72% of Healthcare Organizations Say Cyberattacks Have Disrupted Patient Care

A recent survey of healthcare IT and security professionals has highlighted the impact cyberattacks are having on patient care. Cyberattacks are causing major disruption to patient care, with appointments often postponed in the days following a cyberattack, resulting in delays to tests and medical procedures, which translates into an increase in transfers, delayed admissions, longer patient stays, and an increase in medical complications and mortality rates.

These findings came from a survey of 677 U.S.-based healthcare IT and cybersecurity professionals, conducted by the Ponemon Institute on behalf of the cybersecurity firm Proofpoint. The survey revealed that 93% of healthcare organizations experienced at least one cyberattack in the past 12 months, with an average of 43 attacks experienced over the space of a year, up from 40 the previous year.

The survey explored the human cost of these attacks. Out of the organizations that experienced one of four common types of cyberattack – ransomware, cloud compromise, supply chain attacks, and business email compromise/phishing – 72% reported that the attacks negatively affected patient care, a three-point increase from last year. The most commonly reported issue was an increase in medical complications after the attack, which occurred at 54% of surveyed organizations, 53% said patient stays in hospital increased, and 29% reported an increase in mortality rates.

These findings clearly demonstrate that cybersecurity is a patient safety issue, not just an IT issue. “Patient safety is inseparable from cyber safety,” said Ryan Witt, vice president of industry solutions at Proofpoint. “This year’s report highlights a stark reality: cyber threats aren’t just IT issues, they’re clinical risks. When care is delayed, disrupted, or compromised due to a cyberattack, patient outcomes are impacted, and lives are potentially put at risk.”

The cyberattacks that had the biggest impact on patient care were supply chain attacks, with 87% of organizations that experienced such an attack reporting a negative impact on patient care, up from 82% last year. Out of the four attack types, ransomware attacks had the biggest impact on extended hospital stays, which were reported by 67% of organizations that experienced a ransomware attack. Business email compromised attacks had the biggest impact on delays to procedures and tests that had poor outcomes (65%), and 61% of the 72% of organizations that experienced cloud compromises reported an increase in complications in procedures, and 36% reported an increase in mortality.

Data loss incidents were extremely common, with 96% of organizations experiencing at least two incidents involving exfiltration or data loss. Organizations experienced an average of 18 of these incidents in the past year, and 55% of respondents said those incidents disrupted patient care. While many of these incidents involved hacking, ultimately it was the failure of employees to follow procedures that was cited as the cause of data loss, with 25% of incidents involving privileged access abuse, and 25% involving employees sending PII or PHI to an incorrect email recipient.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

While it is essential to provide HIPAA training to employees to avoid regulatory penalties, training must also be reinforced. By providing initial and ongoing training on HIPAA and internal policies and procedures, along with regular security awareness training, healthcare organizations can eradicate risky practices and reduce the number of data breaches. The survey showed that progress is being made in this area, as 76% of surveyed organizations said they are addressing employees’ lack of awareness about security threats, up from 71% last year, although 24% are not and will be at an increased risk of employees causing data breaches. Out of the organizations that are addressing employee risks, only 63% conduct regular training and awareness programs, and fewer than half (47%) conduct phishing simulations.

“This year’s findings are a wake-up call for the healthcare industry; the root cause of many incidents lies in human factors—negligence, insider risk, and gaps in cyber awareness,” said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute. “Cyberattacks are now routinely affecting patient safety, and while security spending is up, many organizations still lack clear leadership and internal expertise to meet the challenge.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/