Report Shines Spotlight on Cybersecurity Crisis in Healthcare Sector

KnowBe4 recently released its International Healthcare Report. The report takes a closer look at the cybersecurity crisis currently experienced by the healthcare sector, in particular hospital groups, across the world.

The healthcare sector in North America is facing a severe cybersecurity crisis. In fact, a staggering 73% of global ransomware attacks on healthcare institutions affected those in the US. This prompted The Department of Health and Human Services to take action, developing new rules for hospitals to bolster their defenses against cyber threats. Furthermore, the department plans to revise the rules for the Health Insurance Portability and Accountability Act later this year, incorporating new provisions that specifically address cybersecurity concerns.

Hospitals have become increasingly attractive targets for ransomware attacks due to their comprehensive patient databases, sensitive information, and their interconnectedness between systems and equipment. Moreover, poor security measures have made hospitals vulnerable to cyber threats. When attacked, cybercriminals can potentially take control of entire hospital systems, and gain access not only to patients' health information but also their financial and insurance data.

Hospitals are severely impacted by cyberattacks, which can lead to a reduction in patient care, loss of access to electronic systems, and a reliance on incomplete paper records. This can also result in the cancellation of surgeries, tests, appointments, and, in some cases, even loss of life.

Some shocking facts discussed in the report include:

  • In the first three quarters of 2023, the global healthcare sector experienced a staggering 1,613 cyberattacks per week, nearly four times the global average, and a significant increase from the same period the previous year.
  • The healthcare sector has seen a dramatic surge in cyberattack costs over the past three years, with the average cost of a breach reaching nearly $11 million, more than three times the global average. This makes healthcare the costliest sector for cyberattacks.
  • Ransomware attacks have been the most prevalent type of cyberattack on healthcare organizations, accounting for over 70% of successful attacks in the past two years.
  • The majority of cyberattacks (between 79% and 91%), across sectors, begin with phishing or social engineering tactics, which allow cybercriminals to gain access to accounts or servers.
  • According to KnowBe4’s 2024 Phishing by Industry Benchmarking Report, healthcare and pharmaceutical organizations are among the most vulnerable to phishing attacks, with employees in large organizations in the sector having a 51.4% likelihood of falling victim to a phishing email. This means that cybercriminals have a better than 50/50 chance of successfully phishing an employee in the sector.

“The healthcare sector remains a prime target for cybercriminals looking to capitalize on the life-or-death situations hospitals face,” says Stu Sjouwerman, CEO of KnowBe4. “With patient data and critical systems held hostage, many hospitals feel like they are left with no choice but to pay exorbitant ransoms. This vicious cycle can be broken by prioritizing comprehensive security awareness training to empower employees and cultivate a positive security culture as a strong defense against phishing and social engineering attacks."

The report examines the state of cybersecurity in the healthcare sector in North America, Europe, the United Kingdom, Asia-Pacific, Africa, and Latin America. In addition it also highlights some of the most prolific global ransomware attacks that occurred between December 2023 and May 2024, the aftermath thereof and what healthcare organizations can do to protect themselves from cyberattacks.

To download a copy of KnowBe4’s International Healthcare Report, click here.

Featured

  • Enhancing Security and Business Intelligence

    From border security to parking lots, ALPR has gained traction across multiple use cases as the technology becomes more accurate and affordable than ever. I spoke with Jason Cook, business development director at Vaxtor, a leader in ALPR AI-based analytics, and Rui Barbosa, category manager, Surveillance Products at i-PRO, a maker of AI-enabled security cameras, to delve into the latest advancements and applications of ALPR technology. Automated License Plate Recognition (ALPR) has transformed significantly over the years, evolving from a niche technology into a powerful tool for a wide range of applications, particularly in border security. Read Now

  • Leveraging Smart Sensors

    The integration of smart sensors with data-driven video technology provides schools with a comprehensive solution to enhance safety and security. This combination offers advanced capabilities such as environmental monitoring, audio analytics, vape detection and unified data management, empowering schools to create a secure and healthy learning environment for students and staff. Read Now

  • Unlocking the End-user Perception

    An observation as a creator of identity verification solutions is that while industry leaders are often excited by the opportunity to leverage biometrics, there are often concerns raised about the end-user mindset during the conversation. Primarily, what are end-users’ expectations of biometric technology? What concerns might they have about its usage to authenticate and protect their access? Read Now

  • 4 Killed, 9 Injured at Georgia High School Shooting

    Four people were killed and nine were hospitalized after a shooting at Apalachee High School in Winder, Georgia on Wednesday. That’s according to CNN. Read Now

Featured Cybersecurity

Webinars

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3