Locked files. No access to EHRs. And patients waiting to go into surgery.
 
This isn’t a fictional scenario — it’s a ransomware attack — and it’s happening in hospitals and health systems across the world … including right here in the U.S.
 
The truth: Any computer system with valuable data is a target for cyber criminals. Hospitals and health systems, municipal governments, even personal computers can be targeted.
 
October is National Cybersecurity Awareness Month… and it’s a good time to do a status check on how prepared your hospital or health system is to prevent a cyber attack from disrupting care and potentially endangering your patients and their data.
 
Cyber attacks targeting hospitals are on the rise. Most attacks come in the form of phishing emails that trick people into clicking links or opening attachments that insert malware into computer networks. Regardless of their origin, these attacks can interrupt care delivery and impact patient safety by shutting down emergency departments, forcing ambulance diversions, disabling medical devices and denying access to essential patient health records.
 
Cyber attacks can be so devastating that many hospitals and health systems now rank cyber risk within their top three enterprise risk issues.
 
The AHA is working to mitigate this threat to America’s hospitals, health systems and our patients. We’re engaging directly with the federal government on both the policy and legislative fronts for increasing cybersecurity resources, creating incentives to expand the cybersecurity workforce, increasing cyber threat information sharing and enhancing medical device cybersecurity requirements.
 
This is only half the battle, though. As many members have already seen, our in-house cybersecurity expert, John Riggi, is working directly with members to enhance their defenses and manage their risk. John spent nearly 30 years at the FBI — including as a senior executive in the FBI cyber division — and was recently selected to co-lead a national health care field cyber task group with the U.S. Department of Health and Human Services. Visit AHA’s website to learn more about how the AHA can provide tailored trainings, workshops and webinars to fit your needs.
 
October may be cybersecurity awareness month … but cybersecurity is something hospital leaders should prioritize every month. The AHA is proud to be your partner in keeping your data — and your patients — safe.

Headline
An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to…
Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Headline
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved. The…
Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…