Organizations using the National Institute of Standards and Technology’s Cybersecurity Framework as their primary cybersecurity framework report one-third lower cyber insurance premium cost growth, according to the 2024 Healthcare Cybersecurity Benchmarking Study, produced by Censinet and KLAS Research in collaboration with the AHA, Health Information and Analysis Center (Health-ISAC), and Healthcare and Public Health Sector Coordinating Council. 

Almost six in 10 of the 58 respondents reported using the NIST Cybersecurity Framework as their primary cybersecurity framework, among other findings.  

“The 2024 Benchmarking Study is a vital resource to AHA members and a critical resource in our collective response to escalating cyberattacks on our nation’s health care system,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “When criminal and nation state-supported ransomware attacks target hospitals, health systems and our mission-critical third parties, patient safety is directly placed in their crosshairs. U.S. hospitals and health systems need urgent support from initiatives like the Benchmarking Study to swiftly strengthen cyber resiliency and protect patients from these malicious attacks.” 
 

Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…
Headline
The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July…
Headline
Stryker, a medical technology company that provides services and products for hospitals, was disrupted globally by a cyberattack, the company announced March…