If you work in healthcare revenue cycle management or with healthcare providers, this statistic may just blow your mind: 92% of healthcare providers said they faced at least one cyber attack in the past 12 months, up from 88% a year ago, according to a report published by Proofpoint and The Ponemon Institute.
The average financial hit per cyberattack has also climbed, with disruptions now costing healthcare organizations an average of $1.47 million in operational downtime, up from $1.3 million in 2023.
Supply chain attacks have proven to be particularly devastating. More than two-thirds of healthcare organizations reported facing such attacks, and 82% of those respondents said the incidents disrupted patient care, a slight increase from 77% in 2023. These attacks caused operational breakdowns that led to longer delays in billing cycles, affecting the collection of debts from both healthcare providers and their business partners.
Ransomware remains one of the most dangerous threats, with 59% of respondents reporting such attacks. While the percentage of organizations paying ransoms has decreased slightly, the average ransom payout has risen to nearly $1.1 million, a 10% increase compared to last year. The study also highlights the ongoing patient safety risks, with 70% of ransomware victims experiencing negative impacts on care, such as longer hospital stays and procedure delays.
Cloud account compromises have become the most common cyberattack, with 69% of respondents reporting breaches in their cloud systems. On average, healthcare providers experienced 20 such attacks over the past two years. While these incidents often result in slower operational recovery compared to ransomware or supply chain breaches, they still create financial pressure due to the costs of securing systems and managing disrupted services.
.




