Protecting the Health Care Ecosystem Requires Looking at Cyber Culture
Industry and federal partners are working on collaborations to transform the evolving cybersecurity landscape.

Every year, the number of ransomware attacks in the health care sector increases as leaders work to protect the digital health care ecosystem.
“It is a problem,” said Department of Health and Human Services CIO Karl Mathias at the 2023 Billington Summit — adding that the sector has seen a 42% increase since 2016 in ransomware attacks. “Last year, and this year, it’s going to be the biggest sector for ransomware attacks.”
Mathias said that prevention is key in order to get in front of the problem. The agency has created a program, 405D, which is dedicated to risk management and strengthening cybersecurity within the sector before threats occur.
“HHS isn’t just looking at it from a single hospital point of view, or even a medical group. We’re looking at the entire infrastructure of the health care system, whether it’s a provider, whether it’s a hospital, whether it’s pharmaceutical manufacturing company,” Mathias said.
In addition, HHS released a roadmap to guide health care organizations to prevent and confront cyberattacks in March. The cybersecurity implementation guide is targeted to help public and private health care sectors.
The number of cybersecurity threats is expected to increase as emerging technology like AI continues to mature and open up the threat landscape. In 2022, health care organizations in America were targeted with more than 1,400 cyberattacks weekly per organization.
“Cyber incidents pose risks to patient data, intellectual property, scientific or laboratory research, medical manufacturing and ultimately the ability of health care organizations to safely serve their patients,” said HHS Deputy Secretary Andrea Palm in a March statement.
Cybersecurity industry leaders say data protection is critical and will ultimately provide a solution to ongoing threats.
“The health care industry generates almost a third of the data that’s been put out. Health care data is so attractive, so lucrative in the dark web and the other areas that people want to get into,” Leidos CTO Srini Iyer said at the 2023 Billington Summit. “Protecting the data is so important. If we can do that, I think it’ll probably prevent a lot of activities.”
To stay ahead of these threats, Mathias said HHS is collaborating with other agencies for additional support.
“We’re working with CISA, we’re working with the FBI, to see if we can get to those places that are in trouble, particularly when you see the small rural hospitals get hit, they have less resources, we want to make sure that we can come in and help them,” Mathias said.
In 2022, the FBI received more than 200 reports of ransomware attacks in the health care sector, topping all other sectors. This is where shaping a cybersecurity culture will be key across organizations.
“Health care organizations must safeguard their information technology systems to help prevent attacks and create a culture of cyber safety in the health care industry,” Assistant Secretary for Preparedness and Response Dawn O’Connell said in a statement.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Inside Oak Ridge National Lab’s Pioneer Approach to AI
Energy Department’s Oak Ridge National Lab transforms AI vulnerabilities into strategic opportunities for national defense.
22m listen -
AWS Summit: Innovation Accelerates IT Delivery at DOD
Marine Corps Community Services is tackling outdated IT processes with agile development and cutting-edge cloud security to deliver mission-critical capabilities faster.
12m watch -
AWS Summit: NIST Secures High-Performance Computing Against Evolving Threats
NIST’s Yang Guo reveals the broad attack surface of high-performance computing and explains developing guidance and future-proofing security strategies.
9m watch -
Trump Overhauls Federal Cybersecurity with New Executive Order
The new directive aims to strengthen digital defenses while rolling back "burdensome" software requirements and refocusing AI security.
3m read -
AWS Summit: Forging Successful Cloud Modernization Partnerships
Industry leaders share insights on the critical role industry partnerships have in enabling government agencies to navigate procurement challenges for cloud and zero trust solutions.
24m watch Partner Content -
CISA's CVE Program and Why it Matters for Zero Trust
The vulnerability program provides the cybersecurity community visibility into software as part of a key pillar of CISA's zero trust model.
5m read -
Air Force, Coast Guard Talk Data Security Efforts for AI Development
The services' AI initiatives include efforts like creating clean training data, countering data poisoning and bridging siloed teams.
4m read -
DHS Secretary Urges Congress to Reauthorize CISA 2015
Federal leaders highlight CISA 2015's role in strengthening public-private partnerships and defending against evolving cyber threats.
3m read -
Rep. Gerry Connolly Leaves Lasting Mark on Federal Tech
Connolly's leadership in Congress significantly advanced government IT, emphasizing accountability, efficiency and a robust cybersecurity posture.
4m read -
Agencies Use AI to Boost Efficiency, Cybersecurity Under White House Mandates
DLA and GAO are investigating how AI can boost efficiency and bolster cybersecurity as agencies align with the president's tech directives.
3m read -
DOD Cyber Strategy to Adapt to New Budgets, Tech Innovation
Budgetary pressures spur innovation as department tackles aging infrastructure and evolving threats, says top cyber official.
4m read -
Federal Agencies Tout Tech in President Trump’s First 100 Days
Defense modernization and health care restructuring landed among some of the key IT highlights within the president's first few months.
6m read