NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

77% of Ransomware Groups Are Targeting the Healthcare Sector

A new analysis of ransomware activity reveals broad, consistent targeting pressure across the United States. Ransomware activity is not limited to any specific industry, with all sectors attacked to varying degrees. The analysis was conducted by the AI-driven cybersecurity and threat intelligence platform provider Anomali, with the findings published in its US Ransomware Industry Targeting Report. Anomali observed ransomware targeting across 8 industry sectors by 200 distinct ransomware entities, with its analysis showing that technology was the most targeted sector, followed by manufacturing and healthcare.

Anomali looked at ransomware targeting across eight industry sectors – technology, manufacturing, healthcare, financial services, government public services, construction, education, and energy. There was in excess of 50% observed targeting presence in all eight sectors, with technology companies targeted by 172 of the 200 ransomware entities (86%), followed by manufacturing with 166 (83%), and healthcare in third place with 154 (77%).

The healthcare sector has long been an attractive target for ransomware groups as it is a high-pressure extortion environment combining patient care, protected health information, insurance, payments, and clinical operations, which provides multiple points of leverage for extortion. The healthcare industry is reliant on continuous access to patient data, and any attack that prevents access creates a significant safety risk. There is pressure on victims to recover rapidly, which increases the likelihood of a ransom being paid. Further, a sprawling attack surface, including legacy systems and devices that cannot be patched, makes attacks easier than in many other sectors.

While there are many potential entry points, the most common are unpatched VPNs, firewalls, edge devices, and other internet-facing applications, and these are likely to remain the most high-value entry points into healthcare environments. Internet-facing exposure should be closed before ransomware groups are able to exploit it, focusing on VPNs, firewalls, edge devices, backup platforms, RMM tools, and externally reachable applications.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Anomali recommends treating identity as the primary ransomware boundary and ensuring that phishing-resistant multifactor authentication is implemented for remote access, administrators, SSO, VPN, and privileged service accounts. Exposed RDP should be removed, reviews should be conducted to identify stale accounts, and there should be continuous monitoring for credential exposure and anomalous logins.

File encryption causes significant disruption to healthcare operations, so a rapid recovery is essential. Offline, immutable backups should be created for all critical systems and data, and restoration procedures should be tested under ransomware conditions. Anomali has seen evidence that EDR evasion is becoming a common part of the affiliate playbook and predicts increased use of EDR-killing tools by adversaries over the coming year. Anomali recommends enabling EDR tamper protections, preserving centralized logs, and monitoring PowerShell, RMM, and exfiltration behavior, and rehearsing legal, communications, regulatory, and law-enforcement decisions before an extortion deadline.

“Healthcare organizations face an especially difficult ransomware threat because attackers know that patient care cannot simply pause while systems are restored. As ransomware groups broaden their targeting and reuse the same tactics across industries, healthcare leaders need real-time threat intelligence that helps them identify emerging activity earlier, prioritize the risks most likely to affect their environment and respond before an intrusion disrupts patient care,” Patrick Holt, head of product at Anomali, told the HIPAA Journal.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist