H-ISAC, AHA, Executive Summary for CISOs: Current and Emerging Healthcare Cyber Threat Landscape

February 2024

Some call it the wall of shame – the U.S. Government website that lists healthcare
industry data breaches since 2009 – breaches which have put millions of patients’ Protected Health Information (PHI) at risk. The site, run by the Department
of Health and Human Services Office for Civil Rights (OCR), reports breaches
affecting the PHI of 500 or more individuals. When Health-ISAC reviewed the data
in mid-2023, the site listed 5,558 events totaling nearly 438 million breached PHI
records. That averages to more than 86,000 PHI records exposed every single
day for the past 13 ½ years. What’s even more troubling is that the number of
incidents reported is increasing at an alarming rate. In just the last three years
alone, 2,209 incidents were reported, whereas a total of 3,349 incidents were
reported in the first 10 ½ years of reporting.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA


(O) +1 202 626 2272