In the first eight months of 2023, nearly had been breached. On top of this startling stat, experienced a cyberattack in the past year. This is a 244% year-on-year increase over August 2022. And 612,000 Medicare beneficiaries were affected in the as of May 2023. It should be obvious鈥攈ealthcare is under attack.
Today, a lot of the discussion surrounding cybersecurity in healthcare revolves around antiquated technology; a lack of resources, both people and financial; and the industry鈥檚 unique vulnerability to disruptions. Pair these challenges with the fact healthcare organizations house personal health information (PHI) and electronic health records (EHR), and it becomes clear why healthcare is such an attractive target for cybercriminals.听
If we just look at business email compromise (BEC)鈥攐ne of the more frequent types of attacks on healthcare organizations鈥攚e鈥檝e really got a problem. surveyed 653 healthcare organizations, with 71% of participants reporting that BEC attacks caused poor patient outcomes due to delayed procedures. These delayed procedures led to procedural complications, longer lengths of stay, and increased readmission rates. Even more staggering, 23% of those surveyed saw a rise in mortality rates.
These were just a few of the drivers behind President Biden鈥檚 in March 2023. After almost a year, change is finally happening. But not fast enough. That鈥檚 why the U.S. Department of Health and Human Services (HHS) is now stepping on the gas. As early as the spring of 2024, HHS plans to:
They do. Health Insurance Portability and Accountability Act (HIPAA) penalties aren鈥檛 just reserved for larger healthcare organizations. In 2022, assessed by HHS鈥檚 Office for Civil Rights (OCR) were on small medical practices.听听
In fact, there鈥檚 no shortage of healthcare organizations by OCR. Some of these facilities have as few as 25 employees.听
The bottom line is this鈥攅nforceable standards are coming. HIPAA Security Rules will be updated as early as spring 2024. And it鈥檚 time to get prepared.听
HHS identifies the top five most impactful threats as:
Within each of these threats, HHS identifies the top ten Cybersecurity Practices (or what they call CSPs) to mitigate these threats. To get the full download, HHS does a great job at outlining the vulnerabilities, impact, and best practices to consider. .听听
If you look across the five most impactful threats, you鈥檒l also see a few repeat offenders among the vulnerabilities.
With finite IT resources and limited teams, there鈥檚 a lot of pressure to do more with less. There are few organizations out there offering tools custom built for smaller organizations with under 50 physicians, under 500 providers, or less than 300 beds. There are even fewer orgs that offer multiple solutions and a person to call (or will call you) if something suspicious crops up.听
Specifically, an endpoint detection and response (EDR) solution can monitor, detect, investigate, and respond to malicious activity. A managed EDR, such as 杏吧传媒 Managed EDR, can be a cost-effective way to extend the capabilities of your team with a 24/7 Security Operations Center (SOC), fully staffed with cybersecurity experts who can respond accordingly to suspicious behavior. With more patient triage and administrators working remotely, it鈥檚 important to make sure that whichever solution you choose, it can manage hybrid work environments.
These services can monitor, identify, and respond to suspicious login activity, suspicious email forwarding configurations, and privilege escalation attempts. In 2023, just up to August, BEC attacks had (compared to 2022 levels). That鈥檚 why you need a team that can support you 24/7.
An engaging SAT program can educate your clinical and administrative staff on cyber threats. But it鈥檚 important to make sure the program is relevant to your business and your challenges. Look for courses that dive into how to:聽
An effective SAT enables your team to be your first line of defense. After all, it鈥檚 best not to take on cyber threats alone.听听
When it comes to cybersecurity, your organization is the patient. You shouldn鈥檛 have to self diagnose. That鈥檚 why you need a trusted team who can guide you, contact you directly, and educate you on how to keep your organization healthy and hacker-free.听
杏吧传媒 stands alongside you 24/7, protecting your sensitive health records and vulnerable endpoints from malicious threats. Learn more about how 杏吧传媒 can be integral to your healthcare IT systems.
At the end of the day, healthcare organizations do so much good. You deserve HHS鈥檚 carrots. Not their sticks. Learn more about what you can do to prepare for these new guidelines in our webinar: Dissecting the New Health and Human Services Regulations.
Or speak with 杏吧传媒 experts directly and schedule a live demo.听
Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.