Healthcare

Healthcare Cyber Attacks Examples: Joseph Steinberg on Why Medical Boards Face Unique Oversight Duties

4 Mins read

When a hospital loses access to patient records during a ransomware attack, the consequences extend far beyond IT downtime. Clinical decisions may be delayed, appointments canceled, patient trust damaged within hours, and those are in a good situation- the worst-case scenario includes people potentially dying. Clearly, for healthcare organizations, cybersecurity failures can quickly become patient care issues, making cyber risk a serious governance concern rather than simply a technology problem.

The cyberattack on Change Healthcare in February 2024 demonstrated just how far-reaching healthcare cyber incidents can become. Change Healthcare, a subsidiary of UnitedHealth Group, processes billions of healthcare transactions annually and supports critical functions ranging from insurance eligibility verification and claims processing to prescription management and payments. When a ransomware attack attributed to the ALPHV BlackCat group disrupted the company’s systems, the effects rippled across the entire U.S. healthcare ecosystem. Hospitals, providers, pharmacies, and patients experienced delays and operational disruptions, while many healthcare organizations faced significant financial strain as they worked to maintain services while payments to them were delayed. The incident highlighted an important reality for healthcare boards: cyber risk is not limited to their own organizations’ systems. A disruption affecting a critical third-party provider can create consequences that are potentially as harmful as a direct attack on the organization itself.

Unlike many industries, healthcare organizations must navigate a complex combination of regulatory requirements, highly sensitive data, operational dependencies, and patient safety concerns. As a result, boards overseeing healthcare entities face responsibilities that sometimes differ significantly from those of directors in most other sectors.

Healthcare Cybersecurity Compliance: HIPAA Requirements Boards Must Oversee

The foundation of healthcare cybersecurity compliance in the United States is the HIPAA Security Rule, which requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect patient information.

Protected Health Information (PHI) includes medical histories, treatment records, insurance details, billing information, and other personal data that can be highly valuable to cybercriminals. The sensitivity of this information places healthcare organizations under heightened regulatory scrutiny and creates unique expectations for board oversight.

One of the most significant compliance concepts under HIPAA is willful neglect. Regulators distinguish between organizations that make documented, good-faith efforts to address cybersecurity risks and those that fail to remediate known vulnerabilities. HIPAA penalties for willful neglect can range from $10,000 to $50,000 per violation, and when multiple categories of patient information are involved and numerous sensitive records leak, the resulting penalties can escalate quickly.

The financial consequences extend well beyond regulatory fines. A single ransomware incident in healthcare can result in weeks of operational disruption. Industry data suggests average downtime can reach 17 days, at documented revenue loss rates of approximately $1.9 million per day. For smaller regional healthcare systems, the impact can be even more severe due to limited financial reserves and reduced operational redundancy.

According to Joseph Steinberg, a cybersecurity expert witness, effective governance begins with understanding what security leaders should be doing and ensuring that those activities are being consistently performed, documented, and reviewed. In healthcare, that responsibility becomes particularly important because regulatory agencies often examine whether boards exercised reasonable oversight of cyberrisk management before an incident occurred.

HIPAA Breach Liability: When Oversight Gaps Create Exposure

Healthcare organizations carry a unique burden because cyber incidents can directly affect patient care, meaning that human life and health are on the line.

A data breach may expose confidential patient records, leading to identity theft, medical identity fraud, reputational harm, and loss of patient confidence. However, healthcare cyberattacks often create consequences that extend beyond privacy concerns.

Ransomware attacks can prevent clinicians from accessing critical medical records during treatment, and corrupted data can lead to deadly mistakes. Compromised medical devices may malfunction in ways that not only create operational disruptions but also harm patients. In these situations, cybersecurity becomes inseparable from patient safety.

For this reason, Joseph Steinberg notes that a frequent point of failure in legal disputes isn’t a lack of technical tools, but a lack of board-level documentation proving that directors actively fulfilled their responsibility to properly oversee the management of cyberrisk. Because of the stakes involved, patient data security requires a broader governance framework than traditional business cybersecurity. Boards must consider continuity of care, medical device security, protection of research data, and operational resilience alongside standard regulatory compliance.

Healthcare Board Cyber Oversight: Strategic Questions for Patient Data Protection

While boards are responsible for oversight, they are not responsible for implementing technical controls. Directors are not expected to select cybersecurity software, configure networks, or manage day-to-day compliance activities or even to actively supervise those who perform these tasks. The Board’s role is to ensure that management has established, implemented, tested, and kept current an effective cybersecurity and compliance program capable of identifying, mitigating, and responding to risk.

Rather than focusing on technical details, effective healthcare boards concentrate on whether management can answer several critical governance questions.

  • Risk and Remediation: When was our most recent enterprise-wide risk assessment completed? What vulnerabilities were identified, and what is the timeline for remediation? To what dangers do these technological risks expose our organization?
  • Incident Preparedness: Do we maintain tested incident response and breach notification plans? Have we established relationships with legal, forensic, and communications specialists before an incident occurs? Many specific questions might be appropriate here. For example, “How likely are we to experience a multi-week disruption from ransomware, and, if there is such risk, could patient care continue during that type of multi-week ransomware disruption?”
  • Third-Party Risk: How are vendor relationships evaluated and monitored? Are Business Associate Agreements current, and do we understand which third-party providers could significantly disrupt patient care, revenue cycles, or operations if they experience a cyberattack? Are there insurance policies in place in case a third party fails to deliver on its agreed level of service?
  • Workforce Readiness: Are employees receiving ongoing training and testing to reduce their exposure to falling prey to phishing attacks and other forms of social engineering attempts? Do clinical departments have designated security champions who reinforce cybersecurity awareness and best practices? Do people know what to do if something does go wrong from a security perspective?

Joseph Steinberg has long emphasized that strong governance depends on ensuring that critical security activities are measurable, documented, and subject to ongoing review. For healthcare boards, that principle is particularly important because regulators increasingly expect organizational boards to demonstrate that they have implemented proper oversight, not simply claim to have done so.

As cyber threats continue to evolve, healthcare organizations must recognize that cybersecurity is no longer solely an IT issue or a management issue. It is a governance responsibility that directly influences compliance, operational resilience, patient trust, and, ultimately, the quality of care delivered to the communities they serve.

Related posts
BusinessHealthcare

Workit Health Examines the Insurance Barriers That Interrupt Opioid Treatment

3 Mins read
For a health plan, the math on opioid use disorder looks straightforward: medication keeps members in treatment, treatment reduces costly emergencies, and…
HealthcareLifestylePeople

Founder of The Core Therapy Working Toward a More Emotionally Aware and Mentally Healthy India

1 Mins read
Healthcare

Complete Overview of Fistula Treatment in Delhi

2 Mins read
Fistula treatment in Delhi is known for its advanced medical care, modern technologies, and high success rates. A fistula is an abnormal…