Patient Care Disrupted by Cyberattacks at 20% of Healthcare Orgs
For some time now, it hasn’t been a case of whether there will be a cyberattack, but rather when and how frequently. Cyberattacks are a fact of life for healthcare providers, who must be able to continue to provide patient care in the event of an attack and if ransomware has been used to encrypt their network.
Naturally, cyberattacks will cause some disruption to patient care, but effective incident response plans will minimize the cost and disruption caused by a cyberattack. There is considerable concern that cyberattacks will cause more harm than delays to patient care. According to one recent healthcare survey conducted by Omega Systems, many healthcare leaders believe it is only a matter of time before a cyberattack results in the death of a patient. 52% of respondents said they believe there will be a fatal cyberattack in the next five years, with one in five saying they have already experienced disruption to patient care as a result of a cyberattack.
The survey was conducted on 250 healthcare leaders and explored the security gaps that exist at healthcare organizations. The 2025 Healthcare IT Landscape Report confirmed that many healthcare organizations are struggling to achieve the right balance between digital innovation and cybersecurity.
There was a high level of confidence that their organizations would be able to defend against AI-based attacks; however, the data undermines that confidence, as four-fifths of respondents (81%) reported being breached by an AI-driven social engineering attack last year. 48% of respondents experienced a social engineering or phishing attack, and 34% experienced a ransomware attack. Given the number of cyberattacks now being reported, it is particularly concerning that almost 1 in 5 respondents said they do not have an effective incident response plan, 30% said they do not regularly train their staff on how to respond to cyberattacks and data breaches, and around half are not conducting phishing simulations.
When asked how long it would take to detect and contain a breach, almost one-quarter of respondents said up to a month. During that time, it is inevitable that patient care would be disrupted, data would be stolen, and the entire organization could be put at risk.
One of the problems with shortening that time is outdated systems, which 56% of respondents said would delay the recovery from a cyberattack and data breach. 36% of respondents said they do not have the necessary cybersecurity tools, especially for protecting patient data stored in the cloud. Only 46% of respondents said they have adopted next-generation endpoint detection and response (EDR) tools, and the same number said they do not have data discovery technologies.
Out of the 65% of respondents that have their own cybersecurity staff, 23% said their teams are understaffed and around 20% said they lacked personnel with the right experience or have enough staff to provide 24/7 security assistance, which would inevitability delay the response to a cyberattack.
One of the solutions to the problem is to work with an MSSP to help manage and maintain cybersecurity, but 55% of respondents do not currently work with an MSSP. Omega Systems reports that when IT is co-managed with an MSSP, threat detection speed is increased, vulnerability detection is improved, and so is the adoption of HIPAA controls.
“Healthcare teams are under immense pressure, and internal resources alone aren’t enough to stay ahead of today’s threats,” said Mike Fuhrman, CEO of Omega Systems. “Leading organizations are leveraging MSSPs to gain a competitive advantage through advanced tools, continuous monitoring, and regulatory expertise for a new level of security.”
With respect to HIPAA, a major update to the HIPAA Security Rule is pending, and if passed in a form similar to the notice of proposed rulemaking issued last year, there will be a great deal more mandatory security requirements. Even with understaffing, 80% of respondents felt prepared for the upcoming changes, although meeting the compliance deadline may be a challenge, as 54% of respondents still rely on manual, in-house processes to manage compliance. 60% of respondents admitted that it is a major challenge keeping up to date with regulations at the federal and state level.
