do zero-trust architectures, identity management, and access controls play in modern healthcare security strategies?
Zero-trust has become a foundational principle for healthcare cybersecurity because today's environments extend far beyond traditional network boundaries. Rather than assuming users, devices, or applications are trusted once inside the network, organizations continuously verify identities, evaluate risk, and limit access based on specific roles and needs.
Identity management and role-based access controls are especially critical in healthcare, where thousands of employees, contractors, vendors, and systems interact with sensitive data every day. Many healthcare organizations now require enterprise single sign-on, Active Directory or Entra ID integration, multi-factor authentication, and least-privilege access models across their technology environments.
Similar requirements are increasingly standard in RTLS and healthcare IoT deployments. Enterprise customers routinely expect SSO, role-based permissions, directory integration, and detailed audit logging as part of their security requirements.
Ultimately, zero trust is not just an IT strategy. It is an operational strategy that allows organizations to innovate confidently while reducing risk.
How are Health IT leaders ensuring compliance with evolving regulatory and privacy frameworks while maintaining operational efficiency?
The most effective organizations are embedding compliance into technology architecture and operational workflows rather than treating it as a separate administrative function.
This means standardizing security controls, maintaining clear audit trails, automating governance where possible, and selecting vendors that align with enterprise security and privacy requirements from the outset. Increasingly, healthcare organizations are evaluating products through security assessments and looking for evidence of mature security programs, including frameworks such as SOC2 and other industry-recognized controls.
A growing area of focus is governance surrounding operational and location-based data. As healthcare organizations implement technologies such as RTLS for staff safety, workflow optimization, and asset visibility, they must establish clear policies regarding who can access live and historical location information, under what circumstances, and how that access is monitored and audited.
This is particularly important in environments where workforce privacy concerns exist, including organizations with nursing union considerations. Healthcare leaders want solutions that allow them to support staff safety and operational efficiency while maintaining strong privacy protections and appropriate governance over sensitive location data.
Technology vendors also have a role to play. During RTLS deployments, for example, organizations benefit from guidance on how existing access policies, governance structures, and approval processes may need to evolve to include location data alongside other operational information. The most successful implementations occur when technology, policy, security, and privacy stakeholders collaborate from the beginning.
The goal is to make security and compliance enablers of operational efficiency rather than obstacles to innovation.
What lessons have been learned from recent security incidents or data breaches, and how have those insights influenced security investments and practices?
Perhaps the biggest lesson is that cybersecurity is now a patient care and operational resilience issue, not simply an IT issue. Recent incidents have demonstrated how disruptions to critical systems can impact everything from clinical workflows to revenue cycle operations and patient access to care.
As a result, healthcare organizations are investing more heavily in cyber resilience strategies that emphasize preparation, detection, recovery, and business continuity. This includes stronger identity protections, network segmentation, incident response planning, third-party risk management, and greater visibility across connected devices and systems.
Healthcare leaders have also learned that visibility is essential. You cannot secure what you cannot see. That principle applies equally to users, devices, applications, and operational assets. As healthcare environments become increasingly connected, technologies that improve visibility into people, devices, workflows, and critical resources can play an important role in supporting both operational performance and security readiness.
