Ascension Health has detected a cyberattack that potentially harms 13.4 million individuals.
A chain of Catholic hospitals in the US has experienced a cyberattack in May 2024 that disrupted operations and patient care that may have affected 13.4 million customers. Ascension Health detected unusual activity on its network systems and launched an investigation. The company is assessing the impact and duration of the disruption.
The company has engaged Mandiant, a third-party expert, to aid in the investigation. Additionally, relevant authorities have been notified about this incident.
A healthcare provider at Ascension Health told Fox Business that their “teams are trained for these kinds of disruptions and have initiated procedures to ensure patient care delivery continues to be safe and as minimally impacted as possible." Although clinical operations have been disrupted, the teams continue to investigate the extent and length of the disruption.
In February, Change Healthcare fell victim to one of the most significant cyberattacks ever carried out against the US healthcare system. This attack on Ascension Health is yet another example of how healthcare organizations must prioritize strengthening their cybersecurity measures. Globally, the average cost of a cyberattack has risen to $4.45 million in 2023 and has risen 2.3% since 2022. However, organizations that prioritized a risk-based analysis approach to their cybersecurity experienced data breach costs averaging $3.98 million. This suggests that organizations that prioritize cybersecurity measures could save money. Prioritizing cybersecurity can also enhance HIPAA compliance and maintain trust with their patients.
Go deeper: The economic reality of cybersecurity attacks in healthcare
A data breach is a security incident in which sensitive, protected, or confidential data is accessed, disclosed, or stolen without authorization.
Read more: Healthcare data breaches: Insights and implications
Compliance with regulations like HIPAA requires robust cybersecurity measures to ensure patient information's confidentiality and integrity. Cybersecurity is essential for safeguarding medical devices and systems, maintaining continuity of care, and preserving reputation and trust. Effective cybersecurity measures are crucial for ensuring the confidentiality, integrity, and availability of healthcare services and patient information.
An incident response strategy is a structured approach that outlines the actions and procedures to be taken in the event of a cybersecurity incident or breach. It involves a coordinated effort to detect, respond to, mitigate, and recover from security incidents effectively.
Read more: The 6 steps of incident response