Hospitals, clinics, and medical practices in the U.S. handle large amounts of electronic Protected Health Information (ePHI). This data is very valuable to cybercriminals because it is sensitive and permanent. The healthcare sector faced the most data breaches in 2023. About 58% of affected people were related to attacks on healthcare business associates—third-party vendors that provide technology or services to healthcare providers. This is a 287% increase from the previous year, showing fast growth in risk from third parties.
An example of this threat is the ransomware attack on UnitedHealth Group’s Change Healthcare. This attack severely disrupted operations in hospitals across the U.S. Cybercriminals often use a “hub and spoke” method. They target a single third-party provider to access many healthcare organizations at once. This method increases risk and shows the need for strong cybersecurity in all parts of healthcare.
John Riggi, AHA’s National Advisor for Cybersecurity and Risk, says that cyber risk is now an issue for the whole organization, not just the IT department. It affects clinical, administrative, and operational parts of healthcare. To handle this risk well, medical practice administrators and IT managers must create complete Third-Party Risk Management (TPRM) programs. These programs should include:
At the same time, requiring vendors to have cyber insurance can help reduce financial losses from breaches.
Artificial Intelligence (AI) is changing healthcare by helping with diagnosis, personalizing treatments, and improving how work is done. In 2023, the healthcare sector spent $6.1 billion on AI. This was more than any other U.S. industry. But using AI also brings special cybersecurity risks that healthcare managers must watch out for.
AI systems use large amounts of patient data. This makes them targets for cyberattacks. Common risks include:
AI also helps defend against cyber threats. AI and machine learning can detect unusual activity faster and automate responses to reduce damage. New Digital Risk Protection Services (DRPS) use machine learning to watch for and block complex threats before they affect healthcare operations.
Additionally, AI tools help automate front-office tasks like answering phones and scheduling appointments. For example, systems created by Simbo AI reduce human contact with sensitive patient data. This lowers risks from phishing and social engineering. Automating routine tasks lets staff focus on more important work while AI handles secure communication with patients.
Healthcare groups should use special security steps for AI, like encryption, controlling access based on roles, regular security checks, and ongoing staff training to handle AI risks. People should watch AI systems closely to catch misuse or errors. Guidelines like ENISA’s cybersecurity approach, the NIST AI Risk Management Framework, and Google’s Secure AI Framework help to safely use AI in clinical and administrative work.
Even with new technology, healthcare workers are often the biggest cybersecurity risk. Doctors, staff, and IT teams must work together to build awareness and share responsibility for security.
Many healthcare workers use personal devices to access patient data. This raises risks because security rules may vary. Regular training focused on healthcare roles is very important. It should cover password safety, spotting phishing, keeping devices secure, and safely handling data. Training that uses real-life practice scenarios helps staff understand cyber threats better.
Clear communication from leaders about cybersecurity policies keeps everyone aware without getting in the way of care. Rewards and leader support encourage workers to stay active in security efforts.
IoT devices like ICU monitors, patient wearables, and home health gadgets add more connected devices to healthcare networks. While these devices help monitor patients and coordinate care, they also increase security risks. Many IoT devices cannot easily update their security or apply patches, making networks vulnerable to attacks.
IT teams must use flexible methods to secure IoT devices. This includes buying devices that meet security standards, constantly assessing risks, and working with clinical teams to ensure devices work safely within patient care.
Good cybersecurity in healthcare needs teamwork among administrators, IT staff, doctors, vendors, and third-party providers. Groups like the American Hospital Association offer resources and work with security vendors to help hospitals prepare for and respond to cyber threats.
Using technology wisely means balancing risks and thinking ahead about healthcare needs. This includes innovation and risk management at different levels—from helping patients directly to building secure systems—to build trust in technology-driven healthcare.
To lower cybersecurity risks from both direct attacks and third-party weaknesses, administrators and IT teams should:
Using these technology tools and management steps helps U.S. healthcare providers handle cybersecurity problems better. This approach creates a safer space for sensitive health data and protects key healthcare systems against changing cyber threats.
Cyberattacks disrupt patient care and safety, posing risks to patients in hospitals and affecting the entire community’s access to urgent health services. Ransomware attacks can delay care and lead to potential loss of life.
Attacks on third-party providers can be more disruptive than direct hospital attacks, affecting critical functions and services, as demonstrated by the Change Healthcare incident that impacted every hospital in the U.S.
Fifty-eight percent of the 77.3 million individuals affected by healthcare data breaches in 2023 were due to attacks on health care business associates, marking a significant increase from the previous year.
Cybercriminals employ a ‘hub and spoke’ strategy, targeting a single third-party provider to access numerous healthcare organizations, thereby amplifying the attack’s impact.
Hospitals should assess and enhance their business continuity plans, specifically for critical technology and services, and prepare for possible extended disruptions.
Training staff ensures effective execution of incident response plans during real cyberattack scenarios, thereby minimizing the impact of potential incidents.
The four strategies include reviewing the TPRM framework, implementing risk-based controls, clearly communicating policies, and intensively preparing for incident response.
Cyber insurance requirements should be specified in business associate agreements based on the vendor’s risk level, helping to mitigate financial impacts from data breaches.
Technology providers must create more secure products, as the responsibility for cybersecurity should shift from end-users to those developing technology.
The AHA provides resources, partnerships with cybersecurity vendors, and guidance for hospitals and health systems to prepare, prevent, and respond to cyber threats.