Cyber risks are among the most significant and costly risks facing healthcare organizations today. Recovering from a cyberattack can be costly financially and in terms of the organization’s reputation. To make matters worse, falling victim to a cyberattack makes it more likely that there will be future attacks. So, how do healthcare organizations protect themselves from this costly threat?
In a recent HealthStream webinar entitled “The True Cost of Healthcare Cyber Risks,” subject matter experts quantified the real cost of such attacks and offered practical advice on how organizations can protect themselves against such attacks. The webinar was moderated by Amelie Smith, HealthStream’s Marketing Manager, Quality and Compliance and featured presenters:
Smith set the stage by describing the scope of the problem. Sixty-seven percent of C-Level executives feel that their organization is unprepared for cyberattacks. The problem is widespread and increasing. The FBI logged 300,000 phishing complaints in 2023. That number represents a 38% increase in the attempts reported in previous years.
The cost of a healthcare breach averages $10,000,000.00, an amount that does not include damage to the organization’s reputation. Healthcare organizations need a proactive approach to thwarting these attacks. What steps can they take right now?
Balsley encouraged healthcare leaders to clearly categorize organizational roles and responsibilities to ensure that at-risk groups (IT staff, information security staff, executive team, etc.) receive additional training as these groups are often targeted due to their levels of access and power. She also encouraged regular risk assessments for applications and the organization as a whole. She also urged staff to follow industry boards to keep up with the latest tactics being used by hackers and to ensure that the organization’s systems are updated regularly.
McMillan encouraged leaders to create a mindset of zero trust. Staff should be encouraged to be suspicious of everything – systems, software, people, and access — until those things are proven safe. Staff should ask questions, test systems, and regularly conduct recovery exercises.
Soldswisch shared that Hospitals are currently the number one target for ransomware attackers. In 2023, the healthcare sector experienced the largest share of ransomware attacks. In addition, there was an 18% increase in the number of attacks from 2022.
Reported losses also increased 74% now between 34.3 and 59.6 million dollars. To make matters worse, paying a ransom does not always ensure that an organization will regain access to its data. Incompetent hackers may accidentally or deliberately destroy and/or share that data on the dark web even after the ransom is paid.
In addition, there are other costs associated with a cyberattack.
And lastly, McMillan shared that up to 85% of organizations paying ransoms will fall victim to another attack.
The experts agreed that healthcare staff need to be educated on how to recognize a scam. Balsley encouraged leaders to provide staff education on scam recognition. Staff should recognize things like unexpected or unsolicited contact as a potential scam. Urgent requests for money or gift cards for the executive team or others are another clear indication of a scam.
Emails with spelling, grammar, and syntax errors along with those with generic greetings should be treated with suspicion. Staff should also be trained to look carefully at the sender’s email address and to be cautious about removable media such as USB drives that may be used to introduce malware.
Physical safety is also important. Staff should know what to do when equipment is lost or stolen and to be cautious when using devices in public where the wi-fi connection may not be sufficiently secure to protect data. Staff should also be required to lock their computer screens before leaving their desks and to use rigorous password protection.
Staff also need to understand the importance of time in cybersecurity. Should they notice anything odd about their computer’s performance or receive a suspicious email, those things should be reported to security at once as a timely response to the threat can help mitigate risk.
Staff also need to be aware of social engineering, which Balsley defined as the tactics that criminals use to persuade people to do things that they should not by exploiting their good nature. This technique may be particularly useful when directed at an industry largely populated by people with a genuine desire to help others.
Leaders are also encouraged to follow their own organization’s best practices and operate within their cybersecurity framework. Regular education and communication on the topic along with tabletop exercises in support of disaster recovery plans should also be included. The leadership team should also be educated about sensitive data, where it is, and how it is being protected.
McMillan also encouraged healthcare leaders to be aware of mistakes. “If we constantly question what we are doing, rigorously test before implementation, and engage in thoughtful change management strategies, we can avoid the kinds of mistakes that put organizations at risk,” said McMillan.
To learn more, you can access the webinar here. You can also reach out to HealthStream today to learn more about how to prepare your organization to prevent cyberattacks.
Expand the decision-making skills and effectiveness of your healthcare workforce with HealthStream's clinical development programs and services.
View All Clinical DevelopmentOur competency development solutions personalize learning for clinicians to bridge the gap between theory and practice for your nurse residents.
View All ProductsEnhance maternal & child nursing care with solutions focused on improving the quality of care for mothers, infants, and children.
View All ProductsAddress staffing orientation challenges to easily achieve and maintain certification with our emergency and acute care training solutions.
View All ProductsAs a premier provider of healthcare education, we are committed to promoting safer, more successful surgical and sedation outcomes for each and every patient.
View All ProductsOur solutions are designed to cater to the needs of patients, healthcare professionals, and organizations dealing with illnesses or chronic conditions.
View All ProductsOnline clinical placement software allows schools, healthcare organizations, and students to seamlessly manage clinical and nursing rotations.
View All ProductsComprehensive, industry-leading provider onboarding and credentialing software that validates health outcomes and supports provider assessment.
View All CredentialingOur affordable CVO credentialing services establish patient safety by enabling primary source verification for your healthcare organization.
View All ProductsIntegrate with Epic to validate and add new providers directly to your provider master file.
View All ProductsHealthStream’s learning management system and healthcare training solutions support medical training initiatives and allow for the best patient care.
View All Learning & PerformanceHealthStream offers performance learning management solutions to help develop your healthcare staff into leaders and reduce turnover.
View All ProductsHealthStream works with healthcare organizations to create engaging and high-quality training videos for your staff and management.
View All ProductsImprove care quality and save money by making informed decisions about your healthcare facility and staff with HealthStream's reporting analytics solution.
View All ProductsHealthStream's proven methods for the improvement and overall engagement of your healthcare staff foster a positive workplace and increase retention rates.
View All ProductsWhen you enact HealthStream's quality compliance solutions, you can do so with the confidence your healthcare organization will meet all standards of care.
View All Quality & ComplianceBe confident in your staff’s ability to reduce risk by providing compliance training that changes behavior.
View All ProductsDevelop next-level people for next-level care by prioritizing quality and safety improvements.
View All ProductsEstablish a culture of belonging with education supporting DEI, wellness, engagement, and leadership development.
View All ProductsMake sure your healthcare staff can schedule out appointments and work schedules with ease using HealthStream's line of software solutions.
View All SchedulingHealthcare workforce management is essential. We provide advanced scheduling solutions for organizations to solve issues such as nurse retention
View All ProductsUtilize patient access solutions and advanced reimbursement solutions to manage clinical denials and improve your organization’s reimbursement strategy.
View All ReimbursementLearn about our advanced resuscitation training solutions. Our solutions are designed to help improve patient outcomes.
View All Resuscitation