The AHA today hosted a briefing on Capitol Hill to examine cybersecurity threats facing the health care sector, and share how hospitals and health systems are responding. John Riggi, AHA senior advisor for cybersecurity and risk, said hospitals and health systems take seriously the protection of highly-sensitive and valuable information, and employ important security measures to safeguard clinical technologies and information systems, while continuing to enhance their data protection capabilities. “Cybersecurity is not just an information technology issue focused on risk to the security and privacy of patient data, it is an enterprise risk management issue focused on patient safety and delivery of care as a priority,” said Riggi, who joined the AHA in February after spending nearly 30 years with the Federal Bureau of Investigation in a variety of assignments. He explained that many hackers, have moved from hacking credit cards to health records because they can sell the health data for 10 times more than the credit card data on the dark web. Among other key takeaways, Riggi said hospitals and health systems should have good offline backups in case data becomes encrypted from ransomware attacks, and ensure vendors manage cybersecurity risks to their systems, since any potential attack against a vendor could result in harm to a hospital or health system’s information systems.

Related News Articles

Headline
U.S. and international agencies Jan. 14 released guidance on secure connectivity for operational technology environments. Examples of OT environments in health…
Headline
The AHA Jan. 14 expressed support for the Rural Hospital Cybersecurity Enhancement Act (S. 2169), legislation that would direct the Department of Health and…
Headline
The FBI Jan. 8 released an alert on evolving threat tactics by Kimsuky, a North Korean state-sponsored cyber threat group. As of last year, the group…
Headline
Former AHA Board Member John “Jack” J. Lynch III and AHA President and CEO Rick Pollack have been announced as the 2026 recipients of the American College of…
Headline
The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable…
Headline
U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in…