In the wake of rising cyberattacks on hospitals and health systems, a recent survey has revealed alarming trends in cybersecurity practices: Forty percent of cybersecurity professionals across various industries have not reported cyberattacks due to fears of job loss. This figure is notably concerning in the healthcare sector, where 30% of cybersecurity experts admitted to withholding breach reports for the same reason.
Kevin Pierce, Chief Product Officer at VikingCloud, which conducted the survey, expressed surprise at these findings, highlighting the urgent need for healthcare organizations to foster a culture where reporting breaches is safe and encouraged. Pierce emphasized that the reluctance to report cyber incidents indicates a deeper cultural issue within organizations.
The survey underscores the significant pressures faced by cybersecurity staff in the healthcare sector. Many professionals are dealing with frequent “false positives” in their security defenses, with over half of the healthcare respondents spending more than four hours per week managing these issues.
Compounding the problem, 66% of healthcare cybersecurity professionals expressed doubts about their organizations’ ability to comply with Security & Exchange Commission (SEC) requirements to disclose a cybersecurity incident within four business days. This lack of confidence is alarming, given the increasing regulatory scrutiny and the potential penalties for non-compliance.
Pierce advocates for clear communication from healthcare leaders to reassure employees that reporting cyberattacks and breaches will not result in job loss. He stresses that organizations need to prioritize transparency and accountability to protect both the institution and its patients effectively.
The survey also highlighted several critical vulnerabilities within the healthcare sector:
- Preparedness for Ransomware Attacks: Nearly half (44%) of healthcare cybersecurity professionals believe their organizations are not adequately prepared for ransomware attacks, particularly those targeting third-party vendors.
- Technological Lag: Over half (58%) of respondents feel that their cybersecurity teams are lagging behind the capabilities of cybercriminals and ransomware groups. Additionally, 54% indicated they are not equipped to defend against AI-driven cyberattacks.
Recent high-profile cyberattacks, such as the ransomware attack on the Ascension health system and Change Healthcare, underscore the urgent need for improved cybersecurity measures. These attacks have caused significant operational disruptions, financial losses, and potential exposure of sensitive patient data.
Senator Ron Wyden [D-Ore.] has called for an investigation into UnitedHealth Group’s cybersecurity practices following the Change Healthcare breach. Wyden sent a letter to the Federal Trade Commission and the SEC criticizing UHG’s failure to implement basic cybersecurity measures, such as multi-factor authentication, and urged accountability for the company’s senior officials.
Learn More. And Even More
.




