Keeping Our Defenses Up Against Cyberattacks
Every day, hospitals and health systems perform a remarkable balancing act. They invest in talented caregivers, advanced technologies, innovative partnerships and modern facilities, all while keeping their focus where it belongs: delivering safe, high-quality care for every patient who comes through their doors.
But in today’s environment, delivering great care also requires something increasingly essential: protecting the digital infrastructure that makes care possible.
Cyberattacks against healthcare continue to grow in frequency, sophistication and impact. This summer alone, we’ve seen a troubling increase in cyber threats perpetrated by international cyber gangs and state-sponsored hackers. They have increased their targeting of healthcare third-party vendors, conducted ransomware attacks and led data-theft extortion campaigns.
As these attacks become more common, there is a risk that we will begin to view them as simply another operational challenge. We cannot afford to do that.
As AHA National Advisor for Cybersecurity and Risk John Riggi frequently emphasizes, we must not become desensitized to the true impact of these crimes. Cyberattacks are not merely technology incidents. They are threats to patient care and patient safety.
When cybercriminals disrupt critical systems, the consequences can extend far beyond computer networks. Surgeries may be delayed. Emergency department services may be limited. Ambulances may need to be diverted. Clinicians may temporarily lose access to information they rely on to make informed decisions about patient care.
Compounding the challenge is the growing use of artificial intelligence by cybercriminals to create more convincing phishing attempts and more sophisticated attack methods. At the same time, attacks on third-party vendors, utilities and supply chain partners have demonstrated that an organization’s cybersecurity posture is only as strong as the ecosystem on which it depends.
That is why cybersecurity remains one of the AHA’s top priorities.
We have worked closely with hospitals and health systems, federal agencies, law enforcement partners and private-sector organizations to strengthen the healthcare sector’s cyber resilience. Through our Cybersecurity and Risk Advisory Services webpage, we provide timely threat intelligence, practical guidance and actionable resources to help organizations prepare for, respond to and recover from cyber incidents.
The AHA also offers continuously updated tools, advisories and best practices designed to help hospitals maintain a heightened level of vigilance. These resources include assessments that help organizations evaluate their cybersecurity readiness, identify vulnerabilities and strengthen defenses before an incident occurs.
We also have placed significant emphasis on operational resilience. Hospitals and health systems should be prepared to maintain clinical and business continuity even if critical technologies become unavailable. In partnership with Joint Commission, we recently launched the Cyber Resilience Readiness program to help the field prepare for such a “Not if, but when” scenario. Planning, exercising and preparing for such scenarios can help ensure that patient care continues safely during a cyber disruption.
The AHA’s Preferred Cybersecurity & Risk Provider Program identifies trusted providers with vetted services that can help hospitals and health systems protect their patients and operations from cyberattacks and physical threats. Recognizing that smaller and rural hospitals often face unique resource challenges, the AHA also has partnered with organizations such as Microsoft to expand access to cybersecurity tools, training and support specifically tailored to rural providers.
While no organization can eliminate risk entirely, every organization can improve its preparedness. That starts with conducting regular risk assessments, strengthening defenses and incident response plans, training staff to recognize threats, and leveraging trusted resources and partnerships.
Most importantly, no hospital or health system should face these threats alone. Protecting healthcare from cyber crime requires a whole-of-nation approach that includes collaboration among providers, government agencies, law enforcement and industry partners.
Cybersecurity is now an essential component of patient safety. By remaining vigilant, sharing information and working together, we can strengthen our collective defenses and help ensure that hospitals and health systems continue to provide the care and services our communities depend on every day.
And as always, the AHA stands ready to help. Together, we can meet this challenge and continue our mission of caring for and protecting the patients who entrust us with their health.
For more information, contact John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, at sgee@aha.org.
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.