Skip to main content
Tech

Healthcare’s cyberattack problem is getting worse

These attacks can expose people’s personal information and shut down or delay vital healthcare services.

4 min read

TOPICS: Tech / Hospital Operations & Infrastructure / Cybersecurity

Cyberattacks are never good news. But they can be particularly devastating to medical service providers and suppliers, and they’re becoming more common.

Healthcare data breaches have trended up since the federal government began posting public summaries in 2009, according to an analysis by news outlet the HIPAA Journal.

These attacks can expose people’s personal information and shut down or delay vital healthcare services. An attack on the UK’s National Health Service in 2024 caused delays that reportedly contributed to a patient’s death.

The motives for a cyberattack are as varied as their methods. They involve AI tools like targeted voice phishing and malware to achieve goals ranging from revenge to extortion.

One cybercrime group, ShinyHunters, has claimed to have stolen millions of records to obtain ransoms from medical device makers Medtronic, Abbott, and Baxter along with pharmaceutical supplier McKesson. The Health Information Sharing and Analysis Center (Health-ISAC), a cybersecurity nonprofit, posted an urgent threat alert about the group on Aug. 28.

To find out more about what’s at stake and how healthcare organizations can avoid becoming victims, we talked with Errol Weiss, Health-ISAC’s chief security officer. Weiss joined Health-ISAC in 2019 and has previously worked at Bank of America, Citigroup, and the National Security Agency.

This interview has been edited for length and clarity.

What stands out about ShinyHunters’s attacks?

You’ve got an adversary who’s determined. They’re seeing success, and they’re just relentlessly going after the sector. [They] use social engineering tactics to be able to get multi-factor authentication tokens reset, or somehow steal them from unwitting users. That provides them a foothold inside the organization, and then they use that to install their ransomware.

They’re not hacking. They’re not taking advantage of a software vulnerability. They’re taking advantage of human vulnerability.

Navigate the healthcare industry

Healthcare Brew covers pharmaceutical developments, health startups, the latest tech, and how it impacts hospitals and providers to keep administrators and providers informed.

By subscribing, you accept our Terms & Privacy Policy.

In these recent attacks, they’re calling your personal device and they’re spoofing the phone number to make it look like they’re calling from the main number at your company.

Is the healthcare sector adequately prepared to counter cyberattacks?

That’s definitely one of the things that is quite different from my time in the finance sector.

Banks, by regulation, had to have a chief information security officer. That’s not the case in health, for example. That was really surprising for me. And then digging down deeper into that, I definitely saw that [healthcare’s] investments in cybersecurity were lagging behind other sectors.

It’s getting better, within the last five to seven years, but…I think one of the biggest challenges that health organizations today face is just that lack of investment. It shows itself in terms of not only not having the technology that’s needed to properly secure and protect the environment, but [lacking] the people that you need to operate that and run it successfully. It’s difficult to recruit and retain that kind of talent in the face of competing with all of these other sectors.

How can organizations protect themselves?

Make sure everybody’s thinking about security. Everybody inside the organization, even if it’s not their job…If they see something that they think is suspicious, there should be clear ways, without penalty, to report that kind of information.

I tell IT leads and security leaders…you want to patch often. Stay up to date as these new patches come out because the adversaries are taking advantage of old vulnerable software that hasn’t been patched. The next thing is backing up your systems and making sure you can restore them if needed, testing that periodically. Then the last one is the use of multi-factor authentication.

About the author

Caroline Catherman

Caroline Catherman is a reporter at Healthcare Brew, where she focuses on health insurance developments, Medicare and Medicaid, and policy.

Healthcare Brew covers pharmaceutical developments, health startups, the latest tech, and how it impacts hospitals and providers to keep administrators and providers informed.

By subscribing, you accept our Terms & Privacy Policy.