logo
Why Healthcare Gets Hit Hardest With Cyberattacks

Why Healthcare Gets Hit Hardest With Cyberattacks

Yahoo08-06-2025

Our health data is some of the most confidential information we have, and the systems that most healthcare companies use to protect it from cybercrooks are somewhat sickly.
Thanks to a toxic mix of aging hardware, outdated software and shoestring operating budgets, they're increasingly susceptible to cybercriminals who are not only lured by a gold mine of data but also armed with state-of-the-art hacking tools, experts told The Daily Upside, leading to some of the largest data breaches in history. And the risks extend far beyond lost data and eye-popping ransom payments.
'There's really a direct danger to patient care and life,' says Rob Hughes, chief information security officer at security firm RSA. 'That's as serious as you can get. It's a different type of pressure.'
READ ALSO: NBA Finals Kick Off With an Old (Footwear) Friend and Tariffs Deliver Record Drop in US Trade Deficit
Statistics back him up: Last year was a landmark for healthcare data breaches. According to HIPAA Journal, there were 14 attacks involving the records of 1 million or more patients in 2024, exposing the records of more than 237 million individuals altogether. The biggest healthcare breach in history occurred only two months into the year, when ransomware attackers stole the data of 190 million people from Change Healthcare in February.
'There are a lot of vulnerabilities that healthcare organizations don't even realize they have,' said Alpesh Shah, vice president of security strategic alliance at Myriad360. 'Every individual who is touching a smart device is vulnerable to bring some sort of threat to the organization.'
The technological advances that have revolutionized healthcare over the past 50 years have simultaneously ramped up cybersecurity risks exponentially. The amount of personal information collected at healthcare facilities is mountainous, with every machine collecting bits of data on patient health at a constant rate.
Many of the technologically complex devices used daily or even hourly are operating on outdated software, Hughes said, a combination that leaves medical centers riddled with vulnerabilities.
For instance? A big MRI machine that still makes a nice MRI image but runs 'an old version of Windows that can't accept patches anymore,' he said.
Exacerbating the problem are security measures that often involve a patchwork of systems inexpertly quilted together, said Gary Salman, CEO of Black Talon Security. Healthcare organizations often use security solutions from multiple vendors, which can lead to a lack of standardization or centralization, he said.
While this puts them in a 'feel-good position,' the mishmash of products may not always cover the ground that it should while creating both unnecessary complexity and a glut of data. 'How do you triangulate all of this, especially in medium- and large-size healthcare organizations?' he asked.
At a more strategic level, few shareholders and healthcare practitioners prioritize cybersecurity budgets, focusing instead on delivering patient care. Smaller regional and rural healthcare facilities are often living below the 'cybersecurity poverty line,' he said. 'Security is going to come second.'
Plus, talented cybersecurity professionals have become increasingly sought after and expensive. And because of healthcare's limited budgets for technology, it doesn't always get the best cybersecurity talent, said Shankar Somasundaram, founder and CEO of Asimily.
'Healthcare may not always be able to pay the same amount,' said Somasundaram. 'Strong talent would go to another vertical, where they're getting paid more.'
While formidable to healthcare executives, the tangled web of cybersecurity challenges merely sweetens the pot for hackers who, according to Salman, view healthcare data as a 'pot of gold.' The information is highly sensitive, incredibly personal and usually deeply detailed. Plus, organizations are collecting massive amounts at a constant rate, he said. 'Any size healthcare organization that has anywhere from thousands to millions of patient records – the risk is high,' Salman said.
Selling such data to brokers through underground channels is also far more lucrative than pushing other types of data, Somasundaram added. When hackers sell credit card information, 'they have to collect 50 credit cards to make a single dollar,' he said. 'They can sell a healthcare record for tens of dollars each.'
Because of the sensitivity of health data – and the fact that these records generally can't be wiped or changed the way a credit card or phone number can – healthcare organizations will often pay up when hit with ransomware attacks, said Salman.
'Imagine having a human being's complete demographic profile. That data could be sold to pharmaceutical companies,' said Shah. 'Thieves will go where the money is. And data is the new money.'
Data loss is only the beginning of the problem, added Hughes. Cyberattacks can completely shut down healthcare facilities, forcing patients to seek care elsewhere, he said. In extreme cases, cyberattacks on healthcare organizations have been linked to fatalities, such as the 2019 attack on a hospital in Alabama that led to the death of a newborn.
'There is a state of mind that hackers are moral,' said Itay Glick, director of product at security firm OPSWAT. 'We need to understand that not all the attack groups share the same ethical standards that we think they should.'
Despite the growing risks, healthcare organizations all too often simply react to attacks rather than working to prevent them, said Salman. Along with putting patients at risk, the strategy ends up costing organizations a far larger sum than they would have paid to establish adequate cyber defenses.
While change often happens slowly, there are a variety of steps healthcare organizations can take to make themselves less attractive targets.
Some are simpler, such as consistent security patching, strengthening credentials and providing cybersecurity education to staff, said Hughes. Vulnerability and penetration-testing can also help organizations identify their biggest pitfalls, said Glick.
Backup Plan: Backing up data, meanwhile, is vital for healthcare organizations, Glick added. Since a major part of ransomware attacks is 'winning your data back,' having a backup stored can allow an organization to quickly recover, he said.
The most important fix, however, is making cybersecurity a priority, especially among leadership and stakeholders. Change and awareness have to come from the top, said Somasundaram. Rather than viewing cybersecurity as an additional cost, corporate decision-makers should treat it as a vital necessity.
'In any industry which prides itself on patient outcomes and patient wellness and improvement, they see cybersecurity as a cost, not an outcome-based thing,' Somasundaram said. 'But if they could see the tie between cybersecurity and patient impact or lives, then I do believe they'd invest.'
This post first appeared on The Daily Upside. To receive delivering razor sharp analysis and perspective on all things finance, economics, and markets, subscribe to our free The Daily Upside newsletter.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

PCP Toolkit for Treating Patients With Respiratory Diseases
PCP Toolkit for Treating Patients With Respiratory Diseases

Medscape

time43 minutes ago

  • Medscape

PCP Toolkit for Treating Patients With Respiratory Diseases

Primary care physicians (PCPs) regularly encounter respiratory issues, from the common cold to asthma, chronic obstructive pulmonary disease ( COPD), and more. These conditions can, at times, be diagnosed fairly quickly and easily. But sometimes, ubiquitous symptoms can make differentiating diagnoses difficult. Lung diseases can range from very minor to critical, so you don't want to waste any time in the diagnostic process. It's important, then, to know what tools PCPs have at hand and how to best apply them. This is especially true as many lung diseases also have comorbidities. 'Patients with COPD often also have high blood pressure, high cholesterol, and left-sided heart disease,' said Jeffrey Marshall, MD, pulmonologist at University of Maryland Baltimore Washington Medical Center in Glen Burnie, Maryland. It's also common for patients with respiratory diseases to experience concomitant mental health struggles, according to Marshall. For instance, high rates of anxiety are often found in patients with advanced lung disease. 'All these comorbid conditions can both exacerbate the patient's underlying pulmonary disease or be confused as an exacerbation of that pulmonary disease,' he said. Respiratory complaints — like difficulty breathing and chest pain — are among the most common reasons patients visit the emergency room. While these complaints may fall within respiratory illnesses, there are often other explanations for a patient's symptoms. Learning to discern these differences can be an important skill set as a PCP. That said, it's also important to know when to refer to a specialist. 'Early recognition and timely referral can significantly improve patient outcomes,' said Tejaswini Kulkarni, MD, associate professor of medicine and director of the Interstitial Lung Disease Program at The University of Alabama at Birmingham. Here's what you need to know to treat and guide your patients presenting with respiratory issues. PCP Toolkit The first step to having a handle on respiratory issues with your patients is taking a comprehensive medical history. For patients who have been already diagnosed with a respiratory condition, 'it's important to reinforce proper disease management and medication adherence,' said Marshall. 'Exposures, triggers, prior personal history, and a detailed family history are all important components of understanding a patient's pulmonary condition.' Tobacco use is a primary example of this — patients who currently smoke or have smoked in the past are going to be more susceptible to respiratory conditions of all kinds. 'Though cigarette use has declined in most places across the country, tobacco use still has a significant impact on our nation's health,' said Marshall. 'Tobacco use contributes to many diseases, including asthma, COPD, heart disease, and, of course, cancer. Current and former smokers are also at a significantly increased risk of infections, namely the development of pneumonia.' In addition, patients with a history of smoking are more likely to be hospitalized and die from pneumonia, he said. Physicians should also consider their patients' work history, hobbies, and current occupation. Patients who work in certain occupations, like construction, for instance, may have exposure to harmful substances, like asbestos or certain paints. Chronic exposure may lead to complications and can be a good starting point for diagnosis. Even living in an area with high pollution and poor air quality can be a contributing factor. Patients will present with both acute and chronic symptoms, ranging from cough to shortness of breath, exercise-induced asthma, allergies, and sleep apnea. After taking a comprehensive history, physicians can utilize a variety of tools for further diagnosis — one of which could include pulse oximetry. 'Though patients typically present with symptoms prior to ever becoming hypoxemic, it may be helpful to get a walking pulse oximetry to understand the degree of changes in SpO2 and heart rate with exertion,' said Marshall. 'Simply walking a patient with a pulse oximeter can provide helpful information regarding exercise tolerance and whether that patient needs oxygen.' Physicians might also want to try a handheld spirometer, which is simple to use and provides a good deal of information regarding patients' pulmonary and respiratory health. 'Spirometers can provide you with a basic set of numbers right in the office,' said Orlando Ruiz-Rodriguez, MD, a pulmonologist at Orlando Health in Orlando, Florida. A basic stethoscope can also help in diagnosing pulmonary issues. 'Listening to lungs is part of the standard of care,' said Ruiz-Rodriguez. 'Make sure there are no abnormal sounds, like wheezing, crackling, or decreased breathing. Today's generation of stethoscopes are electronic and a much-improved tool at the primary care level.' There are other tests PCPs can explore before deciding it's time to seek out a specialist. 'To expedite workup and management of patients with lung diseases, pulmonologists typically prefer certain baseline tests before a referral,' said Kulkarni. 'These commonly include pulmonary function tests to assess airflow obstruction or restriction, chest imaging (chest x-ray or high-resolution CT if interstitial lung disease is suspected), and basic lab work such as CBC [complete blood count], CMP [comprehensive metabolic panel], and BNP [B-type natriuretic peptide test].' To help reduce diagnostic delays and improve patient outcomes, it's best to move with caution when considering a pulmonary fibrosis diagnosis, said Kulkarni. Pulmonary fibrosis is often challenging to diagnose because clinical presentation mimics common conditions like coronary artery disease and COPD, 'but it has worse clinical outcomes with delays in treatment,' she said. Beyond diagnostics, one consideration to keep in your toolkit, said Marshall, is vaccines. 'Patients with underlying respiratory or pulmonary conditions are at a higher risk of developing and becoming sick from respiratory illnesses,' he said. 'We now have several extraordinary vaccines available to our patients to help reduce the burden of infectious respiratory disease.' When to Refer While PCPs can treat respiratory issues in office to the best of their ability, there are times when referring to a pulmonologist is essential. 'Your local neighborhood pulmonologist is your friend,' said Marshall. 'Referrals to a pulmonologist should be considered whenever there is diagnostic uncertainty, when initial therapeutics are not working, or when more complex interventions or therapeutics are necessary in the workup and management of your patient.' A few common reasons to refer to a pulmonologist include treating or diagnosing unremitting cough or chronic refractory, he said. There are certain times when immediate referral is appropriate, according to Kulkarni. These include rapidly progressive dyspnea, hypoxia, hypercapnia, hemoptysis, suspected lung cancer, and large pleural effusions. For cases of symptom progression, she recommends referring with chronic coughs lasting over 8 weeks, unexplained or worsening dyspnea, frequent asthma or COPD exacerbations despite treatment, recurrent pneumonia, and signs of pulmonary hypertension. Referring should not be considered a last resort, either, said Ruiz-Rodriguez. 'Some primary care doctors want to do as much as possible before referring,' he said. 'But know the limitations of what you have available to you. If your patient has symptoms, abnormal test results, or even a complicated medical history, send them to us. Even sleep apnea with a complicated history is a cue to move on to a specialist.'

Summer 2025 brings killer heat. Here are some surprising ways to stay safe.
Summer 2025 brings killer heat. Here are some surprising ways to stay safe.

Yahoo

timean hour ago

  • Yahoo

Summer 2025 brings killer heat. Here are some surprising ways to stay safe.

Summer 2025 has arrived. It's starting off hot, and the forecast says get used to it. A hot summer isn't just uncomfortable — it's dangerous. Heat killed more people in the United States in 2024 than floods, tornadoes, wind or hurricanes, according to a report on weather-related fatalities published by the National Weather Service. The 30-year average tells the same story. Heat danger comes in many different forms. Sun exposure can damage your skin; sweating dehydrates you; humidity prevents sweat from doing its job; your body stops functioning property when it gets too hot. That can all quickly cascade into a life-threatening or deadly illness, even in otherwise healthy people. Some heat safety tips are obvious — but some are surprising. (Do you know how much water to drink while in the heat? It's probably more than you think.) Here's what to know: Keep your cool: Experts on how to stay safe, avoid sunburns in record-high temps Use sunblock or sunscreen: And reapply it regularly (every 2 hours is a good baseline.) Dress for the heat: Pick loose fitting, light colored and lightweight clothes, the National Weather Service recommends. Don't leave kids or pets in the car: The temperature quickly becomes deadly — even if it's not that hot outside. Check the weather: Your favorite weather app should have a wealth of information about UV index (for sunblock purposes), heat warnings and the feels-like temperature (more on why that's important below.) has additional information about the forecast and heat risk. Bring water: You'll need multiple bottles of water per person if you're spending extended time out in the sun. (How many bottles? Read more here.) Seek shade and air conditioning: Minimize your risk by staying cool and avoiding direct sun when you can. Know your risks: Heat is dangerous for everyone, but some people are more vulnerable than others. Being a child, over 65 or pregnant puts you at greater risk, the Centers for Disease Control and Prevention says. How long does sunscreen last? A guide to expiration dates, and if waterproof really works When the humidity is high, sweating isn't as effective at cooling the body. That makes it feel hotter than it is — and increases the danger. The heat index is a measure of how hot it really feels when relative humidity is factored in with the actual air temperature. When the heat index reaches 105 degrees or higher, conditions can quickly become dangerous for both people and pets. A lot. In Arizona, officials recommend drinking about 65 ounces of water a day, even if you're mostly indoors. It's even more urgent for people working outdoors in extreme heat. The Occupational Safety and Health Administration says outdoor workers should drink at least 8 ounces of water every 20 minutes, even if they're not thirsty. If you're drinking 16-ounce bottles of water, that would be 3 bottles every 2 hours. Your body may need to replenish electrolytes – but be careful about sugary or caffeinated drinks if you're trying to stay hydrated. Kelly Olino, assistant professor of surgical oncology at the Yale School of Medicine, previously told USA TODAY that people can dilute a bottle of Gatorade with water to replenish both water and replace salt losses from extended sweating. "In the extreme heat, with sweating, we're losing pure water, but we're also losing salt," she said. Excessive heat and humidity make it difficult for your body to regulate its temperature. Here are some of the signs and symptoms of heat illness, according to the CDC. The National Athletic Trainers' Association says heat stroke can quickly turn deadly. The association says to watch out for: Altered consciousness ("seizures, confusion, emotional instability, irrational behavior or decreased mental acuity") Nausea, vomiting, or diarrhea Headache, dizziness or weakness Increased heart rate Decreased blood pressure or fast breathing Dehydration Combativeness A person with a temperature around 104 degrees is in a life-threatening situation — they need immediate medical treatment. One incredibly effective treatment: An ice-filled tub. Contributing: Cybele Mayes-Osterman, USA TODAY; Raphael Romero Ruiz, Arizona Republic; Cheryl McCloud, Pensacola News Journal This article originally appeared on USA TODAY: Summer 2025 heat safety tips: How much water to drink and more

Bill Gates reveals 'next phase of Alzheimer's fight' as he shares dad's personal battle
Bill Gates reveals 'next phase of Alzheimer's fight' as he shares dad's personal battle

Fox News

timean hour ago

  • Fox News

Bill Gates reveals 'next phase of Alzheimer's fight' as he shares dad's personal battle

Bill Gates is speaking out about his personal experience with Alzheimer's — and his hope for progress in fighting the disease. In an essay published this week on his blog at the Microsoft co-founder and tech billionaire, 69, reflected on the difficulty of spending another Father's Day without his dad, Bill Gates Sr. The elder Gates passed away in 2020 at the age of 94 after battling Alzheimer's. "It was a brutal experience, watching my brilliant, loving father go downhill and disappear," Gates wrote in the blog post. Today, motivated by his own experience with the common dementia, Gates — who serves as chair of the Gates Foundation — is committed to working toward a cure for the common dementia, which currently affects more than seven million Americans, or one in nine people over 65. In his blog, Gates expressed optimism about the "massive progress" being made in the fight against Alzheimer's and other dementias. Last year, Gates said he visited Indiana University's School of Medicine in Indianapolis to tour the labs where teams have been researching Alzheimer's biomarkers. "I also got the opportunity to look under the hood of new automated machines that will soon be running diagnostics around the world," he wrote. "It's an exciting time in a challenging space." One of the biggest breakthroughs in Alzheimer's research, according to Gates, is blood-based diagnostic tests, which detect the ratio of amyloid plaques in the brain. (Amyloid plaques, clumps of protein that accumulate in the brain, are one of the hallmarks of Alzheimer's.) "I'm optimistic that these tests will be a game-changer," Gates wrote. Last month, the U.S. Food and Drug Administration (FDA) approved the first blood-based test for patients 55 years and older, as Fox News Digital reported at the time. "A simple, accurate and easy-to-run blood test might one day make routine screening possible." Traditionally, Gates noted, the primary path to Alzheimer's diagnosis was either a PET scan (medical imaging) or spinal tap (lumbar puncture), which were usually only performed when symptoms emerged. The hope is that blood-based tests could do a better job of catching the disease early, decline begins. "We now know that the disease begins 15 to 20 years before you start to see any signs," Gates wrote. "A simple, accurate and easy-to-run blood test might one day make routine screening possible, identifying patients long before they experience cognitive decline," he stated. Gates said he is often asked, "What is the point of getting diagnosed if I can't do anything about it?" To that end, he expressed his optimism for the future of Alzheimer's treatments, noting that two drugs — Lecanemab (Leqembi) and Donanemab (Kisunla) — have gained FDA approval. "Both have proven to modestly slow down the progression of the disease, but what I'm really excited about is their potential when paired with an early diagnostic," Gates noted. He said he is also hopeful that the blood tests will help speed up the process of enrolling patients in clinical trials for new Alzheimer's drugs. To accomplish this, Gates is calling for increased funding for research, which often comes from federal grants. "This is the moment to spend more money on research, not less," he wrote, also stating that "the quest to stop Alzheimer's has never had more momentum." "There is still a huge amount of work to be done — like deepening our understanding of the disease's pathology and developing even better diagnostics," Gates went on. "I am blown away by how much we have learned about Alzheimer's over the last couple of years." Gates pointed out that when his father had Alzheimer's, it was considered a "death sentence," but that is starting to change. "I am blown away by how much we have learned about Alzheimer's over the last couple of years," he wrote. For more Health articles, visit "I cannot help but be filled with a sense of hope when I think of all the progress being made on Alzheimer's, even with so many challenges happening around the world. We are closer than ever before to a world where no one has to watch someone they love suffer from this awful disease."

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store