Intelligent CISO Issue 81 | Page 27

EDITOR ’ S question

HOW CAN HEALTHCARE ORGANISATIONS DEVELOP A

CYBERSECURITY APPROACH THAT MINIMISES HUMAN-TARGETED

ATTACKS WHILE ENSURING HIGH-QUALITY PATIENT CARE ?

roofpoint , a leading cybersecurity

P and compliance company , and Ponemon Institute , an IT security research organisation , recently released the results of their third annual survey on the effects of cybersecurity in healthcare .

The report , Cyber Insecurity in Healthcare : The Cost and Impact on Patient Safety and Care 2024 , found 92 % of healthcare organisations surveyed experienced at least one cyberattack in the past 12 months – an increase from 88 % in 2023 – with 69 % reporting disruption to patient care as a result .
Among the organisations that suffered the four most common types of attacks – cloud compromise , ransomware , supply chain and business email compromise ( BEC ) – 56 % reported poor patient outcomes due to delays in procedures and tests , 53 % saw an increase in medical procedure complications and 28 % say patient mortality rates increased – an increase of five percentage points over last year .
These findings indicate that healthcare organisations continue to struggle with mitigating the risks these attacks pose to patient safety and well-being .
The report , which surveyed 648 information technology and security practitioners in US healthcare organisations , found supply chain attacks are most likely to affect patient care .
More than two-thirds ( 68 %) of respondents said their organisations had an attack against their supply chains , of which 82 % said it disrupted patient care , an increase from 77 % in 2023 .
BEC leads the group of attacks most likely to result in poor outcomes due to delayed procedures and tests ( 69 %), followed by ransomware ( 61 %), which was also most likely to result in longer lengths of stay ( 58 %) and increase in patients diverted or transferred to other facilities ( 52 %).
“ Our third annual report was conducted to determine if the healthcare industry is making progress in reducing human-centric cybersecurity risks and disruptions to patient care ,” said Larry Ponemon , Chairman and Founder of the Ponemon Institute . “ For the third consecutive year , we found the four types of analysed attacks show a direct negative impact on patient safety and well-being .
“ The good news , however , is the healthcare industry seems to increasingly recognise the importance cybersecurity plays in patient outcomes ; on average , IT budgets have increased , and fewer IT practitioners indicate that budget is a challenge in keeping their organisation ’ s cybersecurity posture from being fully effective ,” added Ponemon .
Ryan Witt , Chair , Healthcare Customer Advisory Board at Proofpoint , said : “ An effective cybersecurity approach centred around stopping human-targeted attacks is crucial for healthcare institutions , not just to protect confidential patient data but also to maintain the highest quality of medical care .
“ This report underlines that cyber safety is patient safety ; protecting healthcare systems and medical data from cyberattacks is critical to ensuring continuity in patient care and avoiding disruption of critical services . And while security awareness is foundational , driving sustained behaviour change through programmes tailored to specific roles and responsibilities will help support both organisational and patient safety ,” Witt said .
WWW . INTELLIGENTCISO . COM 27