Why is cybersecurity important for the healthcare industry?
- According to Soax, in 2023, the healthcare sector experienced 809 verified major data breaches, representing a 136% increase from 2022. An estimated 56 million victims were affected by these breaches.
- In 2023, healthcare was second only to finance in the list of most attacked industries. The sector accounted for 20% of all data breaches investigated.
- In the 2023 Sophos State of Ransomware survey, 60% of healthcare organizations reported ransomware attacks. This is almost double the 34% reported by the sector in 2021.
- The healthcare sector suffers the highest average cost of major data breaches impacting large organizations ($10.93 million USD per-breach).
- Between 2020 and 2023, the average cost of a healthcare data breach increased by 53%.
These statistics serve up a useful reminder: cybersecurity is an area that no healthcare organization can afford to ignore.
To understand why cybersecurity is of outsized concern in this sector, try looking at it from the point of view of cyber criminals. In around 90% of attempts to intrude, manipulate, steal, or destroy data or systems, the primary motive is financial gain. Healthcare organizations tend to hold large volumes of sensitive personal data; exactly the type of information that can demand a high price on the dark web. And of course, when a critical healthcare system goes down, the impact can be catastrophic. Criminals know that a clinic or hospital will do ‘whatever it takes’ to stay up and running; something that helps make healthcare a prime target for ransomware and other extortion campaigns.
Alongside this, the typical healthcare business offers multiple entry points to take advantage of. Busy clinical staff are not always as diligent as they could be when it comes to cyber hygiene. Meanwhile, the digitization of healthcare and a proliferation of new connected devices means a larger digital footprint, and more entry points for hackers to explore.
Against this backdrop, it is vital for healthcare organizations to understand where and why they are vulnerable, and what processes and technologies need to be in place to build cyber resilience.