In a statement submitted to the Senate Health, Education, Labor and Pensions Committee for a hearing today on health care cybersecurity and patient privacy, the AHA said the highest cyber risk for patient data is often through third-party service and software providers. The AHA encouraged Congress to use federal agencies and resources to protect hospitals and health systems, and in turn the patients they serve, by combating international cyber threats and supporting funding for cybersecurity training and workforce, especially in rural areas.  

“Hospitals and health systems have invested billions of dollars and taken many steps to protect patients and defend their networks from cyberattacks that can disrupt patient care and erode privacy by the loss of personal health care data,” AHA said in its statement. “Any cyberattack on the health care sector that disrupts or delays patient care creates a risk to patient safety and crosses the line from an economic crime to a threat-of-life crime. These attacks should be aggressively pursued and prosecuted by the federal government.”  

The AHA also recommended reducing administrative burdens, like making the Health Insurance Portability and Accountability Act of 1996 cybersecurity requirements voluntary and strengthening the HIPAA preemption.  

“Rural hospitals are struggling under the crushing weight of these existing policies and thus support efforts to reduce and streamline regulatory burdens,” said hearing witness Linda Stevenson, chief information officer of Fisher-Titus Medical Center, a rural hospital in Ohio. In written testimony, she said, “We must shift away from punitive approaches that penalize providers who are targeted by malicious actors. These only worsen the burden and divert resources away from patient care. Instead, we need supportive policies that empower healthcare providers to strengthen their cyber defenses.” 

Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…
Headline
The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July…