Skip to content
  • About
  • Contact
  • Contribute
  • Book
  • Careers
  • Podcast
  • Recommended
  • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
  • About KevinMD | Kevin Pho, MD
  • Be heard on social media’s leading physician voice
  • Contact Kevin
  • Discounted enhanced author page
  • DMCA Policy
  • Establishing, Managing, and Protecting Your Online Reputation: A Social Media Guide for Physicians and Medical Practices
  • Group vs. individual disability insurance for doctors: pros and cons
  • KevinMD influencer opportunities
  • Opinion and commentary by KevinMD
  • Physician burnout speakers to keynote your conference
  • Physician Coaching by KevinMD
  • Physician keynote speaker: Kevin Pho, MD
  • Physician Speaking by KevinMD: a boutique speakers bureau
  • Primary care physician in Nashua, NH | Doctor accepting new patients
  • Privacy Policy
  • Recommended services by KevinMD
  • Terms of Use Agreement
  • Thank you for subscribing to KevinMD
  • Thank you for upgrading to the KevinMD enhanced author page
  • The biggest mistake doctors make when purchasing disability insurance
  • The doctor’s guide to disability insurance: short-term vs. long-term
  • The KevinMD ToolKit
  • Upgrade to the KevinMD enhanced author page
  • Why own-occupation disability insurance is a must for doctors

Under siege: the escalating ransomware crisis in health care

Cecil Pineda
Tech
December 29, 2024
Share
Tweet
Share

It’s not your imagination. Ransomware threats to health care organizations are at record levels and continue to rise. Last year, there were 389 reported ransomware attacks on health care organizations in the U.S., up from 258 in 2022. This year, there were 44 ransomware attacks against health care organizations in April alone, the most ever recorded for one month by cybersecurity firm Recorded Future and up from 30 in March. The trend is ominous.

Major health care ransomware incidents this year

Drug distributor Cencora Inc. (formerly AmerisourceBergen) paid a record $75 million ransom in bitcoin last March after a breach resulted in the theft of sensitive data.

Lehigh Valley Health Network, a health system based in eastern Pennsylvania, agreed in September to pay $65 million to victims of a 2023 ransomware attack after hackers posted nude photos of cancer patients online.

Leading health care clearinghouse Change Healthcare (a subsidiary of UnitedHealth Group) was hit with a ransomware attack in February that prevented electronic payments to physicians and claims processing. Change Healthcare paid a $22 million ransom in early March and was not given access to its data, as acknowledged by UnitedHealth Group CEO Andrew Witty in a Congressional hearing.

The cost of these attacks extends far beyond any ransom payments. Change Healthcare says the incident has cost it $872 million and expects that amount to exceed $1 billion. In addition, the American Medical Association found that four in five clinicians lost revenue due to the Change Healthcare breach, with 55 percent of practice owners resorting to using personal funds to pay bills and meet payroll.

Ransomware attacks also threaten the lives of patients when provider organizations’ systems and files are controlled by hackers demanding payment in return for decryption keys. In the case of the high-profile Change Healthcare breach, the ability of clinicians to approve medical procedures and prescriptions was limited. The attack disrupted 80 percent of U.S. hospitals and 60 percent of pharmacies, leading to delays in billing and processing claims.

Ransomware disrupts everything in a health network, including labs and administrative functions. Work slows to a crawl when organizations shift from electronic to physical paper-and-pen communication. This crippling inefficiency alone can severely compromise patient safety.

Cybersecurity experts for years have recommended that health care organizations refuse ransom demands. Caving in, experts warn, encourages more attacks and rewards criminal actions. And as happened in the Change Healthcare breach, the attackers who stole 4TB of patient and payment information were paid $22 million in bitcoins, but they did not provide the decryption key, and Change did not get their data back.

Yet the prospect of a ransomware attack costing the lives of patients under the care of a hospital or health system is something decision-makers undoubtedly want to avoid. After all, their primary mission is to care for patients; better to pay and get back to normal, many believe. This urgency to protect lives and sensitive patient information offers powerful leverage to bad actors and is a main reason why health care organizations are the most lucrative targets of ransomware.

When ransomware hackers strike – to pay or not to pay?

The dreaded day finally arrives – clinicians and staffers at your large hospital or health system suddenly are unable to log on to their networks to do their jobs. Instead, they are greeted with a grim warning on their computer screens that they will not be able to access any systems or data until a multimillion-dollar ransom is immediately paid in bitcoin. What do you do?

Your response depends on several factors. First, don’t panic. If you’re the organization’s chief information security officer (CISO), you should immediately consult with internal leaders and external partners to get more information about how an ongoing ransomware incident will impact various departments and processes but also impact legal and compliance aspects. The critical elements to be considered when responding to a ransomware demand are the risks to the organization, exactly which data has been stolen and held, and whether patient safety and data privacy are imperiled.

ADVERTISEMENT

Working directly with your general counsel (GC), health care CISOs should seek input from external experts such as digital forensics specialists, ransomware experts, cyber insurance carriers and brokers, law enforcement (including the FBI and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, or CISA), and your organization’s outside counsel.

Experienced outside voices can assess a ransomware hacker’s history and help you soberly weigh the risks and benefits of paying the ransom. Health care organization leaders faced with a ransom demand understandably may be angry, but it is imperative that their response isn’t influenced by emotion. At this point, whether you pay the ransom is a business decision.

Investing in cybersecurity

Legacy infrastructures and specialized connected devices (which may lack robust security features) make health care organizations inviting targets for ransomware hackers. Given the continuing increase in ransomware incidents, health care organizations should assume they eventually will be attacked.

Indeed, the Change Healthcare ransomware attack earlier this year has galvanized security efforts at provider organizations. A new Bain & Company survey shows that 38 percent of provider organizations have increased spending on cybersecurity software designed to detect and prevent ransomware attacks.

Further, many organizations have developed a variety of effective response and recovery plans and technologies that enable them to continue operations even if ransomware attackers seize their systems and data.

Whatever health care organizations decide, it is critical that they carefully weigh the pros and cons of paying a ransom to hackers that have seized their systems and data before an incident occurs. This is a critical business decision and a legal decision as well that needs to be made before any actual incident. Most CISOs I have surveyed said their stance is not to pay as it just supports the criminal industry. However, these decisions may change depending on the impact of these threats to any organizations and to protect health care information.

Developing long-term strategies for ransomware attacks will make health care organizations better prepared to effectively manage these incidents should they occur. More significantly, a comprehensive cybersecurity strategy will decrease the chances of an organization being successfully targeted by bad actors seeking exorbitant ransom payments.

Cecil Pineda is a health care executive.

Prev

How to rebuild trust in health care and improve patient outcomes [PODCAST]

December 28, 2024 Kevin 0
…
Next

Understanding alpha-1 antitrypsin deficiency: What you need to know

December 29, 2024 Kevin 0
…

Tagged as: Health IT

< Previous Post
How to rebuild trust in health care and improve patient outcomes [PODCAST]
Next Post >
Understanding alpha-1 antitrypsin deficiency: What you need to know

ADVERTISEMENT

Related Posts

  • A theological answer to our health care crisis

    Cedric Dark, MD, MPH
  • Truth be told: We have a leadership crisis, not a health care crisis

    Tomi Mitchell, MD
  • Why the health care industry must prioritize health equity

    George T. Mathew, MD, MBA
  • Migrant health in crisis: How we can lead the way in inclusive care

    Stephanie Dominic Berchmans, LMSW
  • Improve mental health by improving how we finance health care

    Steven Siegel, MD, PhD
  • The rural health care crisis and medical education

    Nick Richwagen, Evan Chen, and Jacob Riegler

More in Tech

  • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

    Martha Rosenberg
  • Why voicemail in outpatient care is failing patients and staff

    Dan Ouellet
  • Building a clinical simulation app without an MD: a developer’s guide

    Helena Kaso, MPA
  • AI-enabled clinical data abstraction: a nurse’s perspective

    Pamela Ashenfelter, RN
  • Agentic AI in medicine: the danger of automating the doctor

    Shiv K. Goel, MD
  • Will AI replace primary care physicians?

    P. Dileep Kumar, MD, MBA
  • Most Popular

  • Past Week

    • My wife’s story: How DEA and CDC guidelines destroyed our golden years

      Monty Goddard & Richard A. Lawhern, PhD | Conditions
    • Why medical school DEI mission statements matter for future physicians

      Aditi Mahajan, MEd, Laura Malmut, MD, MEd, Jared Stowers, MD, and Khaleel Atkinson | Education
    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Visual language in health care: Why words aren’t enough

      Hamid Moghimi, RPN | Conditions
    • Breast cancer and the daughter who gave everything

      Dr. Damane Zehra | Conditions
    • End-of-life care cost substance use: When compassion meets economic reality

      Brian Hudes, MD | Physician
  • Past 6 Months

    • Will AI replace primary care physicians?

      P. Dileep Kumar, MD, MBA | Tech
    • A physician father on the Dobbs decision and reproductive rights

      Travis Walker, MD, MPH | Physician
    • What is the minority tax in medicine?

      Tharini Nagarkar and Maranda C. Ward, EdD, MPH | Education
    • Why the U.S. health care system is failing patients and physicians

      John C. Hagan III, MD | Policy
    • Alex Pretti: a physician’s open letter defending his legacy

      Mousson Berrouet, DO | Physician
    • Why voicemail in outpatient care is failing patients and staff

      Dan Ouellet | Tech
  • Recent Posts

    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Autism comorbidities: the hidden link between POTS, GI issues, and hypermobility

      Carrie Friedman, NP | Conditions
    • The impact of CDC’s new childhood immunization guidance

      Umayr R. Shaikh, MPH | Conditions
    • Remote nursing for burnout: How changing environments saved my career

      Michele Abbott, RN | Conditions
    • Doctors often struggle to separate professional advice from family love [PODCAST]

      The Podcast by KevinMD | Podcast
    • Beyond weight loss: the expanding benefits of GLP-1 receptor agonists

      Zehra Haider, MD | Meds

Subscribe to KevinMD and never miss a story!

Get free updates delivered free to your inbox.


Find jobs at
Careers by KevinMD.com

Search thousands of physician, PA, NP, and CRNA jobs now.

Learn more

Leave a Comment

Founded in 2004 by Kevin Pho, MD, KevinMD.com is the web’s leading platform where physicians, advanced practitioners, nurses, medical students, and patients share their insight and tell their stories.

Social

  • Like on Facebook
  • Follow on Twitter
  • Connect on Linkedin
  • Subscribe on Youtube
  • Instagram

ADVERTISEMENT

ADVERTISEMENT

  • Most Popular

  • Past Week

    • My wife’s story: How DEA and CDC guidelines destroyed our golden years

      Monty Goddard & Richard A. Lawhern, PhD | Conditions
    • Why medical school DEI mission statements matter for future physicians

      Aditi Mahajan, MEd, Laura Malmut, MD, MEd, Jared Stowers, MD, and Khaleel Atkinson | Education
    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Visual language in health care: Why words aren’t enough

      Hamid Moghimi, RPN | Conditions
    • Breast cancer and the daughter who gave everything

      Dr. Damane Zehra | Conditions
    • End-of-life care cost substance use: When compassion meets economic reality

      Brian Hudes, MD | Physician
  • Past 6 Months

    • Will AI replace primary care physicians?

      P. Dileep Kumar, MD, MBA | Tech
    • A physician father on the Dobbs decision and reproductive rights

      Travis Walker, MD, MPH | Physician
    • What is the minority tax in medicine?

      Tharini Nagarkar and Maranda C. Ward, EdD, MPH | Education
    • Why the U.S. health care system is failing patients and physicians

      John C. Hagan III, MD | Policy
    • Alex Pretti: a physician’s open letter defending his legacy

      Mousson Berrouet, DO | Physician
    • Why voicemail in outpatient care is failing patients and staff

      Dan Ouellet | Tech
  • Recent Posts

    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Autism comorbidities: the hidden link between POTS, GI issues, and hypermobility

      Carrie Friedman, NP | Conditions
    • The impact of CDC’s new childhood immunization guidance

      Umayr R. Shaikh, MPH | Conditions
    • Remote nursing for burnout: How changing environments saved my career

      Michele Abbott, RN | Conditions
    • Doctors often struggle to separate professional advice from family love [PODCAST]

      The Podcast by KevinMD | Podcast
    • Beyond weight loss: the expanding benefits of GLP-1 receptor agonists

      Zehra Haider, MD | Meds

MedPage Today Professional

An Everyday Health Property Medpage Today

Copyright © 2026 KevinMD.com | Powered by Astra WordPress Theme

  • Terms of Use | Disclaimer
  • Privacy Policy
  • DMCA Policy
All Content © KevinMD, LLC
Site by Outthink Group

Leave a Comment

Comments are moderated before they are published. Please read the comment policy.

Loading Comments...