Enhancing Cyber Defenses: HHS Responds to Surge in Healthcare Threats

The Department of Health and Human Services (HHS) is ramping up its efforts to safeguard the healthcare sector from rising cyber threats by setting industry-specific cybersecurity performance goals (CPGs) and introducing a cybersecurity gateway.

In the past year, ransomware attacks on U.S. healthcare entities surged by 128%, with 258 incidents recorded in 2023 compared to 113 in 2022, according to the Office of the Director of National Intelligence (ODNI).

In response to the escalating cyber threats both domestically and globally, HHS is intensifying its efforts to bolster cybersecurity across the healthcare sector. Brian Mazanec, deputy director at HHS’s Office of Preparedness Administration for Strategic Preparedness and Response (ASPR), highlighted these efforts at a Nextgov/FCW and Washington Technology event on August 16.

Mazanec emphasized that electronic health records (EHR), which store patient medical histories electronically, are frequently targeted or forced offline by cyberattacks. This disruption severely hampers healthcare providers’ access to patient information.

Cyberattacks on EHR systems can cause delays in medical treatments, interruptions in care, rescheduled appointments, and increased pressure on emergency services. These issues are particularly challenging for smaller rural clinics, which may have fewer IT resources and lower cybersecurity priorities. HHS’s CPGs are designed to support these less-resourced healthcare providers.

Released earlier this year, the CPGs recommend practices such as multi-factor authentication, managing risks in third-party supply chains, and maintaining an effective incident response plan. Additionally, HHS launched HHScyber.gov in January to facilitate better collaboration between healthcare providers and the government on cybersecurity matters. The site is currently being enhanced to better align with the CPGs, according to Mazanec.

Preventive measures include robust backup systems, the ability to revert to paper records during EHR system outages, and training for new clinicians on paper recordkeeping. Mazanec also pointed out that cloud-based EHR systems might handle cyberattacks differently than traditional local systems.

To improve incident response, Mazanec suggested investing in “pop-up” EHR systems, which could provide a quicker recovery and data restoration option compared to paper records. These systems would enable faster reactivation and data upload once the primary system is back online.

HHS collaborates with the FBI, Department of Defense, and Cybersecurity and Infrastructure Security Agency to support incident response and combat cyber threats.

More Articles & Posts