LAS VEGAS — Cyberattacks on the healthcare industry have brought hospitals, clinics and other providers to a breaking point, researchers said on Friday.
“These are patient safety issues, and yet these types of attacks continue to increase,” Christian Dameff, the co-director of the University of California San Diego’s Center for Healthcare Cybersecurity, said during a presentation at the DEF CON conference here.
The healthcare sector consistently ranks as one of hackers’ top targets because of the sector’s financial constraints, supply-chain opacity and low tolerance for downtime. Cybercriminals have repeatedly broken into hospital chains and healthcare vendors, sometimes causing widespread disruptions and even jeopardizing patient safety.
Dameff and his UCSD center co-director Jeff Tully, who joined him at DEF CON, have studied how cyberattacks affect patient care. When ransomware crippled four San Diego hospitals in 2021, wait times at other nearby hospitals skyrocketed as the hacked hospitals were forced to turn away patients at a historic rate, according to a study that they and others authored in 2023. The crush of activity caused by the cyberattacks led to a 48% increase in the median waiting-room time, a 128% increase in patients leaving hospitals without being seen and a 50% increase in visits where patients were advised to stay and left anyway.
Dameff and Tully also published a study in 2024 showing that patients suffering from cardiac arrest experienced worse outcomes when they visited hospitals near ransomware-afflicted hospitals than when they sought care elsewhere.
“Unfortunately, this is a problem that is worsening,” Dameff said. “And we are lagging with respect to … policy interventions that can help to address this problem.”
Diagnosing the problem
Policymakers have sometimes made things worse, the UCSD researchers said.
They pointed to the 2009 Health Information Technology for Economic and Clinical Health (HITECH) Act, which offered hospitals more money the sooner they upgraded to electronic health records. Cybersecurity was not a major consideration in that digitization push.
“We raced to connect healthcare without the responsible security infrastructure around it,” Dameff said.
The HITECH Act also required healthcare providers to promptly report breaches affecting 500 or more patients. (Smaller breaches only needed to be reported annually.) But the limited information contained in those reports has not proven useful to experts trying to understand the threat landscape, Dameff said.
“We need to be able to understand how best to help [hospitals], but we can’t do that because we’re flying blind right now,” he said. “We do not currently have the data that we need to be able to intervene from a clinical or operational standpoint.”
Tully said healthcare cybersecurity regulation generally falls short because it focuses on protecting the privacy of patient data instead of the availability of medical services.
Systemic challenges in healthcare
The researchers also called attention to other problems afflicting the healthcare community.
Funding is one of the biggest challenges, with rural healthcare providers in particular struggling to keep their doors open. “They lose a ton of money and are backstopped by their communities time and time again,” Dameff said. “Rural critical access to healthcare in this country is dying.”
The industry’s consolidation has also increased cybersecurity risks. A hack of one vendor or hospital chain can have widespread cascading effects. The Change Healthcare ransomware attack, which interrupted patient care for weeks, starkly illustrated this danger. By the time of the hack, Change was processing roughly half of all medical claims in the U.S., so its outage crippled many healthcare providers’ ability to receive payments and forced some of them to reduce services.
“That consolidation that led to the catastrophic failure of Change Healthcare is just one example of so many other types of consolidation in healthcare that ultimately make it much, much more dangerous,” Tully said.