Cyberattacks are increasing and expected to reach record numbers in the U.S. by the end of 2024. Although no field or industry is immune from attacks that involve phishing, ransomware and data theft, health care organizations have become a top target for cybercriminals.

October is Cybersecurity Awareness Month. It’s a topic we can’t talk about enough — this month and every month. Every single day, cybercriminals are out there trying to get information they can use for nefarious purposes. Hospitals and health systems must be diligent and prioritize their efforts to prevent and mitigate cyberattacks.

Cyberthreats are threat-to-life crimes. That’s why it’s critical to view cybersecurity as a patient safety, enterprise risk and strategic priority, and not solely as a technical issue falling under the IT department’s domain.

Earlier this year, the U.S. Department of Health and Human Services released a publication that outlines voluntary cybersecurity performance goals for health care and public health organizations. This resource describes essential goals to address common cybersecurity vulnerabilities, as well as enhanced goals to reach the “next level of defense” to protect against cyberthreats. HHS recommends, as does the AHA, prioritizing these goals to strengthen cyber preparedness, improve cyber resiliency and, ultimately, protect patient health information and safety.

The AHA is committed to keeping the field informed on cybersecurity issues and supporting our members:

  • The AHA website provides resources and information on the latest and ongoing cybersecurity threats and how to protect against them.
  • John Riggi, AHA’s national advisor for cybersecurity and risk, offers cybersecurity education, awareness and risk advisory services to hospital and health system leadership teams.
  • In a recent blog, Riggi described the threat of third-party providers to health care — an example is the cyberattack on UnitedHealth Group’s Change Healthcare this past spring — and outlined strategies to bolster an organization’s third-party risk management program.
  • In addition, the AHA has developed partnerships with several companies, including Microsoft, Google, AON, Censinet, Critical Insight and Cylera, that give discounts to AHA members for cybersecurity services and assessment tools.

As hospitals and health systems make investments in cybersecurity that protect their patients and communities, the AHA will continue to advise and assist teams in defending against and deflecting cyberattacks. 

Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…
Headline
The National Security Agency has released two phases of its Zero Trust Implementation Guidelines for organizations to improve their zero trust architecture.…
Headline
The Cybersecurity and Infrastructure Security Agency announced Feb. 13 that it will host a series of virtual town hall meetings to gather public input on…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, talks with Brett Leatherman, FBI assistant director, Cyber Division, and Gretchen Burrier, FBI…