26.3 C
New York
Tuesday, August 25, 2026

We’re Eager for Washington to Address Healthcare Cybersecurity

### The Growing Threat of Cyberattacks in Healthcare

In recent years, the healthcare sector has faced an alarming rise in ransomware attacks, significantly impacting patient care and compromising sensitive medical records. According to various reports, these attacks have surged, endangering patient safety and privacy, and exposing millions of medical records to malicious actors. Health organizations have been under relentless siege, making it clear that while cybersecurity investments seem adequate on paper, they are often insufficient when tested against real-world threats.

### Noteworthy Incidents in 2025

Just this year, the attack landscape has revealed several staggering breaches. A cybercriminal managed to siphon data from 5 million patients via IT vendor Episource. Likewise, Connecticut Community Health Center faced a severe breach affecting 1 million patients, while a ransomware incident at Maryland’s Frederick Health compromised the records of over 900,000 individuals, even leading a neighboring hospital into chaos as it scrambled to accommodate additional patients.

### Legislative Recognition and Response

Recognizing the pressing need for improved cybersecurity measures, Congress has proposed the Healthcare Cybersecurity Act. This bill acknowledges a bitter truth long understood by healthcare security executives: our existing infrastructure is obsolete, and protecting patient data has not been prioritized. The proposed legislation aims to facilitate a coordinated federal response involving the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA). While this bill is a promising step forward, history shows that similar attempts have faltered in the past.

### The Urgent Need for Action

Despite the legislative efforts in the pipeline, the pressing reality is that healthcare organizations cannot afford to wait for Washington to provide solutions. The timelines set forth for responses and updates are shockingly slow, imposing a 120-day wait for initial reports and suggesting one year to revise risk management plans. In the meantime, healthcare organizations continue to endure daily cyberattacks, and patients require immediate solutions for their data protection needs.

### Underlying Infrastructure Challenges

Having experienced the cybersecurity landscape from within major healthcare institutions, I can attest to the complexities healthcare organizations face. Many entities are hamstrung by decades-old practices, characterized by siloed systems that hinder effective data management and security. The prevalent issue is a lack of clarity regarding where patient data resides. For many large enterprises, this confusion can multiply with each acquisition, leading to a landscape filled with fragmented Electronic Health Records (EHRs) scattered across various teams and contracts.

### The Dangers of Fragmented Data

The challenge doesn’t just stem from keeping track of where data is stored. The integration of proactive threat intelligence becomes increasingly convoluted, as healthcare organizations often struggle to keep up with data visibility and compliance. Many are inadvertently at risk of falling out of compliance with regulations like HIPAA and GDPR, perpetuating a cycle of vulnerability and response that often proves insufficient.

### Moving Toward Proactive Security Measures

The path to real change must begin within healthcare organizations themselves. It’s crucial for these entities to recognize that the root of their risks often lies in limited data visibility. By investing in modern data infrastructure, healthcare providers can mitigate these risks more effectively. Furthermore, treating security, privacy, and engineering as integrated domains rather than isolated departments can lead to significant improvements in data security.

### The Need for Alignment Across Teams

Effective cybersecurity does not only hinge on having advanced tools; it necessitates collaboration between various departments. Privacy leaders need to understand where data lives to maintain data rights, while security teams must know where to defend. Engineers, on the other hand, require clarity on data ownership and usage to address vulnerabilities accurately. Enhanced cooperation across these domains can lead to shared infrastructure that helps protect sensitive information without the inefficiencies caused by siloed approaches.

### Investment in Cybersecurity as a Priority

Despite the mounting evidence of the consequences of inadequate cybersecurity, many healthcare organizations still view it as a peripheral concern. Instead, cybersecurity should be treated as a fundamental aspect of patient care that directly correlates with how patient data is managed. This approach requires organizations to conduct thorough audits to understand data locations, replace legacy systems with modern solutions, and focus on automation to enhance efficiency and effectiveness in their security protocols.

### The Cost of Inaction

The consequences of neglecting cybersecurity are far-reaching, affecting not only the organizations involved but also patients who rely on their services. Organizations risk facing lawsuits, reputational damage, and lost revenue as a direct result of security breaches. Moreover, patients, in turn, may experience anxiety associated with data loss or privacy invasion, leading to deteriorating trust in healthcare providers. This erosion of public trust can have devastating effects on patient outcomes and operational costs.

### Future Directions

With the healthcare system generating trillions of dollars annually, a large portion of which could be directed toward effective cybersecurity measures, it’s crucial that leaders prioritize this issue. While legislation like the Healthcare Cybersecurity Act is essential, organizations must take proactive steps to evaluate their own practices. To truly combat cybersecurity threats, healthcare entities must not only invest sufficient resources but also cultivate a culture of shared responsibility that prioritizes patient safety and data integrity.

### About Aimee Cardwell, CISO in Residence at Transcend

Aimee Cardwell is a seasoned cybersecurity leader with extensive experience in security, engineering, and compliance. Her previous roles have included CISO at UnitedHealth Group and CIO of Optum Financial Services. Currently serving as CISO in Residence at Transcend, Aimee is dedicated to helping organizations unify their compliance and security efforts while preparing for future challenges.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles