Empower Your Practice

Journal for Practice Managers

How Healthcare Organizations Can Protect Themselves from Cyberattacks

Chris Jones
Written by
Chris Jones
Vlad Kovalskiy
Reviewed by
Vlad Kovalskiy
Last updated:
Expert Verified

As modern technology becomes more common in healthcare, the vulnerability to cyber threats continues to increase. Healthcare cyberattacks targeting US organizations have risen sharply over the past several years, compromising the health information and security of tens of millions of Americans. In 2024 alone, healthcare data breaches affected more than 289 million individuals, representing nearly 85% of the US population. By 2026, this trajectory has only worsened, with threat actors utilizing advanced extortion tactics to compromise clinical networks globally. Securing these environments requires continuous visibility into modern applications and APIs, which is why many organizations rely on API security platforms like Escape, Veracode, or Synopsys to discover and fix vulnerabilities before they can be exploited. Healthcare remains one of the most targeted industries, and the average cost of a healthcare data breach has reached $10.93 million, the highest of any sector.

Learn how to simplify your practice workflow and free up more time for patients with Medesk.

Open the detailed description >>

The Current State of US Healthcare Cyberattacks

The scale of healthcare cyberattacks in the United States has reached a crisis point. The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has tracked a steady and steep rise in large healthcare data breaches since 2009. Between 2022 and 2023, the number of individuals affected by healthcare data breaches increased by more than 193%. Between 2023 and 2024, that number surged by another 58%, driven largely by a wave of mega breaches targeting third-party vendors and critical healthcare infrastructure.

The Latest Healthcare Ransomware Statistics

As we move through 2026, analyzing healthcare ransomware statistics reveals that extortion-based attacks are now the predominant threat to clinical operations. Ransomware groups are no longer just locking systems. They are actively stealing sensitive patient data to leverage against providers. The financial and operational damage caused by these aggressive extortion models has forced federal agencies to treat healthcare cybersecurity as a critical public safety issue.

The drivers behind this surge are varied. The rapid expansion of digital health technologies, including telemedicine, cloud-based electronic health records, and internet-connected medical devices, has dramatically expanded the attack surface for healthcare organizations. Remote work adoption, accelerated during the Covid-19 pandemic, introduced new vulnerabilities as employees accessed clinical systems from home networks without enterprise-grade security controls. Nation-state threat actors, organized ransomware groups, and financially motivated cybercriminals have all identified healthcare as a high-value, high-vulnerability target.

HHS OCR publishes breach data continuously through its public breach reporting portal, commonly referred to as the "Wall of Shame." Tracking this portal over time gives security professionals and administrators a reliable picture of year-over-year trends in healthcare data breach statistics, including which types of organizations are most frequently affected and which attack vectors are driving the largest breaches. Monitoring this resource regularly is one of the most practical steps an organization can take to contextualize its own risk profile against the broader threat landscape.

Attackers are drawn to healthcare for several reasons. Patient records contain a rich combination of personally identifiable information (PII), financial data, and medical history, making them far more valuable on the dark web than a standard credit card number. Healthcare organizations also face intense pressure to restore operations quickly, which makes them more likely to pay ransoms.

Specific threat vectors targeting US healthcare organizations today include:

  • Business email compromise (BEC): Attackers impersonate executives or vendors to trick employees into transferring funds or revealing credentials. BEC is one of the costliest attack types in healthcare.
  • Exploited VPNs and remote access tools: Unpatched virtual private network appliances and remote desktop protocol (RDP) services have served as common entry points for ransomware groups. Healthcare organizations that rapidly expanded remote access during the pandemic often did so without sufficient security hardening. Healthcare organizations can also implement remote browser isolation (RBI), which executes web activity in a secure, isolated environment to prevent web-based threats from ever reaching clinical systems or patient data.
  • Phishing and spear-phishing: Targeted email campaigns remain the most common initial access vector, using deceptive messages designed to steal credentials or deliver malware.
  • Supply chain attacks: Rather than targeting a hospital directly, attackers compromise a widely used third-party vendor or software provider. The downstream impact can affect hundreds or thousands of healthcare organizations simultaneously.
  • Medical device cybersecurity vulnerabilities: Interconnected medical devices, including infusion pumps, imaging systems, and patient monitors, often run outdated operating systems and lack robust authentication controls. These devices create entry points directly onto clinical networks and are increasingly exploited as attack vectors. The FDA has introduced cybersecurity requirements for new medical devices, but legacy equipment remains a significant gap.

The Rise of Double Extortion Ransomware

Understanding how these criminal groups operate is essential for defending against them. Modern threat actors heavily rely on double extortion tactics. In a traditional ransomware attack, criminals simply encrypt an organization's data and demand a ransom for the decryption key. Double extortion adds another layer of severity to the attack.

Before deploying the encryption payload, the attackers quietly exfiltrate vast amounts of sensitive patient health information and financial records. Once the data is stolen, they lock the hospital's systems. The attackers then issue two simultaneous threats. If the organization refuses to pay the decryption ransom, the criminals will permanently cripple the hospital's operations by leaving its records inaccessible. Furthermore, they threaten to publish the stolen sensitive patient data on the dark web. This second threat often forces healthcare administrators into paying the ransom to avoid massive HIPAA violations and loss of patient trust. Conducting a proactive dark web scan assists in detecting whether exfiltrated datasets or administrative credentials have been uploaded to illicit directories.

Case Studies: The Impact of Change Healthcare and Black Basta

Two attacks in particular illustrate just how devastating healthcare cyberattacks have become for US patients and providers.

The Change Healthcare Cyberattack

On February 21, 2024, the Russian ransomware group ALPHV BlackCat launched an attack against Change Healthcare, a subsidiary of UnitedHealth Group. Change Healthcare is the largest health payment processing company in the United States, annually processing 15 billion healthcare transactions and touching one in every three patient records. The attack encrypted and incapacitated significant portions of Change Healthcare's systems.

The consequences were catastrophic and nationwide. A March 2024 survey of nearly 1,000 hospitals by the American Hospital Association (AHA) found:

  • 74% reported direct patient care impact, including delays in authorizations for medically necessary care.
  • 94% reported the attack impacted them financially.
  • 33% reported the attack disrupted more than half of their revenue.
  • 60% required between two weeks and three months to resume normal operations.

Many hospitals were forced to pull from cash reserves or take out emergency loans to cover payroll, medical supplies, and essential services while manual processes replaced automated ones. The Change Healthcare cyberattack demonstrated that attacking a single critical third-party vendor can effectively hold the entire US healthcare system hostage.

The Black Basta Ransomware Group

Black Basta is a ransomware-as-a-service group that has encrypted and stolen data from at least 12 of 16 critical infrastructure sectors, with healthcare among its most frequent targets. CISA, the FBI, HHS, and MS-ISAC have issued joint advisories warning healthcare organizations about Black Basta's tactics, which include exploiting known VPN vulnerabilities, deploying credential harvesting tools, and using double extortion, encrypting files while also threatening to publish stolen data publicly. Attacks attributed to Black Basta have disrupted hospital operations across the country, forcing care diversions and access restrictions to patient records.

Together, these cases illustrate a core truth: in healthcare, a cyberattack is not just a technology problem. It is a patient safety emergency.

Cyber Risk Is Patient Risk

Unlike a data breach at a retailer or financial institution, a cyberattack on a hospital or health system can directly harm patients. When clinical systems go down, care delivery is disrupted in ways that have measurable consequences for health outcomes.

Documented patient safety impacts of healthcare cyberattacks include:

  • Ambulance diversions: Hospitals that cannot access electronic systems are often forced to divert incoming ambulances to other facilities, increasing transport times for critically ill patients.
  • Delayed procedures and diagnostic results: Ransomware attacks that encrypt laboratory systems, imaging archives, and scheduling platforms force clinicians to delay surgeries, cancer treatments, and time-sensitive diagnostics.
  • Compromised medical devices: Cyberattacks that reach clinical networks can affect networked infusion pumps, ventilators, and monitoring equipment, creating direct risks to patients receiving treatment.
  • Access loss to medication records: When pharmacy systems are knocked offline, care teams may lack access to patient medication histories, increasing the risk of dosing errors or dangerous drug interactions.

A 2025 narrative review published in a peer-reviewed journal found that the number of cybersecurity incidents affecting hospital systems has tripled over the past decade. The review identified cyber incidents as a genuine public health concern requiring multi-level prevention and preparedness strategies. As CISA has stated plainly: "Cyber Safety is Patient Safety."

Healthcare organizations must understand that investment in cybersecurity is not simply an IT budget decision. It is a clinical governance responsibility.

US Regulatory Compliance: HIPAA and HHS Cybersecurity Goals

US healthcare organizations operate under a specific and evolving set of federal cybersecurity requirements. Understanding these obligations is essential for compliance and for building an effective security posture.

HIPAA Cybersecurity Requirements

The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires covered entities and their business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). HIPAA cybersecurity requirements include conducting regular risk assessments, implementing access controls, encrypting ePHI where appropriate, establishing audit controls, and maintaining policies for responding to security incidents. The HHS OCR enforces the HIPAA Security Rule and can impose civil monetary penalties for violations, with fines reaching into the millions of dollars for willful neglect.

Importantly, HIPAA also includes a breach notification requirement. Covered entities must notify affected individuals, HHS, and, in cases involving more than 500 residents of a state or jurisdiction, local media, following the discovery of a breach of unsecured ePHI. Notifications must be made without unreasonable delay and within 60 days of discovery.

Third-Party Vendor Risk and Business Associate Agreements

The Change Healthcare attack exposed a structural vulnerability that every covered entity must address directly: the risk posed by third-party vendors who handle ePHI on your behalf. Under HIPAA, any vendor that creates, receives, maintains, or transmits ePHI for a covered entity is classified as a business associate. Covered entities are legally required to execute a business associate agreement (BAA) with each of these vendors before sharing any patient data. A properly constructed BAA under HIPAA defines the permitted uses of ePHI, establishes the vendor's security obligations, and requires the vendor to notify the covered entity promptly in the event of a breach.

However, having a signed BAA on file is not sufficient on its own. The Change Healthcare case demonstrated that a single widely used vendor can become a single point of failure for thousands of downstream healthcare organizations simultaneously. HIPAA compliance requires covered entities to conduct vendor due diligence, not just execute paperwork. This means evaluating a vendor's security posture before engagement, reviewing their controls periodically, and assessing what would happen to your operations if that vendor were suddenly taken offline.

Organizations should maintain a complete inventory of all business associates and the ePHI flows that connect them. Regular review of this inventory allows administrators to identify dangerous concentrations of dependency, where the loss of one vendor would cascade into a clinical or financial crisis. The lessons of Change Healthcare apply to any health system that has not mapped its vendor ecosystem for single points of failure: the question is not whether a major vendor will be attacked, but whether your organization is prepared to absorb the impact.

HHS 405(d), CPGs, and Federal Resources

The HHS 405(d) program, established under the Cybersecurity Act of 2015, is a public-private partnership designed to align healthcare industry security approaches. It produced the Health Industry Cybersecurity Practices (HICP), a set of voluntary but widely recognized technical volumes and implementation guides covering the most impactful cybersecurity practices for healthcare organizations of all sizes. The HICP guides are organized by organization size, making them particularly accessible for small and medium-sized practices that may lack dedicated IT security staff. Through this program, HHS provides free resources, training materials, and implementation guides at 405d.hhs.gov.

In 2024, HHS released the Healthcare and Public Health Cybersecurity Performance Goals (CPGs), developed in coordination with CISA. The CPGs are divided into two tiers. Essential Goals represent a foundational set of high-priority controls that all healthcare organizations should implement regardless of size or resources. Enhanced Goals represent more advanced practices for organizations with greater technical capacity. Essential CPGs include mitigating known vulnerabilities, implementing multi-factor authentication, establishing basic incident response capabilities, and maintaining an up-to-date asset inventory. Enhanced CPGs address more sophisticated capabilities such as third-party risk management programs, advanced detection tooling, and network segmentation.

The CPGs are voluntary, but HHS has signaled its intent to tie them to future funding and regulatory incentives. Healthcare administrators should treat the CPGs as a practical roadmap for improving their security posture, regardless of organization size. Taken together, the HICP publication and the CPG framework give even resource-constrained organizations a clear, federally endorsed starting point for prioritizing their cybersecurity investments.

US healthcare organizations do not have to navigate the threat landscape alone. Several federal programs exist specifically to support the healthcare and public health sector. The Health Sector Cybersecurity Coordination Center (HC3), operated by HHS, produces regular threat intelligence briefings and sector alerts tailored to healthcare. The Multi-State Information Sharing and Analysis Center (MS-ISAC) provides cybersecurity services to public health agencies. Furthermore, CISA offers free vulnerability scanning and cybersecurity assessments to critical infrastructure operators. Finally, the FBI Cyber Division actively investigates ransomware and significant cyber incidents targeting US healthcare organizations. Establishing relationships with these agencies before an incident occurs is strongly recommended.

How to Prevent Healthcare Cyberattacks and Prepare for Downtime

Proactive defense requires a combination of technical safeguards and operational readiness. Knowing how to prevent ransomware in healthcare means understanding exactly how attackers gain entry and cutting off those pathways. Prevention strategies must address human error, network vulnerabilities, and legacy systems simultaneously. Commissioning cloud penetration testing against your AWS, Azure or GCP environment is one way to find those pathways before an attacker does.

Healthcare organizations should start by enforcing strict access controls. Implement multi-factor authentication across all portals, email systems, and remote access points. Keep all software, operating systems, and third-party applications continuously patched to close known exploits. Additionally, adopting continuous dark web monitoring helps security teams identify compromised credentials before they can be used for unauthorized entry. Effective endpoint threat protection further secures workstations, servers, and medical devices by monitoring suspicious activity and helping contain threats before they spread. Furthermore, organizations must actively segment their networks. If a ransomware actor compromises an administrative workstation, network segmentation ensures the infection cannot immediately spread to life-saving clinical systems or medical devices.

However, prevention measures will eventually fail. True resilience requires robust downtime procedures. A comprehensive cyber preparedness plan must include paper chart backups, ensuring clinicians have access to blank patient intake forms, allergy records, and medication templates when electronic health records go dark. Hospitals must establish clear, offline surgical protocols and emergency service procedures so that operating rooms can continue to function safely without digital monitoring systems. Staff must practice these downtime procedures regularly through realistic tabletop exercises.

Implementing the NIST Cybersecurity Framework

To structure their prevention and recovery strategies, many healthcare organizations adopt the NIST Cybersecurity Framework (CSF). The NIST framework provides a rigorous, standardized methodology for managing and reducing cyber risk across five core functions: Identify, Protect, Detect, Respond, and Recover. HHS has formally mapped the NIST CSF to the HIPAA Security Rule, meaning that organizations using the framework as a self-assessment tool are simultaneously benchmarking their HIPAA compliance posture. For small and mid-size practices without dedicated security staff, this mapping makes the NIST CSF an especially practical starting point: working through the five functions surfaces gaps in both technical controls and administrative safeguards at the same time.

Identify: Organizations must begin by mapping all hardware, software, data flows, and ePHI locations across the network. A complete asset inventory is the foundation of every other control. You cannot protect what you have not catalogued, and many breaches exploit systems that an organization did not know were internet-accessible.

Protect: Once assets are mapped, the organization implements access controls, encryption, workforce training, and maintenance procedures to limit the impact of a potential incident. This includes enforcing least-privilege access to EHR systems, encrypting ePHI at rest and in transit, and applying patches on a defined schedule.

Detect: Active monitoring capabilities allow the organization to identify anomalous activity quickly. In healthcare, where clinical operations depend on continuous system availability, early detection is critical. Network monitoring tools, endpoint detection and response (EDR) platforms, and security information and event management (SIEM) systems all contribute to this function.

Respond: A structured response plan ensures that when an incident occurs, the organization can contain the threat rapidly and systematically, rather than improvising under pressure. This function is where building cyber resilience into clinical operations becomes concrete: response plans must account for patient care continuity, not just IT recovery.

Recover: The recovery function ensures that data can be restored securely from clean backups and that clinical operations return to normal in a controlled, verified sequence. Recovery planning should specify which systems must come online first to support patient safety, how staff will be notified when systems are safe to use again, and how the organization will validate data integrity before resuming full electronic operations.

The NIST CSF does not require a large budget or a dedicated security team to begin applying. Even a small practice can work through the Identify and Protect functions using free HHS 405(d) resources, then use the gaps uncovered to prioritize investment in detection and response capabilities over time.

Incident Response: What to Do When Your Organization Is Breached

Even well-prepared organizations can experience a breach. Having a defined incident response plan specific to the US healthcare environment is essential for minimizing harm and meeting legal obligations. Organizations that have tested their plan before an incident occurs through tabletop exercises and simulated breach scenarios consistently respond faster and more effectively than those improvising in the moment. A pre-written, regularly rehearsed incident response plan is not an optional IT document. It is an operational requirement for any organization that handles ePHI.

When a breach is discovered, the response should follow a clear phased sequence: Contain, Assess, Notify, and Recover.

Immediate steps upon discovery:

  1. Contain and isolate: Disconnect affected systems from the network to prevent further spread of malware. Do not shut down systems entirely before taking forensic snapshots where possible, as evidence may be needed. Activate downtime procedures immediately so that clinical care can continue while the response proceeds.
  2. Activate your incident response team: Notify your CISO, legal counsel, and executive leadership immediately. Engage a qualified cybersecurity incident response firm if you do not have internal forensic capability. In manufacturing environments, ITSM software for manufacturing helps streamline incident tracking, coordination, and resolution, ensuring faster response times and minimizing operational disruptions.
  3. Contact federal authorities:
    • Report ransomware and significant cyber incidents to CISA via cisa.gov/report or by calling 1-888-282-0870.
    • File a complaint with the FBI at IC3.gov. The FBI Cyber Division can provide operational support and threat intelligence.
    • Notify HHS OCR of any breach of ePHI. For breaches affecting 500 or more individuals, notification must occur within 60 days of discovery. OCR's breach reporting portal is available at hhs.gov/hipaa/breaches.
  4. Preserve evidence: Document the timeline of events, preserve logs, and avoid making changes to affected systems before forensic analysis is complete.
  5. Assess scope: Determine what data was accessed or exfiltrated, which systems were affected, and whether patient care has been or could be impacted. This assessment drives both the notification obligations under HIPAA and the recovery sequencing decisions your team will need to make.
  6. Notify affected individuals: Under HIPAA, affected patients must be notified following confirmed breaches of ePHI. The 60-day notification clock begins at the date of discovery, not the date the breach occurred. Work with legal counsel to determine the correct notification timeline, method, and content. For breaches affecting 500 or more individuals in a state or jurisdiction, local media notification is also required.
  7. Review and remediate: After recovery, conduct a root cause analysis, patch the vulnerability that was exploited, and update your risk assessment and security policies accordingly. Document all actions taken during the response, as OCR may request this record during a subsequent investigation.

Organizations that have engaged HC3, MS-ISAC, or CISA before an incident occurs are better positioned to receive rapid support when one happens. Establishing these relationships proactively is strongly recommended.

How Organizations and Individuals Can Stay Protected

Phishing, ransomware, and other types of cyberattacks against healthcare organizations are on the rise. It's imperative that healthcare providers, medical research facilities, and other healthcare institutions invest in cybersecurity to protect themselves from these threats. Engaging penetration testing companies can help identify security weaknesses before malicious actors exploit them. One of the most effective investments today is in DMARC solutions for business, which offer scalable email security tailored to organizational needs.

To combat these growing threats, healthcare organizations should implement SPF, DKIM, and DMARC protocols, which work together to authenticate email senders and protect against phishing and email spoofing attacks. In this section, we take a look at some of the measures that healthcare organizations can take to combat the threat of cybersecurity.

Backup Your Data

Ransomware has become very common, targeting both organizations and individuals, which is one of the primary reasons that consistent, verified data backups are non-negotiable in healthcare. Even the most security-oriented organizations remain susceptible to ransomware attacks. For clinical environments, standard backups are not enough. Healthcare organizations should maintain air-gapped or immutable backups of EHR data, imaging archives, and pharmacy records, stored in a location that ransomware cannot reach from the production network. That's why organizations in the healthcare sector need a comprehensive cyber resilience solution that goes beyond simple backups, automating infrastructure recovery, detecting configuration drift, and ensuring operations can be restored quickly when disaster strikes. Backup integrity should be tested regularly through restoration drills, not just verified by a completion log.

Encrypt Personal Devices

The use of personal devices in the retrieval, transmission, and collection of electronic health records has increased during the pandemic. Bring Your Own Device (BYOD) presents a significant cybersecurity risk to the confidentiality of health information. Encrypt your smartphones, tablets, and computers to protect healthcare data. Encryption uses cryptography to conceal information by altering it so that it appears to be random, unintelligible data.

Encrypting your devices makes it harder for cybercriminals to hack into them and steal sensitive information. Healthcare organizations should enforce device encryption through a formal mobile device management (MDM) policy that applies equally to personal devices used to access clinical systems, a requirement that is consistent with the HIPAA Security Rule's technical safeguard standards. These concepts are often covered in a comprehensive cyber security course.

Improve Password Security

Passwords are essential to data security. The vast majority of cyberattacks result from insecure or stolen passwords. This is not surprising, given that many people do not take password management seriously. Use strong passwords to prevent hackers from gaining access to your devices via brute force. You can use a open source password manager app to generate and store strong passwords. Because credentials leak eventually, account takeover prevention adds a second layer, verifying the device behind the login rather than trusting the password alone. In healthcare, privileged access management (PAM) tools should be applied to any account with administrative access to EHR systems or clinical databases, limiting the blast radius when a credential is compromised.

Protect Your Wi-Fi

A Virtual Private Network (VPN) has become a vital security tool for individuals and organizations. VPNs are popular for their online privacy benefits, but they can also improve your organization's security. A VPN employs protocols, servers, and encryption to conceal sensitive data from malicious actors on the internet. For instance, using a VPN prevents cybercriminals from intercepting, modifying, or stealing sensitive personal and organizational data, including login credentials, patient health records, emails, and more. Healthcare organizations should ensure that any VPN used to access clinical systems requires multi-factor authentication, uses current encryption standards, and is patched on a priority basis, as unpatched VPN appliances are among the most commonly exploited entry points in healthcare ransomware incidents. Even tracking your location through your IP address presents a risk. If you're concerned about online privacy, you can check what is my IP to see what information is publicly visible and take necessary precautions.

Cybersecurity experts from Cybernews recommend reading their Surfshark VPN review to explore how a trusted VPN service can further bolster your online privacy and security.

Discover more about the essential features of Medesk and claim your free access today!

Explore now >>

Install Antivirus

The vast majority of cybersecurity threats in the healthcare industry are malware-related. When it comes to protecting against malware threats such as ransomware, deploying endpoint security tools across all workstations and servers is a baseline requirement. If you are using Mac scanning with CleanMyMac or installing an antivirus or antimalware software can go a long way. Antivirus programs can detect and eliminate malicious software and Potentially Unwanted Programs (PUPs) from your system. Security software such as antivirus can protect from a wide range of malware threats, including viruses, Trojans, spyware, adware, etc., but doesn't guarantee ransomware protection. Healthcare organizations should complement antivirus tools with endpoint detection and response (EDR) capabilities that can identify behavioral indicators of compromise, not just known malware signatures, since ransomware groups routinely modify their payloads to evade signature-based detection.

Keep Software Up To Date

Update your software regularly to keep cybersecurity threats at bay. Hackers will often attempt to exploit vulnerabilities within your system to gain access to valuable data. Software providers consistently release updates for their applications to keep them secure. Ensure that you install these updates as soon as they are made available. In healthcare, patch management must extend beyond workstation operating systems to include EHR platforms, medical device firmware, and third-party clinical applications. Many ransomware attacks on healthcare organizations have exploited known vulnerabilities for which patches were available but had not been applied, making a defined, monitored patch management program one of the highest-return security investments available.

Cybersecurity Training

We all make mistakes, and cybercriminals are looking for every opportunity to exploit them. Hackers target the human element for their most effective attacks. They employ social engineering tactics such as phishing, spoofing, etc., to exploit human weaknesses. Healthcare organizations need to address the human element in their vulnerability to cybersecurity risks to defend against these threats effectively. HIPAA requires covered entities to provide security awareness training to all workforce members, and that obligation extends to contractors and volunteers who access ePHI. Security awareness training can keep workers aware of the danger as well as the most common cyberattack tactics and how to protect against them. Training should include regular phishing simulation exercises, which research consistently identifies as more effective than passive instruction at changing employee behavior. Staff who handle administrative access to EHR systems or billing platforms should receive additional role-specific training on credential hygiene and social engineering recognition.

Beyond reactionary measures, a robust action plan is paramount. Educating your staff on the importance of incident response goes beyond identifying threats. To truly fortify your healthcare organization, taking proactive steps to build an incident response plan tailored to your specific needs ensures not only preparedness but resilience against potential cyber threats.

Medesk helps automate scheduling and record-keeping, allowing you to recreate an individual approach to each patient, providing them with maximum attention.

Learn more >>

en security 1

Cyberattacks targeting US healthcare organizations are growing in both frequency and severity. When it comes to defending against these cybersecurity threats, being proactive is the best approach. Take a close look at your systems to find out where you are exposed. Use the federal resources available to you, including HC3, CISA, and the HHS 405(d) program, to benchmark your defenses against recognized standards. Then take targeted measures to address the gaps. The tools and guidance in this article provide a strong foundation for protecting your organization and the patients who depend on it.

Frequently Asked Questions

  1. What are the most common types of healthcare cyberattacks in the US?

Ransomware remains the most disruptive attack type, but business email compromise (BEC), phishing, exploited VPN vulnerabilities, and supply chain attacks are all significant threats. Attackers frequently combine techniques, using phishing to steal credentials and then deploying ransomware once they have network access.

  1. Is a healthcare organization liable for a data breach?

Yes. Under HIPAA, covered entities and their business associates can face civil and criminal liability for breaches of electronic protected health information (ePHI), particularly where a risk assessment was not conducted or reasonable safeguards were not in place. HHS OCR has levied fines ranging from thousands to millions of dollars depending on the level of negligence involved.

  1. What are the HIPAA reporting requirements after a breach?

Following discovery of a breach involving unsecured ePHI, covered entities must notify affected individuals without unreasonable delay and within 60 days. For breaches affecting 500 or more individuals, HHS OCR must also be notified within 60 days, and local media outlets in affected states must be notified as well. All breaches, regardless of size, must be reported to OCR at least annually.

  1. How do I report a ransomware attack on my healthcare organization?

You should report to three federal bodies concurrently. File a report with CISA at cisa.gov/report or by phone, submit a complaint to the FBI's Internet Crime Complaint Center at IC3.gov, and notify HHS OCR through the breach reporting portal at hhs.gov/hipaa/breaches if ePHI was involved. Contacting these agencies early can provide access to technical assistance and support recovery efforts.

  1. What is the HHS 405(d) program and why does it matter for small practices?

The HHS 405(d) program provides free, practical cybersecurity guidance tailored specifically to healthcare organizations, including small and medium-sized practices that may lack dedicated IT security staff. Its Health Industry Cybersecurity Practices (HICP) guides offer actionable steps organized by organization size and are widely regarded as a baseline for HIPAA-aligned security. Small practices can access all resources free of charge at 405d.hhs.gov.

  1. What are the Healthcare and Public Health Cybersecurity Performance Goals?

The cybersecurity performance goals (CPGs) are a set of prioritized security practices developed by HHS and CISA to help healthcare organizations focus their limited resources on the controls most likely to reduce risk. Essential CPGs cover foundational measures such as multi-factor authentication, asset inventory, and vulnerability patching. Enhanced CPGs cover more advanced capabilities. While currently voluntary, HHS has indicated the CPGs may be tied to future regulatory requirements and funding conditions.

  1. What are the immediate operational steps administrators must take when systems go down?

When clinical systems go down unexpectedly, administrators must immediately activate their downtime procedures. This includes switching to approved paper charting, implementing offline surgical and medication protocols, and establishing a central command post to coordinate clinical care manually.

  1. How to prevent ransomware in healthcare?

Preventing ransomware requires securing remote access points, enforcing network segmentation, and mandating multi-factor authentication across the organization. Regular data backups stored offline and continuous employee security awareness training are also critical defenses against infection.

  1. What is a business associate agreement (BAA) and when is one required?

A business associate agreement (BAA) is a written contract required under HIPAA between a covered entity and any vendor or third party that creates, receives, maintains, or transmits ePHI on its behalf. The BAA defines the permitted uses of that data and requires the vendor to implement appropriate safeguards and to notify the covered entity promptly if a breach occurs. A BAA is legally required before any ePHI is shared with a vendor, regardless of the vendor's size or the volume of data involved. The Change Healthcare attack illustrated why BAA compliance must be paired with active vendor risk assessment, since a signed agreement does not protect operations if a critical vendor is taken offline.

  1. What recent cyberattacks have targeted US hospitals?

Two of the most consequential recent attacks are the February 2024 ALPHV BlackCat ransomware attack on Change Healthcare, which disrupted payment processing and revenue flows for hospitals nationwide, and the ongoing campaigns by Black Basta, a ransomware-as-a-service group that has targeted healthcare organizations across the country and prompted a joint advisory from CISA, the FBI, HHS, and MS-ISAC. Both cases resulted in widespread care disruptions, ambulance diversions, and prolonged operational outages. HHS OCR's public breach portal provides continuously updated records of breaches affecting US healthcare organizations and is the most reliable source for tracking the current incident landscape.

EHR vs EMR: Key Differences & Advantages

EHR vs EMR: Key Differences & Advantages

EHR vs EMR: how are they different? How are they similar? Most importantly, which one does your practice need? Read our article to find out!
How to Start a Physical Therapy Clinic in 2025

How to Start a Physical Therapy Clinic in 2025

Discover how to start a successful physical therapy clinic with our comprehensive 10-step guide. Learn about business plans, financing, and more.
Top 5 Medical Dictation Software for Your Private Practice in 2025

Top 5 Medical Dictation Software for Your Private Practice in 2025

Confused by medical speech recognition software? We break down 5 top options to help you pick the perfect tool for faster, more accurate documentation.