Part One: The Risks of Cybersecurity in the Health System

In the first part of the Triage series, Sarah Carlins and Jianne McDonald explore recent initiatives by the Department of Health and Human Services (HHS) that address cybersecurity risks faced by hospitals and health systems across the nation. With a focus on telehealth, they examine recommendations by the Office for Civil Rights (OCR) within HHS regarding cybersecurity measures for healthcare providers and patients. Additionally, they discuss the federal government’s emphasis on effective communication about the privacy and security of electronic health information as crucial for quality care in telehealth settings.

The increasing prevalence of cybersecurity incidents involving healthcare providers over the past five years has been a cause for concern. According to OCR within HHS, there was a nearly 300% surge in large data breaches involving ransomware from 2018 to 2022. This trend is likely due in part to interoperability being a key government priority and remote care models gaining popularity. As these models rely heavily on big data to support complex technologies, healthcare providers face ongoing risks related to cybersecurity.

Sarah Carlins and Jianne McDonald provide valuable insights into how healthcare providers can protect themselves from cyber threats while still providing quality care to patients. They discuss OCR’s recommendations for implementing strong password policies, regularly updating software, and conducting regular security audits. They also highlight the importance of employee training and education in preventing cyber attacks. By taking these steps, healthcare providers can better safeguard their electronic health information and protect their patients’ privacy rights.

Overall, Sarah Carlins and Jianne McDonald’s analysis sheds light on an important issue facing healthcare providers today. As technology continues to advance and remote care models become more prevalent, it is essential that healthcare providers take proactive steps to protect themselves from cyber threats while still providing high-quality care to their patients.

