Every organization should take steps to improve encryption, keep backups up to date, and continually remind employees of the ever present danger of hackers getting into computer systems.
Multiple healthcare providers across the United States, including Faxton St. Luke's Healthcare, Gifford Health Care, UPMC Cole and UPMC Wellsboro have reported being affected by a ransomware attack on CaptureRx, a San Antonio-based company providing administrative services to healthcare organizations.
It is reported that files containing the health information of customers and patients, such as names, dates of birth, medical record numbers, and prescription information were accessed and stolen in the breach. CaptureRX announced that it began investigating the incident and notifying the impacted parties.
Having to work with the good old pen and paper after medical staff gets locked out of the system is one thing, but when they can’t access important medical data like information about critical care patients, the situation may become a matter of life and death. Just a month ago, the police in Germany launched an investigation after a woman died as a result of being transferred to another hospital following a ransomware attack.
So, why is healthcare such an appealing target for cybercriminals? And what measures can healthcare providers take to protect patients’ data?
What makes healthcare so attractive to hackers?
Healthcare institutions are a potential gold mine for cybercriminals,as they get to take hold of an overwhelming amount of the most sensitive data. Besides intimate medical data nobody wants to have exposed, hackers can get their hands on other private information, such as patients’ home addresses, social security numbers, and banking information. If stolen, this data can end up in financial or identity theft scams.
Unlike in other sectors, for example, retail, the information stolen in attacks against healthcare cannot be changed upon the detection of the breach. You can always get a new credit card or change your leaked passwords, but you can’t change your DNA.
Healthcare organizations make for an ideal prey for hackers, as many use outdated security software and continue to underinvest in cybersecurity. The healthcare industry invests only 4% to 7% of revenue in digital security initiatives. In comparison, the financial sector spends 15% of its revenue on cybersecurity. This is keeping in mind that, to the private healthcare sector, leaks of personal data might mean huge fines and even criminal charges for HIPPA violations due to negligence.
All of the reasons above provide hackers with a good chance of having their ransom demands fulfilled. To avoid a bad reputation and even legal repercussions, healthcare institutions must make cybersecurity their top priority.
What practical measures can healthcare organizations take to protect themselves?
Here are some steps healthcare companies should take to increase cybersecurity and protect patient information:
Oliver Noble is a security and encryption expert for NordLocker, a cybersecurity company.
Unrealistic Portrayals of Cardiac Arrest in Contemporary Film | ACC 2025
March 31st 2025Cardiac arrests in contemporary film are largely inaccurate when it comes to survival rate and etiology, according to a poster presented today at the American College of Cardiology conference held March 29 to 31 in Chicago.
Read More
Breaking Down Health Plans, HSAs, AI With Paul Fronstin of EBRI
November 19th 2024Featured in this latest episode of Tuning In to the C-Suite podcast is Paul Fronstin, director of health benefits research at EBRI, who shed light on the evolving landscape of health benefits with editors of Managed Healthcare Executive.
Listen
In this latest episode of Tuning In to the C-Suite podcast, Briana Contreras, an editor with MHE had the pleasure of meeting Loren McCaghy, director of consulting, health and consumer engagement and product insight at Accenture, to discuss the organization's latest report on U.S. consumers switching healthcare providers and insurance payers.
Listen
Winrevair Reduced Risk of Morbidity and Mortality by 76% in PAH | ACC 2025
March 31st 2025In the ZENITH trial, Winrevair was evaluated based on a composite endpoint of all-cause death, lung transplantation or disease-related hospitalization for patients with pulmonary arterial hypertension.
Read More
Clopidogrel Beat Aspirin in Preventing Heart Attacks After PCI | ACC 2025
March 31st 2025Clopidogrel monotherapy may be an alternative to aspirin for prevention of cardiac events in high-risk patients after percutaneous coronary intervention, according to a new study presented at ACC 2025.
Read More