84% of Healthcare Organizations Detected a Cyberattack in the Past 12 Months
A recent survey of 1,309 healthcare IT and security professionals by Netwrix revealed 84% detected a cyberattack or intrusion in the past 12 months, with account hijacking and phishing the most common types of attacks. Account compromise was the most common type of attack for organizations with cloud-based infrastructure and occurred at 74% of surveyed healthcare organizations, but just 44% of organizations with on-premises infrastructure. For organizations with on-premises infrastructure, phishing was the most common type of attack with 63% of respondents having experienced at least one phishing attack in the past 12 months. Phishing was the second most common type of incident for organizations with cloud-based infrastructure, with attacks reported by 62% of respondents. Healthcare workers can be particularly vulnerable to phishing attacks and are less likely than workers in other sectors to receive regular security awareness training. “Healthcare workers regularly communicate with many people they do not know — patients, laboratory assistants, external auditors, and more —...
Lessons from 2024 Healthcare Data Breaches
For the fourth consecutive year, more than 700 data breaches of 500 or more healthcare records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). At present, it looks like there has finally been a fall in healthcare data breaches, although OCR has yet to finalize its data for 2024, so the total may still increase. In order to see a more significant reduction in data breaches, healthcare organizations will need to invest more time and effort into cybersecurity. As it currently stands, 2024 was a record-breaking year in terms of breached healthcare records. It has already been confirmed that the personal and healthcare data of more than 278 million individuals was exposed, stolen, or impermissibly disclosed in 2024, more than any other year to date, and there are still many investigations of 2024 data breaches that are yet to conclude. OCR’s data breach portal currently lists 66 data breaches that have been reported as affecting 500 or 501 individuals – commonly used placeholder figures when the breach reporting deadline is reached...
294,000 Allegheny Health Network Patients Affected by Business Associate Cyberattack
Allegheny Health Network (AHN), a Pittsburgh-based 14-hospital academic medical system, has announced a significant data breach involving unauthorized access to patient data at one of its business associates. The attack occurred at IntraSystems LLC, a third-party firm contracted to host, manage, and secure certain computer systems used by AHN’s subsidiary Home Medical Equipment and Home Infusion companies. IntraSystems notified ALN about the cyberattack on November 19, 2024, with its internal investigation confirming that hackers first accessed systems containing patient data on October 11, 2024. The attack only affected limited systems, not ALN’s entire patient database. Approximately 293,900 home care patients who received AHN’s Home Medical Equipment and Home Infusion therapy services were affected and had some of their protected health information accessed or stolen in the incident. ALN has confirmed that some patient data was exfiltrated from the systems managed by IntraSystems. When the breach was detected, the affected systems were immediately taken offline to prevent...
Dr. Dorothy Fink Appointed as Acting HHS Secretary
On January 20, 2025, President Trump appointed Dr. Dorothy Fink as Acting Secretary of the Department of Health and Human Services (HHS). Dr. Fink is board-certified in endocrinology, internal medicine, and pediatrics and a nationally certified menopause practitioner and expert on estrogen, diabetes, and bone health. Dr. Fink has practiced at the Hospital for Special Surgery, New York Presbyterian Hospital, and Cornell University. Dr. Fink was appointed as Deputy Assistant Secretary for Women’s Health during the previous Trump Administration in 2018 and has served for several years as Director of the HHS’ Office on Women’s Health, where she has led a wide-ranging collaborative effort with hospitals to improve maternal health. Fink takes over the $1.7 trillion government agency from President Biden’s HHS Secretary, Xavier Becerra. Following her appointment, Fink issued a statement confirming some of the priorities of the HHS’ Office for Civil Rights regarding the protection of rights of conscience and religious freedom and state funding of abortion procedures. OCR has been...
Sen. Warren Seeks Answers from RFK Jr. Ahead of Potential Appointment as HHS Secretary
Sen. Elizabeth Warren (D-MA) has written to Robert F. Kennedy Jr. seeking answers about his plans for HHS policies and the HIPAA regulations should he be confirmed as the new Secretary of the Department of Health and Human Services (HHS). Sen. Warren has publicly stated her opposition to the appointment of RFK Jr. as Secretary of the HHS, stating his appointment poses a danger to public health, scientific research, medicine, and health care coverage for millions of Americans. “RFK Jr. wants to stop parents from protecting their babies from measles and his ideas would welcome the return of polio,” said Sen. Warren in response to President Trump’s nomination of RFK Jr. for HHS Secretary. “He has spread conspiracy theories on everything from COVID to mass shootings. I will have a lot of questions about Mr. Kennedy’s fitness to serve as health secretary when he appears before the Finance Committee.” Sen. Warren does have a lot of questions, 175 of which were included in the 34-page letter requesting answers be provided promptly after the Senate Finance Committee hearing. While some of...



