Rethinking Hospital Security: TrioTree Technologies CEO Surjeet Thakur on Securing Fragmented Hospital IT Environments

Date:

Before Article Content · 728×90
Advertise Here

Trending

- Advertisement -

In an interaction with TechGraph, Surjeet Thakur, Founder and CEO of TrioTree Technologies, outlined how the pace of digitisation in hospitals has moved faster than the development of consistent security frameworks, with legacy systems, fragmented deployments, and uneven integration across HIS, LIS, and medical devices continuing to create gaps in access control, monitoring, and audit visibility.

He further explained how TrioTree Technologies addresses this by building security layers around existing infrastructure, with its HISTree platform following a multi-tier architecture that allows controlled intervention at different system levels, ensuring better visibility and more consistent security without disrupting ongoing hospital operations.

Read the interview in detail:

TechGraph: Over the past few years, hospitals have moved rapidly toward digitisation, yet cybersecurity has often remained an afterthought. From what you are seeing on the ground, where do Indian hospitals remain most exposed today?

Surjeet Thakur: We’ve seen digitisation move fast, but the biggest exposure today sits in three areas, that are: legacy systems, fragmented infrastructure, and low awareness at the user level. Not all hospitals have an updated HIS, LIS, and billing devices with a single control layer and are deploying partial implementations or older add-ons, which leave gaps in their access control, audit trails, and monitoring.

A second gap is the integration of the devices. ICU monitors, lab equipment, and third-party systems are linked by interfaces, but not all environments have uniform security policies across them.

- Advertisement -

Lastly, role-based workflows are supported by HIS systems, yet in most hospitals, there is typically no rigid mapping of privileges across departments.

IBM Security states that healthcare is among the most vulnerable industries in the world in terms of breaches. So it is not only that the risk in this case is external attack, but it is also uncontrolled internal access and a lack of visibility into the systems.

TechGraph: A large number of hospitals still rely on legacy systems that were never designed for today’s threat landscape. How do you secure such environments without forcing hospitals into expensive and disruptive overhauls?

Surjeet Thakur: We don’t replace core systems; instead, we work around their architecture. Think of it like reinforcing an old building rather than rebuilding it overnight. We start by adding protective layers, network segmentation, endpoint monitoring, and controlled access. Our information systems, like HISTree, already follow a multi-tier architecture (UI, application, database), which allows controlled intervention at each layer.

We secure legacy environments by isolating layers:

- Advertisement -
  • Database level controls (restricted queries, audit logs)
  • Session tracking and authentication at the application layer.
  • Clinical, admin, and device network divisions.

Middleware integrations (particularly HL7-based interfaces) are also used by us to standardise communication between the old and new systems.

The concept is to minimize the risk in phases, as hospitals will be free to operate. In the long term, we bring them to gradual upgrades, yet without compelling major initial investments. Security does not necessarily imply disruption since it can be staged, focused, and in harmony with the functioning of hospitals in reality.

TechGraph: Systems like HIS and EMR sit at the core of hospital operations, and any disruption can directly impact patient care. How is TrioTree Technologies approaching security in a way that protects these systems without interrupting clinical workflows?

Surjeet Thakur: HIS and EMR systems are already designed around workflows such as OPD, IPD, ICU, pharmacy, and diagnostics, so security must be built into that structure, with a focus on how doctors and staff actually use them. We implement:

  • Role-based access tied to clinical functions (doctor, nurse, admin)
  • Audit trails across every transaction (clinical entries, billing, orders)
  • ICD-10 compliant structured data capture, which reduces unstructured exposure

We also monitor systems in the background to detect unusual activity early, without interrupting usage. Such as authentication and access control are not barriers, but they occur automatically.

The aim is to safeguard critical systems without causing disturbance to clinicians as they remain focused on patients. When security becomes an issue of day-to-day activity, then it is normally a sign that it is getting in the way.

TechGraph: Cyberattacks on hospitals are no longer just data breaches; they can shut down entire operations and delay treatment. How prepared are Indian hospitals when it comes to early detection, incident response, and recovery, and where do you see the biggest operational gaps?

Surjeet Thakur: If you look at the current landscape, healthcare is becoming the most targeted sector in India, with 8,614 cyberattacks per organisation per week, nearly four times the global average, accounting for about 22% of all cyber threats, with a 20% annual rise. Globally, 77% of healthcare organisations have faced ransomware, and 53% have paid ransom. In 2025 alone, 508 breaches exposed 36.2 million medical records, which is significant.

Despite this, preparedness across Indian hospitals remains limited. Detection is still slow, with breach identification taking close to 197 days on average, pointing to weak real-time monitoring. In India, this gap is more visible due to resource constraints. The transition must now be shifted to more than prevention but preparedness by detecting early, responding swiftly, and recovering without interrupting care.

To address these issues, we work to develop systems that use solutions like centralised dashboards to monitor operations and anomalies, audit dashboards to track compliance, and the ability to deploy across multiple locations (useful in a failover environment). When cybersecurity is treated by hospitals in the same way as emergency preparedness, it will be much more likely to cope with such incidents.

TechGraph: Healthcare staff often operate in high-pressure environments where security protocols can be overlooked. What patterns have you observed in human-led vulnerabilities, and how can hospitals realistically strengthen this layer without disrupting care delivery?

Surjeet Thakur: I think breaches don’t just start with systems; they start more with people. Patterns that we have observed include poor passwords, phishing emails, shared logins, and unintentional data disclosure. Healthcare has the highest phishing susceptibility at 41.9%, and more than 60 to 65% of organisations report phishing attempts as a primary attack vector.

This is because employees are responding to continuous communication and emergency requests, and attackers are simulating such a sense of urgency and receive prompt responses.

In stressful workplaces, employees are concerned with speed and not security. And so the solution cannot be cumbersome protocols. A simple and practical way forward is to reduce friction with:

  • Single Sign-On and fast authentication to remove login fatigue
  • Strict role-based access so exposure is limited by design
  • Short, continuous training instead of long sessions
  • And most importantly, systems that guide behaviour, auto logouts, audit trails, and restricted data views

The concept is to render the safe path the simplest path. You can’t expect hospital staff to think or act like cybersecurity experts, but you can develop systems that help make better decisions without slowing them down.

TechGraph: With patient data becoming more digitised, questions around privacy, ownership, and compliance are becoming harder to ignore. How do you see Indian regulations evolving, and are hospitals taking these requirements seriously enough today?

Surjeet Thakur: If you look at how regulations are evolving in India, we are clearly entering a much more structured and accountable phase. The Digital Personal Data Protection Act, 2023, and the 2025 rules, which have established the Data Protection Board of India (DPB), introduce clear requirements around breach reporting timelines, consent management (including for children), and penalties for non-compliance.

It requires explicit patient consent, data minimisation, reporting breaches, and limiting the purpose, and harmonizes healthcare with other larger digital systems, such as the Ayushman Bharat Digital Mission, which is already rolling at scale (with more than 420 million health IDs issued).

But the reality on the ground is mixed; privacy policies are outdated or not aligned with Indian law, which shows a gap between regulation and execution.

We emphasize the role-based access, consent-managed workflows, work audit trails, and structured data exchange specifications, such as HL7, so that privacy is enforced in the system, and not in manual processes.

TechGraph: With increasing reliance on cloud infrastructure, connected medical devices, and data exchange between hospitals and labs, the attack surface is expanding rapidly. How is TrioTree Technologies securing this broader ecosystem while maintaining interoperability?

Surjeet Thakur: The attack surface has expanded significantly today; it’s not just the HIS, but cloud environments, connected medical devices, labs, and third-party integrations. In healthcare, more than 60 percent of information flows out of the main hospital system, and it is more exposed unless it is managed.

At TrioTree, we work on ensuring the flow of data instead of limiting it with standardised integrations based on HL7 protocols, thus all exchanges between HIS, LIS, devices, and external systems are organised, traceable, and auditable.

HISTree and LISTree, our platforms, run on the same architecture, and this minimizes fragmentation and keeps data in a controlled space. We also have a multi-tier configuration (UI, application, database) to separate and minimize risk.

For third-party integrations, we rely on middleware and controlled APIs, ensuring external systems don’t become entry points. Lastly, all this is supported by end-to-end audit trails and central dashboards, meaning that hospitals can see across systems and not inside them.

Our concept is straightforward and very targeted at allowing smooth interoperability, yet ensuring that every data transfer is designed to be controlled, visible, and responsible.

TechGraph: Lastly, as hospitals continue to digitise and threats become more sophisticated, what will define a truly secure healthcare system over the next few years, and how is TrioTree Technologies preparing for that shift?

Surjeet Thakur: A secure healthcare system won’t be defined by how many tools it uses, but by how well everything works together. It will be proactive, identify risks early, quickly respond, and recover without violating service. Security is internal, continuous, not a one-time setup.

At TrioTree, we are ready to make that transition with an emphasis on integrated systems, real-time monitoring, and scalable architecture, which can expand alongside hospitals. You can imagine it as an immune system that is not preventing all the threats, but rather recognizes, reacts, and adapts swiftly. That is what healthcare security should be in a couple of years.

Stay ahead of the curve, every day.

A daily briefing covering news, interviews, and the trends driving the world forward. Curated for readers who want news, not noise.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

TECNO to launch CAMON 50 Ultra Smartphone in India

Smartphone maker TECNO has announced the launch of the CAMON 50 Ultra under its premium CAMON series in India on July 17. Designed to attract...

Why does Enterprise need an AI exit strategy before adapting?

From being experimental to being a necessity for any business, Artificial Intelligence has changed everything about how organizations work across various industries. Companies are using AI to optimize their operations, provide a better customer experience, improve decision-making, drive innovation, and do many other things...

How Technology-Led Skilling Is Strengthening India’s Healthcare Services Economy

India’s medical services segment is entering a transformative phase, driven by the rapid expansion...

Organic BSC Volume Bot: What Timing Variation Actually Changes

Timing is one of the easiest automation details to overlook and one of the...

StationPC PA100 Pro: The Next-Gen Portable NAS Storage Solution for On-the-Go Professionals

The next-generation PocketCloud (model: PA100 Pro) portable NAS from StationPC has officially been unveiled,...

The Borderless Startup: FinStackk CGO Nithin Reddy on Simplifying Financial Operations for Global Founders

Speaking with TechGraph, Nithin Reddy, Co-founder & Chief Growth Officer at FinStackk, discussed how...

Why Do Most Enterprise AI Projects Never Make It Past the Pilot Stage?

Conceiving, developing, and implementing AI projects an optimum mix of creativity, dedication, and perseverance.

How Mixed-Use Ecosystems Will Shape the Next Decade of Urban India

India's urban growth story is entering a decisive phase. By 2036, nearly 600 million...

The AI Studio Economy: SimplifyGenAI’s Gurleen Khurana on Redefining Creative Production

Speaking with TechGraph, Gurleen Khurana explains how generative AI is transforming brand storytelling, creative production, and the rise of integrated AI studios.

The Responsiveness Economy: DashLoc’s Sumit Singh on Redefining Customer Conversations with AI

Speaking with TechGraph, Sumit Singh, Co-Founder & CEO of DashLoc, discussed how businesses are...

How Generative AI Could Reshape Airline Distribution and Travel Retailing

Airline distribution is entering a new phase. For decades, the industry has relied on...

The HiPCO Advantage: NoPo Nanotechnologies’ Gadhadar Reddy on Scaling SWCNT Manufacturing for Emerging Industries

Speaking with TechGraph, Gadhadar Reddy, Co-Founder and CEO of NoPo Nanotechnologies, discussed how manufacturing...

AI That Serves: Impact AI Foundry’s Arjun Balaji on Making Artificial Intelligence Accessible for Nonprofits

Speaking with TechGraph, Arjun Balaji, Co-Founder and Programme Director of Impact AI Foundry, discussed...

How AI Is Building India’s Next-Generation Emergency Mobility Infrastructure

Imagine this. A customer is stranded on the roadside due to a vehicle breakdown and raises a request for assistance. In a traditional roadside...

Human-in-the-Loop: Why AI in Education Still Needs the Professor

Generative AI is rapidly entering classrooms, boardrooms, and training programs. Yet a critical question remains unresolved: does AI enhance learning, or quietly replace it? In my recent research published in the International Journal of Management Education, I examine a faculty-led model of integrating generative AI...

Why Indian Men Are Quietly Moving Away From Fast Fashion

When a man opens his wardrobe, stares at a rail of clothes, and realises...

How changing lifestyles are driving demand in home improvement products

The parking lot outside a home interiors store in Bengaluru's Marathahalli is full by...

Nexchain AI Sets Mainnet and Presale Token Launch in Motion With Final $0.06 Access

Nexchain AI has entered a decisive 2026 build phase as its launch roadmap moves...

The Role of Predictive Technology in Creating Sustainable Infrastructure Ecosystems

Infrastructure development today is no longer just about building faster or expanding bigger. The...

The Reliability Equation: Trev Mobility CEO Naveen Gupta on Building Trust in Premium Electric Ride-Hailing

During an interview with TechGraph, Naveen Gupta, Founder & CEO of Trev Mobility, highlighted...

Nexchain Publishes New Roadmap as $0.06 Token Stage Continues

Nexchain has unveiled its updated development roadmap, providing the community with a clearer view...

CasinoBonusesFinder UK: how filters, Telegram alerts and real bonus matching work in practice

Anyone who has spent serious time on casino bonus hunting knows the drill. You...

The Detroit Region’s Role in Modern Global Supply Chains

As global commerce continues to expand its reach, the Detroit region has emerged as...

PatexOne: Could This Platform Be Smarter Than Your Impulses?

Australian investors are used to platforms that shout about leverage and “opportunity”. PatexOne takes...

The HiPCO Advantage: NoPo Nanotechnologies’ Gadhadar Reddy on Scaling SWCNT Manufacturing for Emerging Industries

Speaking with TechGraph, Gadhadar Reddy, Co-Founder and CEO of NoPo Nanotechnologies, discussed how manufacturing...

“Budget should focus on reducing taxes on capital gains,” Says Abhishek Gupta of Hex N Bit

Speaking in the upcoming Union Budget 2021, Abhishek Gupta, Founder, and CEO, Hex N...

“China is a Global thief” Rep. Tom Rice on Uyghur Forced Labor Prevention Act

Speaking at the House on Uyghur Forced Labor Prevention Act, Rep. Tom Rice (R-SC)...

The rise of tier-2 GCCs: How digital infrastructure is redefining India’s technology talent map

For the better part of two decades, India's Global Capability Centre (GCC) story was...

Nexchain AI Maps Its Final Path to Launch as $0.06 Token Presale Window Nears Its Close

Like a building project that moves from design to final inspections, the Nexchain AI...

AI That Serves: Impact AI Foundry’s Arjun Balaji on Making Artificial Intelligence Accessible for Nonprofits

Speaking with TechGraph, Arjun Balaji, Co-Founder and Programme Director of Impact AI Foundry, discussed...

Key differences between a burner phone & prepaid phone

You may have heard both terms mentioned when it comes to protecting your identity....

Alphabet Discloses $2.14 Billion in Public Equity Holdings as of June 30

Alphabet Inc. disclosed $2.14 billion in equity securities held across 39 positions as of...

India to generate $100 bn from telephonic investments

India expects to attract $100 billion in investments in the telecom sector, a union...